Popular code generator for TanStack Query hit by supply chain worm 2026-08-28 True True Good riddance, TeamPCP. Now for the hard part. 2026-08-27 True True Software supply chain security requires decisions rather than defaults 2026-08-26 True True Could OpenClaw have actually hacked that Australian gym? We decided to test it. 2026-08-25 True True How Aikido finds more vulnerabilities than Claude Security at half the cost 2026-08-24 True True Shai-Hulud was the best thing to happen to supply chain security 2026-08-24 True True What is CVE remediation in 2026? 2026-08-21 True True We burned 11.7bn tokens to find the best cyber AI model 2026-08-21 True True Two popular Rust crates arrayref and append-only-vec compromised in Supply Chain Attack 2026-08-20 True True Top enterprise SCA tools in 2026 2026-08-14 True True From Hugging Face to Fable: this summer shows AI control matters more than trust 2026-08-13 True True Who was behind the attack? Possibly nobody 2026-08-05 True True Keyv and friends compromised in active Shai-Hulud supply chain attack 2026-08-04 True True Anthropic's Fever Dream: Claude's package that stole real keys 2026-07-31 True True Four incident-response decisions from the Hugging Face breach 2026-07-29 True True Top LLM security tools to protect AI applications 2026-07-24 True True Finding eight high-severity vulnerabilities in NodeBB in six hours 2026-07-22 True True SQL injection isn't dead 2026-07-22 True True The upgrade trap: when upgrading is the wrong answer to a CVE 2026-07-22 True True SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts 2026-07-19 True True Unauthenticated RCE in WordPress core (wp2shell), via SQL injection 2026-07-17 True True Benchmarking 13 AI models on rediscovering known CVEs 2026-07-16 True True The practical checklist for defending against supply chain attacks 2026-07-14 True True AsyncAPI npm packages backdoored via GitHub Actions 2026-07-14 True True How Aikido Intel detects malware and vulnerabilities first 2026-07-13 True True What is a dependency firewall? 2026-07-13 True True Compromised @injectivelabs/sdk-ts exfiltrates wallet keys through fake telemetry 2026-07-09 True True Predicting MongoDB ObjectId continuously in Rocket.Chat 2026-07-06 True True Authentication Bypass in the default configuration phpBB 2026-07-03 True True And another one. GitHub ships break-glass credential revocation 2026-07-01 True True npm now freezes high-impact accounts after risky account changes 2026-06-26 True True Everybody's shipping code they can't read 2026-06-25 True True Compromised GitHub action codfish/semantic-release-action steals CI/CD secrets 2026-06-24 True True Over 140 popular Mastra npm Packages Hit by Supply Chain Attack 2026-06-17 True True Multiple JetBrains IDE plugins caught stealing AI keys 2026-06-16 True True npm v12 delivers one of the biggest security improvements in years 2026-06-11 True True Code is being written everywhere, and the device is the only constant 2026-06-10 True True Compromised Rust crate onering performs code exfiltration 2026-06-10 True True 10 year old critical vulnerability in phpBB affecting tens of millions of users across thousands of forums 2026-06-10 True True Wait, binding.gyp Can Do What? Exploring npm's Weirdest Build System 2026-06-09 True True Why EDR and proxy won’t save you from supply chain malware 2026-06-02 True True Red Hat npm Packages Compromised to Spread a Credential-Stealing Worm 2026-06-01 True True What MDM can't protect on developer machines (and what to do about it) 2026-05-28 True True Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens 2026-05-27 True True Aikido vs XBOW: 58% more vulnerabilities found in independent benchmark 2026-05-27 True True Why developer machines are now the number one target for supply chain attacks 2026-05-26 True True Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer 2026-05-23 True True Google API keys keep working after you delete them 2026-05-21 True True The Wild West of VS Code extensions and how a poisoned extension breached GitHub 2026-05-20 True True GitHub breached via a malicious VS Code extension: why developer devices are the real target 2026-05-20 True True