BitBucket is a tool tracked across 8 threat clusters and 15 intelligence report mentions on ThreatCluster. First observed November 25, 2025; most recent activity June 17, 2026.
Void Dokkaebi, a North Korean threat actor, has escalated its malware distribution tactics by using fake job interviews to compromise software developers. This campaign, known as the 'Contagious Interview,' targets…
The Secure Login (2FA) plugin for Atlassian Jira, Confluence, and Bitbucket has a serious broken access control vulnerability. This flaw allows attackers with valid user credentials to bypass multi-factor authentication…
On May 20, 2026, GitHub confirmed a significant security breach involving a poisoned Visual Studio Code (VS Code) extension that compromised an employee's device. The attack, attributed to the TeamPCP hacking group,…
Cybercriminals are exploiting the popularity of Battlefield 6 by distributing malware through pirated game versions and fake cheat programs. Bitdefender has warned gamers to avoid these downloads, which are prevalent on…
The European Space Agency (ESA) has confirmed a breach involving servers outside its corporate network. The compromised servers contained unclassified information related to collaborative engineering activities. ESA is…
Microsoft has identified a coordinated campaign targeting software developers through malicious repositories disguised as legitimate JavaScript projects and technical assessments. The attackers used carefully crafted…
Sonatype introduces Golden Pull Requests to automate the remediation of open source vulnerabilities. This method streamlines the traditional manual process of addressing security issues in software dependencies. By…
Hackers are targeting JavaScript developers by seeding malicious repositories that appear legitimate. Microsoft reported that these repositories exploit standard build workflows to execute malicious JavaScript in…