ThreatsDay Bulletin covers AI abuse, poisoned packages, phishing, macOS attacks, SD-WAN flaws, scams, and supply-chain ...
CVE-2026-48907 in the Joomla JCE plugin lets unauthenticated attackers drop PHP web shells with a single crafted request.
Chainguard will use AI to protect open-source code. Athena pools open-source users, developers, and maintainers. Others are ...
Mastra npm packages added easy-day-js malware, exposing developer systems and CI runners to infostealer risks.