Finding eight high-severity vulnerabilities in NodeBB in six hours 2026-07-22 True True SQL injection isn't dead 2026-07-22 True True The upgrade trap: when upgrading is the wrong answer to a CVE 2026-07-22 True True SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts 2026-07-19 True True Unauthenticated RCE in WordPress core (wp2shell), via SQL injection 2026-07-17 True True Benchmarking 13 AI models on rediscovering known CVEs 2026-07-16 True True The practical checklist for defending against supply chain attacks 2026-07-14 True True AsyncAPI npm packages backdoored via GitHub Actions 2026-07-14 True True How Aikido Intel detects malware and vulnerabilities first 2026-07-13 True True What is a dependency firewall? 2026-07-13 True True Compromised @injectivelabs/sdk-ts exfiltrates wallet keys through fake telemetry 2026-07-09 True True Predicting MongoDB ObjectId continuously in Rocket.Chat 2026-07-06 True True Authentication Bypass in the default configuration phpBB 2026-07-03 True True And another one. GitHub ships break-glass credential revocation 2026-07-01 True True npm now freezes high-impact accounts after risky account changes 2026-06-26 True True Everybody's shipping code they can't read 2026-06-25 True True Compromised GitHub action codfish/semantic-release-action steals CI/CD secrets 2026-06-24 True True Over 140 popular Mastra npm Packages Hit by Supply Chain Attack 2026-06-17 True True Multiple JetBrains IDE plugins caught stealing AI keys 2026-06-16 True True npm v12 delivers one of the biggest security improvements in years 2026-06-11 True True Code is being written everywhere, and the device is the only constant 2026-06-10 True True Compromised Rust crate onering performs code exfiltration 2026-06-10 True True 10 year old critical vulnerability in phpBB affecting tens of millions of users across thousands of forums 2026-06-10 True True Wait, binding.gyp Can Do What? Exploring npm's Weirdest Build System 2026-06-09 True True Why EDR and proxy won’t save you from supply chain malware 2026-06-02 True True Aikido vs XBOW: 58% more vulnerabilities found in independent benchmark 2026-05-27 True True Why developer machines are now the number one target for supply chain attacks 2026-05-26 True True Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer 2026-05-23 True True Google API keys keep working after you delete them 2026-05-21 True True The complete GitHub Actions security checklist 2026-05-11 True True Mini Shai-Hulud Targets SAP npm Packages With a Bun-Based Secret Stealer 2026-04-29 True True GPT-Proxy Backdoor in npm and PyPI turns Servers into Chinese LLM Relays 2026-04-22 True True Introducing Device Protection: Security for Developer Devices 2026-04-20 True True Multiple Cross-Site Scripting (XSS) Vulnerabilities in Mailcow 2026-04-17 True True Reliable CVE sources in the age of NIST NVD cutbacks 2026-04-16 True True Axios CVE-2026-40175: a critical bug that’s… not exploitable 2026-04-14 True True GlassWorm goes native: New Zig dropper infects every IDE on your machine 2026-04-08 True True Aikido Attack finds multiple 0-days in Hoppscotch 2026-04-08 True True axios compromised on npm: maintainer account hijacked, RAT deployed 2026-03-30 True True CanisterWorm Gets Teeth: TeamPCP's Kubernetes Wiper Targets Iran 2026-03-22 True True TeamPCP deploys CanisterWorm on NPM following Trivy compromise 2026-03-20 True True GlassWorm Hides a RAT Inside a Malicious Chrome Extension 2026-03-18 True True fast-draft Open VSX Extension Compromised by BlokTrooper 2026-03-18 True True Glassworm Strikes Popular React Native Phone Number Packages 2026-03-16 True True Glassworm Is Back: A New Wave of Invisible Unicode Attacks Hits Hundreds of Repositories 2026-03-13 True True How Security Teams Fight Back Against AI-Powered Hackers 2026-03-12 True True The Return of the Invisible Threat: Hidden PUA Unicode Hits GitHub repositorties 2025-10-31 True True Bugs in Shai-Hulud: Debugging the Desert 2025-09-18 True True We Got Lucky: The Supply Chain Disaster That Almost Happened 2025-09-12 True True duckdb npm packages compromised 2025-09-09 True True