Hackers hijacked the npm account of the Axios package, a JavaScript HTTP client with 100M+ weekly downloads, to deliver ...
Hackers are exploiting a maximum-severity vulnerability, tracked as CVE-2025-59528, in the open-source platform Flowise for ...
Axios 1.14.1 and 0.30.4 injected malicious [email protected] after npm compromise on March 31, 2026, deploying ...
The biggest story of the week is a new massive supply chain breach, which appears to be unrelated to the previous massive supply chain breaches, this time of the Axios HTTP project. Axios was ...
A 10/10 Flowise bug was patched, but is now being abused in the wild.
CVE-2025-59528 exploited in Flowise for over six months across 12,000+ exposed instances, enabling full system compromise.
On March 13, 2026, The Boeing Company (NYSE:BA) secured a $489.31 million contract from the Naval Air Systems Command. The order covers non-recurring engineering and specialized test kits and aims at ...
Language package managers like pip, npm, and others pose a high risk during active supply chain attacks. However, OS updates ...
The UAT-10608 hacking group is using automated scanning and scripts to exploit React2Shell in a large-scale credential ...