A new KICS Docker supply chain attack has sent shockwaves through the DevSecOps community—proving once again … KICS Docker Supply Chain Attack: DevOps Secrets at RiskRead more
open source security
NPM Supply Chain Attack Spreads CanisterWorm Malware
A dangerous new npm supply chain attack has emerged, compromising packages linked to Namastex.ai and delivering … NPM Supply Chain Attack Spreads CanisterWorm MalwareRead more
Axios npm Supply Chain Attack Impacts Developers
A major software supply chain attack has struck the JavaScript ecosystem, prompting an urgent alert from … Axios npm Supply Chain Attack Impacts DevelopersRead more
AI-Powered Exploits Are Collapsing the Patch Window
Cybersecurity has always been a race between discovery and exploitation. But that race is changing shape. … AI-Powered Exploits Are Collapsing the Patch WindowRead more
PHP Composer Vulnerability Exposes Developers to Command Injection Attacks
The recent PHP Composer vulnerability has raised serious concerns across the global development and DevSecOps community. … PHP Composer Vulnerability Exposes Developers to Command Injection AttacksRead more
Axios npm Supply Chain Attack: Detection, Risks, and Mitigation Guide
On March 31, 2026, the cybersecurity community faced a major wake-up call when a widely trusted … Axios npm Supply Chain Attack: Detection, Risks, and Mitigation Guide Read more
Backdoored Telnyx Python SDK on PyPI Steals Credentials Across Platforms
A new software supply chain attack has targeted developers after threat actors compromised the Telnyx Python … Backdoored Telnyx Python SDK on PyPI Steals Credentials Across PlatformsRead more
Malicious Axios Package Delivers WAVESHAPER.V2 Backdoor in Supply Chain Attack
A major software supply chain attack has impacted the JavaScript ecosystem after threat actors compromised the … Malicious Axios Package Delivers WAVESHAPER.V2 Backdoor in Supply Chain AttackRead more
CanisterWorm Spreads Through npm Accounts Stealing Tokens
A new supply chain malware campaign called CanisterWorm is targeting the npm ecosystem by compromising publisher … CanisterWorm Spreads Through npm Accounts Stealing TokensRead more
Urgent Linux Warning: TLP Flaw Bypasses Authentication
Linux systems are often trusted for their strong security model—but that trust can be undermined when … Urgent Linux Warning: TLP Flaw Bypasses AuthenticationRead more