indexed-btree: The npm Malware That Waited for a Library Call
Checkmarx found malicious code hidden in an npm library method rather than an install script. Here's what the trigger means for dependency review and incident response.
In-depth red team tactics, blue team strategy — and privacy-first security tools that run entirely in your browser. No accounts. No telemetry. No data leaves your machine.
Checkmarx found malicious code hidden in an npm library method rather than an install script. Here's what the trigger means for dependency review and incident response.
The Nightmare Eclipse identity reveal is a useful test of how organizations handle departing experts, residual access, institutional knowledge, and vulnerability disclosure.
A joint law-enforcement advisory links fake technical interviews to 30,000 infected devices. The practical boundary is where an interview project runs.
ShinyHunters says it stole FBI personnel and applicant data. The FBI is investigating activity affecting FBIjobs.gov, while the claimed scale and PeopleSoft zero-day remain unverified.
Rapuncel pairs fake GitHub downloads with a signed driver used to kill security processes. What defenders should monitor and why driver controls matter.
Autonomous AI agents are already inside enterprise environments — and most security teams have no idea what they're doing. Here's what attackers exploit and how to defend against it.
Google GTIG's May 2026 report documents a turning point: state actors now use AI to write zero-day exploits, build self-navigating backdoors, and poison the AI supply chain itself.