
Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats
Cybersecurity researchers have flagged a “coordinated malware campaign” on the JetBrains Marketplace that has published no less than 15 malicious plugins capable of exfiltrating artificial intelligence (AI) provider keys. “Every plugin poses as an AI coding…
Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot ChatsRead More

144 Mastra npm Packages Compromised via Hijacked Contributor Account
As many as 144 npm packages associated with the Mastra namespace (“@mastra/*”), a popular open-source JavaScript and TypeScript framework for building artificial intelligence (AI) applications, have been compromised as part of a software supply chain attack…
144 Mastra npm Packages Compromised via Hijacked Contributor AccountRead More

CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting Widget Factory Joomla Content Editor (JCE) to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability,…
CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code ExecutionRead More

Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting
A flaw in the Google Cloud Vertex AI SDK for Python let an attacker with no access to a victim’s project hijack the victim’s machine learning model upload and run code inside Google’s serving infrastructure. Palo…
Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket SquattingRead More

ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures
Cybersecurity researchers have flagged multiple ClickFix campaigns that deliver three malware loaders called BabaDeda Loader, Lorem Ipsum Loader, and Potemkin, per independent reports from Morphisec, BlueVoyant, and Huntress, respectively. Attacks involving BabaDeda Loader, observed in April…
ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update LuresRead More

New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds
Security researchers atĀ Zimperium’s zLabsĀ have documented a new Android banking trojan, Rokarolla, that targets 217 banking and cryptocurrency apps and packs 137 remote commands. Together, they give an operator near-total control of an infected phone: it lifts…
New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet FundsRead More
Get the latest news
Subscribe now and get the latest cyber security news in your email.









