JavaScript is a tool tracked across 34 threat clusters and 31 intelligence report mentions on ThreatCluster. First observed November 5, 2025; most recent activity July 22, 2026.
Google has issued an emergency update to address a high-severity zero-day vulnerability, CVE-2025-13223, in its Chrome browser. This flaw, linked to the V8 JavaScript engine, allows attackers to execute arbitrary code…
A critical vulnerability (CVSS 9.7) in the Cline Kanban server allows any website a developer visits to silently exfiltrate workspace data and inject commands into the AI agent's terminal. This flaw affects version…
A malicious npm package named @validate-sdk/v2, introduced through Anthropic’s Claude Opus AI model, has been linked to a breach in the open-source crypto trading project openpaw-graveyard. This malware, dubbed…
Google has issued an emergency update to address a zero-day vulnerability in Chrome that is actively being exploited. This patch affects approximately 2 billion Chrome users, highlighting the ongoing challenges faced by…
Recent reports indicate that state-linked hackers are leveraging artificial intelligence to enhance their cyber capabilities, posing significant risks to national utilities and intellectual property. Additionally, a US…
The Wikimedia Foundation faced a security incident on March 5, 2026, when a self-propagating JavaScript worm began vandalizing pages and modifying user scripts across multiple wikis, including Wikipedia. The attack…
In March 2026, the EvilTokens phishing kit emerged as a significant threat, allowing cybercriminals to bypass multi-factor authentication (MFA) and compromise Microsoft 365 accounts. This Phishing-as-a-Service (PhaaS)…
On March 12, 2026, important security updates were released for MozillaFirefox and MozillaThunderbird in openSUSE Leap 15.6. The updates address multiple vulnerabilities, including CVE-2026-2757, CVE-2026-2758,…
Chainguard has announced the general availability of Chainguard Libraries for Java, which includes CVE remediation for critical and high-severity vulnerabilities in the Spring Boot ecosystem. This initiative addresses…
In late 2025, a critical vulnerability (CVE-2026-5426) was discovered in the KnowledgeDeliver Learning Management System, allowing unauthenticated remote code execution via ViewState deserialization. This flaw, stemming…