A sophisticated software supply chain attack has compromised some of the most widely used npm packages … Critical npm Worm Infects AI Coding ToolsRead more
software supply chain
Why Most Critical CVEs Never Get Fixed Properly
Security teams have no shortage of vulnerabilities to investigate. Every day, new CVEs flood vulnerability management … Why Most Critical CVEs Never Get Fixed ProperlyRead more
IP Leakage Risks Grow as Code Moves Across Modern Development
Software companies once worried about employees physically walking away with sensitive information. Today, intellectual property can … IP Leakage Risks Grow as Code Moves Across Modern DevelopmentRead more
How This New 7-Zip Flaw Exposes Your Whole System
A high-severity 7-Zip vulnerability has been disclosed that allows threat actors to achieve arbitrary remote code … How This New 7-Zip Flaw Exposes Your Whole SystemRead more
Malicious NuGet Packages Compromise 64K+ Developer Systems
A stealthy supply chain attack is quietly spreading through the .NET ecosystem, targeting developers and build … Malicious NuGet Packages Compromise 64K+ Developer SystemsRead more
pnpm 11 Turns On Minimum Release Age by Default to Reduce npm Supply Chain Risk
The npm ecosystem has become one of the most targeted environments for supply chain attacks, where … pnpm 11 Turns On Minimum Release Age by Default to Reduce npm Supply Chain RiskRead more
NPM Supply Chain Attack Spreads CanisterWorm Malware
A dangerous new npm supply chain attack has emerged, compromising packages linked to Namastex.ai and delivering … NPM Supply Chain Attack Spreads CanisterWorm MalwareRead more
PHP Composer Vulnerability Exposes Developers to Command Injection Attacks
The recent PHP Composer vulnerability has raised serious concerns across the global development and DevSecOps community. … PHP Composer Vulnerability Exposes Developers to Command Injection AttacksRead more
36 Malicious npm Strapi Packages Used in Targeted Supply Chain Attack
A sophisticated software supply chain attack has been discovered targeting developers using Strapi. Attackers published 36 … 36 Malicious npm Strapi Packages Used in Targeted Supply Chain Attack Read more
Axios npm Supply Chain Attack: Detection, Risks, and Mitigation Guide
On March 31, 2026, the cybersecurity community faced a major wake-up call when a widely trusted … Axios npm Supply Chain Attack: Detection, Risks, and Mitigation Guide Read more