» Tag
malware
33 postsYour AI Code Reviewer Ran My Malware
AI code review tools can run malware due to security vulnerabilities. Learn more about these risks.
Stinger: Capture Secret-Stealing Activity via Local Traps on macOS/Linux
Stinger is an endpoint deception tool for macOS and Linux that captures malicious interactions using local traps.
Slopsquatting: Your Coding Agent Is a Supply-Chain Attack Vector
Slopsquatting is a supply-chain attack emerging from AI coding agents. Learn how LineageLens Trellis mitigates this risk.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comExploring Software Cracking with AI
Exploring the effectiveness of AI in software cracking and analysis.
CLOSEDQUORUM Malware Uses AI Models for Autonomous Post-Compromise Actions
CLOSEDQUORUM is a new Windows malware that autonomously selects actions using AI models.
Hackers poison arrayref Rust crate to push infostealer malware
Hackers compromised the arrayref Rust crate to introduce infostealer malware. Learn more about the attack.
Linux Fileless Execution: Process Injection and Syscalls Explained
An in-depth examination of fileless execution methods and system calls on Linux.
Malicious Jscrambler NPM Package Versions Deploy Infostealer
A supply chain attack on the jscrambler npm package highlights risks to developer credentials.
PolinRider Campaign Jumps From GitHub Into Go and PHP Packages
North Korea-linked PolinRider campaign turned hijacked GitHub accounts into compromised Go modules and Packagist packages with no extra effort required.
Cursor and OpenVSX face extension hijacking risk
Trendyol's security team uncovered a live namespace-squatting attack abusing OpenVSX to hijack extensions in Cursor, VSCodium, Windsurf and other VS Code forks.