company · 6 records
AWS

CrowdSec Says TanStack npm Attack Led to Copy of GitHub Repositories
CrowdSec reported that an attacker used a former employee's compromised GitHub account to steal 170 private repositories and investor information.

New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing
Researchers have disclosed DDRop, a hardware-based attack that exploits a lack of memory freshness checks in Intel and AMD confidential computing environments.

Shai-Hulud's Reach Just Grew to 469 Credential Locations
The Shai-Hulud infostealer worm has expanded its credential scanning capabilities across 469 locations in developer and CI/CD environments.

Amazon Kiro IDE security vulnerability allows remote command execution
CVE-2026-10591 disclosed: Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remote unauthenticated actors to execute arbitrary commands via crafted instructions

New NadMesh botnet targets exposed cloud credentials and API keys
A new Go botnet named NadMesh is targeting exposed AI and development services to harvest cloud credentials, Kubernetes tokens, and API keys, with operators claiming thousands of compromised AWS keys.

CISA issues directive on actively exploited Langflow remote code execution vulnerability
CVE-2026-0770 disclosed: Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected ins