Attackers hijacked 400+ Arch Linux AUR packages to run a Rust credential stealer, with optional eBPF rootkit support on root ...
An inexperienced hacker managed to compromise over a dozen companies using AI agents to do most of the work, raising real ...
A major Linux package scare just exposed how dangerous trust-based software ecosystems can get when abandoned packages fall ...
Sygnia says Velvet Ant modified Linux PAM and OpenSSH components to steal credentials and maintain stealthy access since 2016 ...
Attackers hijacked over 1,500 packages in Arch Linux's AUR to plant a credential stealer. The official repos are safe, but the trust model took the hit.