May 29, 2026

VS Code Remote SSH RCE Exposes Developer Workstations

The VS Code Remote SSH RCE vulnerability allows attackers to execute malicious code on developer workstations through compromised remote environments, exposing cloud infrastructure, source code repositories, and DevSecOps pipelines to supply chain compromise risks.
May 30, 2026

GREYVIBE Hackers Use ChatGPT and Gemini for Cyberattacks

GREYVIBE hackers are using ChatGPT and Google Gemini to develop malware and generate phishing content in active cyberattacks targeting Ukraine. This AI-powered campaign signals a dangerous new phase in threat actor capability that every security team needs to understand and prepare for.
June 1, 2026

Famous Chollima Targets PHP Developers via Packagist

Famous Chollima, the North Korean state-sponsored threat group, has hidden malware inside a legitimate Packagist PHP package, targeting developers through fake job interviews and coding tasks. The Famous Chollima Packagist PHP supply chain attack uses blockchain-based command-and-control infrastructure to evade detection and steal cloud credentials, SSH keys, and CI/CD secrets from compromised developer machines.