Dutch investigators arrested two suspects as part of a probe into a hosting network allegedly tied to Russian cyber operations and disinformation campaigns.
Authorities across Europe and North America seized infrastructure linked to First VPN, a service widely used by ransomware groups and cybercriminals to conceal attacks and evade law enforcement.
Grafana Labs said a single GitHub workflow token that was not rotated during an emergency response to the TanStack npm supply-chain attack allowed hackers to access the company’s private repositories and steal source code and internal business information.
Security researchers at LayerX say they’ve discovered a cross-site request forgery (CSRF) vulnerability in OpenAI’s ChatGPT Atlas browser that lets attackers inject hidden instructions into the assistant’s persistent memory, instructions that can survive sessions and devices and later trigger code execution or data exfiltration.