Malicious npm packages abuse dependency confusion to profile developer environments
A dependency confusion campaign leveraged 33 malicious npm packages to collect reconnaissance data from developer and build environments. This report
Read More03-01
A dependency confusion campaign leveraged 33 malicious npm packages to collect reconnaissance data from developer and build environments. This report
Read MoreMicrosoft is named a Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. The post Microsoft is named a
Read MoreIn March 2026, the Wordfence Bug Bounty Program received 1718 vulnerability submissions from our growing community of security researchers working
Read MoreAuthorities dismantle Russian-aligned hosting firm, FBI warns of in-person data thefts, and TrapDoor steals credentials via software supply chain attack.SentinelOneRead
Read MoreWe analyze how fake IPTV apps gain control of Android devices, abuse screen access features, and steal credentials, cash, and
Read MoreWhat a blocked alert in Microsoft Defender or Sentinel can still teach your SOC — and how to turn it
Read MoreWhat are the main risks for container environments: vulnerabilities, supply chain attacks, configuration errors; how to improve container security and
Read MoreThe Mini Shai-Hulud campaign used malicious npm packages to target cloud and CI/CD credentials across developer environments. This report details
Read MoreOn March 24th, 2026, we received a submission for an Unauthenticated Administrator Account Creation vulnerability in WP Maps Pro, a
Read MoreLast week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were
Read More