Rust is a technology platform tracked across 22 threat clusters and 25 intelligence report mentions on ThreatCluster. First observed November 4, 2025; most recent activity July 23, 2026.
Google has issued emergency updates to address the eighth zero-day vulnerability in Chrome for 2025. The flaw, identified as 466192044, was actively exploited in the wild, prompting the company to roll out fixes for…
Google has issued an emergency update to address a high-severity zero-day vulnerability, CVE-2025-13223, in its Chrome browser. This flaw, linked to the V8 JavaScript engine, allows attackers to execute arbitrary code…
A malicious npm package named @validate-sdk/v2, introduced through Anthropic’s Claude Opus AI model, has been linked to a breach in the open-source crypto trading project openpaw-graveyard. This malware, dubbed…
Google has issued an emergency update to address a zero-day vulnerability in Chrome that is actively being exploited. This patch affects approximately 2 billion Chrome users, highlighting the ongoing challenges faced by…
On July 11, 2026, multiple malicious versions of the jscrambler npm package were published, exploiting a compromised npm publishing credential. The affected versions (8.14.0, 8.16.0, 8.17.0, 8.18.0, and 8.20.0) included…
Microsoft's Threat Intelligence unit has issued a warning about a cyber campaign targeting cryptocurrency investors and software developers through compromised npm packages. The malware, embedded in two specific…
On May 2, 2026, the Zcash Foundation announced the release of Zebra version 4.4.0, addressing multiple critical security vulnerabilities in its Rust-based node implementation. This update comes in response to a record…
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
A report by OX Security has identified a critical vulnerability in the Model Context Protocol (MCP) developed by Anthropic, potentially exposing over 200,000 AI servers to remote code execution. The flaw lies in the…
A critical vulnerability, CVE-2026-45829, in ChromaDB allows unauthenticated attackers to execute arbitrary code on exposed servers. This flaw affects the FastAPI server of the open-source vector database, which is…