A sophisticated software supply chain attack has compromised some of the most widely used npm packages … Critical npm Worm Infects AI Coding ToolsRead more
developer security
Claude Code Activity Raises Security Concerns After Reverse Tunnel and Persistence Discovery
A new investigation into Claude Code security risk has sparked debate across the cybersecurity community after … Claude Code Activity Raises Security Concerns After Reverse Tunnel and Persistence DiscoveryRead more
Hidden Web Text Can Trigger AWS Kiro RCE
A newly disclosed AWS Kiro vulnerability shows how a hidden line of text on a webpage … Hidden Web Text Can Trigger AWS Kiro RCERead more
Google Blocks Unrestricted Gemini API Keys After Billing Abuse Surge
Google is tightening Gemini API security after a surge in abuse cases where exposed API keys … Google Blocks Unrestricted Gemini API Keys After Billing Abuse SurgeRead more
OWASP CVE Lite CLI Brings Developer-First Vulnerability Scanning to the Terminal
A new open-source tool is reshaping how developers approach application security. The OWASP CVE Lite CLI … OWASP CVE Lite CLI Brings Developer-First Vulnerability Scanning to the TerminalRead more
Massive npm Supply Chain Attack Targets Red Hat Packages
A large-scale npm supply chain attack has compromised dozens of official packages under the @redhat-cloud-services scope, … Massive npm Supply Chain Attack Targets Red Hat PackagesRead more
North Korean Hackers Exploit Packagist to Target PHP Developers
A sophisticated software supply chain attack linked to the Famous Chollima Packagist attack has exposed a … North Korean Hackers Exploit Packagist to Target PHP DevelopersRead more
npm Resets Tokens After “Mini Shai-Hulud” Supply Chain Attack
A large-scale software supply chain attack has forced npm to take unprecedented action, resetting thousands of … npm Resets Tokens After “Mini Shai-Hulud” Supply Chain AttackRead more
Poisoned IDE Extensions: Lessons from the 2026 GitHub Supply Chain Attack
The modern developer workspace has become the frontline of enterprise cyber warfare. Integrated Development Environments (IDEs), … Poisoned IDE Extensions: Lessons from the 2026 GitHub Supply Chain AttackRead more
Critical Vulnerability in Cline AI Agent Allows Remote Code Execution
A serious security flaw has been uncovered in the Cline Kanban server that puts developers’ workspace … Critical Vulnerability in Cline AI Agent Allows Remote Code ExecutionRead more