Node.js Patches Multiple Vulnerabilities That Enable DoS Attacks and Process Cra...
The Node.js project released a critical security update on March 24, 2026, for the Long-Term Support (LTS) branch, desig...
Found 109 results
The Node.js project released a critical security update on March 24, 2026, for the Long-Term Support (LTS) branch, desig...
A new malware campaign called GhostClaw is actively targeting macOS users through fake GitHub repositories and AI-assist...
A new piece of malware called RoadK1ll has been found silently converting compromised machines into controllable network...
A malicious npm package named undicy-http has surfaced inside the Node.js developer ecosystem, quietly compromising mach...
A major software supply chain attack has struck the JavaScript ecosystem after threat actors slipped a malicious depende...
A sophisticated backdoor called EtherRAT is actively targeting organizations across multiple sectors by hiding its comma...
Application Performance Monitoring Tools Applications’ performance and availability are monitored, measured, and optimiz...
A highly coordinated social engineering campaign is actively targeting top open-source developers in the Node.js and npm...
A new attack campaign is actively targeting open-source repositories on GitHub by carefully disguising malicious code as...
Threat actors are actively exploiting a maximum-severity remote code execution (RCE) vulnerability in Flowise, an open-s...
A fresh wave of cyberattacks is targeting Windows users through a deceptive social engineering technique called ClickFix...
A new supply chain attack has surfaced targeting software developers who work with AI coding tools. On March 20, 2026, a...