In HPE's OneView, malicious actors can inject malicious code from the network without authentication. An update is available.
WatchGuard has warned customers to patch a critical, actively exploited remote code execution (RCE) vulnerability in its ...
Researchers found malicious VS Code extensions and Go, npm, and Rust packages stealing developer data via hidden payloads and exfiltration.
A new campaign involving 19 malicious Visual Studio Code extensions used a legitimate npm package to embed malware in ...
Apache Commons Text is used for processing character strings in Java apps. A critical vulnerability allows the injection of ...
A new malware campaign is A/B testing delivery effectiveness on software developers using malicious VS Code extensions.
Notepad++ version 8.8.9 was released to fix a security weakness in its WinGUp update tool after researchers and users ...
React vulnerability CVE-2025-55182 exploited by crypto-drainers to execute remote code and steal funds from affected websites ...
Static AES keys are enabling attackers to decrypt access tokens and reach remote code execution, triggering urgent patch ...
Thousands of active AWS accounts are vulnerable to a cloud image name confusion attack that could allow attackers to execute codes within those accounts. According to DataDog research, vulnerable ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results