Who was behind the attack? Possibly nobody 2026-08-05 True True Keyv and friends compromised in active Shai-Hulud supply chain attack 2026-08-04 True True Anthropic's Fever Dream: Claude's package that stole real keys 2026-07-31 True True Four incident-response decisions from the Hugging Face breach 2026-07-29 True True Top LLM security tools to protect AI applications 2026-07-24 True True Finding eight high-severity vulnerabilities in NodeBB in six hours 2026-07-22 True True SQL injection isn't dead 2026-07-22 True True The upgrade trap: when upgrading is the wrong answer to a CVE 2026-07-22 True True SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts 2026-07-19 True True Unauthenticated RCE in WordPress core (wp2shell), via SQL injection 2026-07-17 True True Benchmarking 13 AI models on rediscovering known CVEs 2026-07-16 True True The practical checklist for defending against supply chain attacks 2026-07-14 True True AsyncAPI npm packages backdoored via GitHub Actions 2026-07-14 True True How Aikido Intel detects malware and vulnerabilities first 2026-07-13 True True What is a dependency firewall? 2026-07-13 True True Compromised @injectivelabs/sdk-ts exfiltrates wallet keys through fake telemetry 2026-07-09 True True Predicting MongoDB ObjectId continuously in Rocket.Chat 2026-07-06 True True Authentication Bypass in the default configuration phpBB 2026-07-03 True True And another one. GitHub ships break-glass credential revocation 2026-07-01 True True npm now freezes high-impact accounts after risky account changes 2026-06-26 True True Everybody's shipping code they can't read 2026-06-25 True True Compromised GitHub action codfish/semantic-release-action steals CI/CD secrets 2026-06-24 True True Over 140 popular Mastra npm Packages Hit by Supply Chain Attack 2026-06-17 True True Multiple JetBrains IDE plugins caught stealing AI keys 2026-06-16 True True npm v12 delivers one of the biggest security improvements in years 2026-06-11 True True Code is being written everywhere, and the device is the only constant 2026-06-10 True True Compromised Rust crate onering performs code exfiltration 2026-06-10 True True 10 year old critical vulnerability in phpBB affecting tens of millions of users across thousands of forums 2026-06-10 True True Wait, binding.gyp Can Do What? Exploring npm's Weirdest Build System 2026-06-09 True True Why EDR and proxy won’t save you from supply chain malware 2026-06-02 True True Red Hat npm Packages Compromised to Spread a Credential-Stealing Worm 2026-06-01 True True What MDM can't protect on developer machines (and what to do about it) 2026-05-28 True True Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens 2026-05-27 True True Aikido vs XBOW: 58% more vulnerabilities found in independent benchmark 2026-05-27 True True Why developer machines are now the number one target for supply chain attacks 2026-05-26 True True Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer 2026-05-23 True True Google API keys keep working after you delete them 2026-05-21 True True The Wild West of VS Code extensions and how a poisoned extension breached GitHub 2026-05-20 True True GitHub breached via a malicious VS Code extension: why developer devices are the real target 2026-05-20 True True Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again! 2026-05-19 True True Mini Shai-Hulud strikes again: npm worm compromises hundreds of @antv packages 2026-05-19 True True Shadow AI is a fear response, and banning it makes it worse 2026-05-12 True True Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack 2026-05-11 True True The complete GitHub Actions security checklist 2026-05-11 True True Why browser extensions are a major security risk and what you can do about it 2026-05-01 True True Popular PyTorch Lightning Package Compromised by Mini Shai-Hulud 2026-04-30 True True Mini Shai-Hulud Targets SAP npm Packages With a Bun-Based Secret Stealer 2026-04-29 True True Someone published four versions of a fake "tanstack" package in 27 minutes to steal your .env files 2026-04-29 True True It's time to treat browser extensions like supply chain attack vectors 2026-04-24 True True Is Shai-Hulud Back? Compromised Bitwarden CLI Contains a Self-Propagating npm Worm 2026-04-23 True True