Language package managers like pip, npm, and others pose a high risk during active supply chain attacks. However, OS updates ...
The TeamPCP hacking group continues its supply-chain rampage, now compromising the massively popular "LiteLLM" Python package ...
My reliable, low-friction self-hosted AI productivity setup.
A critical supply chain attack has compromised the popular JavaScript library axios, leading to developers unknowingly ...
On the morning of March 24, 2026, tens of thousands of software developers working on AI applications were unknowingly exposed to malware.
Socket and Endor Labs discovered a new TeamPCP campaign leading to the delivery of credential-stealing malware ...
Active exploits, nation-state campaigns, fresh arrests, and critical CVEs — this week's cybersecurity recap has it all.