OpenAI Revokes macOS App Certificate After Malicious Axios Supply Chain Incident
OpenAI revoked its macOS app certificate after a compromised Axios library infiltrated its GitHub Actions workflow on March 31.
Stay updated with the latest cybersecurity news, threat intelligence, and industry updates from secure.com.
OpenAI revoked its macOS app certificate after a compromised Axios library infiltrated its GitHub Actions workflow on March 31.
A critical pre-authentication RCE flaw in Marimo is being actively exploited to steal credentials and any unpatched instance reachable from the internet is already a live...
A critical Juniper Networks default password vulnerability allows remote attackers to completely take over network devices without any authentication.
Amazon Web Services launched Amazon S3 Files, allowing organizations to access S3 buckets through traditional file system interfaces.
Identity visibility platforms are emerging as the answer to fragmented IAM systems that leave enterprises exposed across thousands of applications.
Introduction Anthropic just dropped a cybersecurity bombshell. The AI company’s new Claude Mythos model discovered thousands of zero-day vulnerabilities across major computer systems through a new...
A live Axios npm supply chain attack is putting over 100 million weekly downloads at risk after malicious versions were pushed directly to the registry.
A new study exposes a Claude Code safety bypass rate of 90.5%, raising fresh concerns about how much developers can trust AI coding tools.
Recent critical infrastructure cyberattacks show that digital breaches now trigger devastating physical consequences for millions.
A threat actor on BreachForums claims to have pulled off a massive OVHcloud data breach but the company's own founder says the evidence doesn't hold up.
Dateline: March 25, 2026. TeamPCP Didn’t Hack You. Your Package Manager Did the Work for Them. You ran pip install, went for coffee, and came back...
A credential-stealing campaign targeting GitHub Actions supply chain attack pipelines has spread from Aqua Security's Trivy to two widely-used Checkmarx workflows.
A newly disclosed flaw in Ubuntu 24.04 and later versions gives local attackers a path to full root access — no special permissions required. The catch?...