Risk
-
Google links Axios npm compromise to suspected North Korean group
Google has linked the Axios npm supply chain compromise to a suspected North Korean group after attackers pushed trojanized package versions that could deliver malware to Windows, macOS and Linux systems.
-
Google Drive ransomware detection enabled by default for paying users
Google said its AI-powered Google Drive ransomware detection is now generally available and on by default for paying users, with sync pausing, alerts and file restoration available after an attack is detected.
-
Anthropic employee error exposed Claude Code source code through npm package
Anthropic said an employee exposed Claude Code source code by including a source map in an npm package. The company called it a packaging error, while experts said such files can reveal logic, prompts and secrets.
-
GIGABYTE Control Center flaw could allow remote file writes on Windows systems
GIGABYTE Control Center has a critical arbitrary file-write flaw that could allow remote unauthenticated attacks on Windows systems with pairing enabled. The vendor has released version 25.12.10.01 to address the issue.
-
Claude-assisted analysis finds Vim and Emacs flaws that can run code when files open
Researchers using Claude found remote code execution flaws in Vim and GNU Emacs that can trigger when a file is opened. Vim has been patched, while the Emacs issue remains unresolved.
-
TrueConf zero-day exploited in attacks on Southeast Asian government entities
A zero-day in TrueConf client video conferencing software was exploited in attacks on Southeast Asian government entities. The flaw let a tampered update run arbitrary code, and the vendor has since patched it in Windows client 8.5.3.
-
Dutch finance ministry takes treasury banking portal offline after breach
The Dutch Ministry of Finance has taken its treasury banking portal offline while investigating a cyberattack detected on March 19. About 1,600 public institutions are unable to view balances online, though payments continue through regular banking channels.
-
Google Vertex AI flaw could expose cloud data, researchers say
Researchers say a Google Cloud Vertex AI flaw could let an attacker abuse AI agent permissions to reach customer data and restricted internal repositories. Google has updated guidance and urged least-privilege controls.
-
CareCloud says hackers accessed patient data in eight-hour breach
CareCloud said hackers accessed one of its electronic health record environments on March 16, exposing patient data and causing an eight-hour disruption. The company is still investigating how many people were affected and what information was taken.
-
OpenAI patches ChatGPT data leak bug, researchers say
OpenAI patched a ChatGPT flaw on February 20, 2026, after researchers said a malicious prompt could leak chat messages, uploaded files and other sensitive data through a hidden DNS-based channel.






