A sophisticated software supply chain attack has compromised some of the most widely used npm packages … Critical npm Worm Infects AI Coding ToolsRead more
CI/CD security
IP Leakage Risks Grow as Code Moves Across Modern Development
Software companies once worried about employees physically walking away with sensitive information. Today, intellectual property can … IP Leakage Risks Grow as Code Moves Across Modern DevelopmentRead more
Microsoft Warns Claude Code GitHub Action Flaw Exposes CI/CD Pipeline Secrets
AI-powered coding assistants are rapidly integrating into software development pipelines, but their automated execution layers introduce … Microsoft Warns Claude Code GitHub Action Flaw Exposes CI/CD Pipeline SecretsRead more
Massive npm Supply Chain Attack Targets Red Hat Packages
A large-scale npm supply chain attack has compromised dozens of official packages under the @redhat-cloud-services scope, … Massive npm Supply Chain Attack Targets Red Hat PackagesRead more
TamperedChef Malware Hides Stealth Attacks Inside Signed Apps
One of the most aggressive supply chain attacks in recent memory has struck the developer ecosystem. … TamperedChef Malware Hides Stealth Attacks Inside Signed AppsRead more
Megalodon Attack Injects Backdoors Into 5,500+ GitHub Repositories
One of the most aggressive supply chain attacks in recent memory has struck the developer ecosystem. … Megalodon Attack Injects Backdoors Into 5,500+ GitHub RepositoriesRead more
npm Resets Tokens After “Mini Shai-Hulud” Supply Chain Attack
A large-scale software supply chain attack has forced npm to take unprecedented action, resetting thousands of … npm Resets Tokens After “Mini Shai-Hulud” Supply Chain AttackRead more
GitLab Emergency: New Flaws Allow Session Hijacking and Pipeline Crashes
On May 13, 2026, GitLab issued a series of emergency security updates that every DevOps team … GitLab Emergency: New Flaws Allow Session Hijacking and Pipeline CrashesRead more
vm2 Vulnerabilities Enable Full System Takeover
A critical breakdown in one of the most trusted Node.js sandbox libraries is putting countless applications … vm2 Vulnerabilities Enable Full System TakeoverRead more
Malicious NuGet Packages Compromise 64K+ Developer Systems
A stealthy supply chain attack is quietly spreading through the .NET ecosystem, targeting developers and build … Malicious NuGet Packages Compromise 64K+ Developer SystemsRead more