devsecops 16
- SymJack Attack Weaponizes AI Coding Agents as Supply Chain Delivery Systems
- Laravel-Lang Packages Poisoned to Exfiltrate CI Secrets
- Megalodon Supply Chain Attack Infects 5,500+ GitHub Repositories
- npm Launches Staged Publishing with 2FA Gating to Counter Supply Chain Attacks
- Megalodon GitHub Attack Injects Malicious CI/CD Workflows into 5,561 Repos
- Compromised Nx Console 18.95.0 Delivers Credential Stealer to 2.2M VS Code Users
- GitHub Actions Supply Chain Attack Hijacks actions-cool/issues-helper Tags
- node-ipc npm Package Compromised in Supply Chain Attack to Steal Credentials
- Official Checkmarx Jenkins AST Plugin Backdoored with Infostealer
- Unit 42 Maps npm Attack Surface: Wormable Malware, CI/CD Persistence, and Multi-Stage Chains
- Bitwarden npm Supply Chain Attack Attributed to TeamPCP; Shai-Hulud Worm Component Identified
- Checkmarx Supply Chain Attack Compromises Bitwarden CLI and KICS Analysis Tool
- Trail of Bits Releases C/C++ Security Testing Handbook Chapter with LLM Bug-Finding Prompts
- HackerOne Pauses Bug Bounties as AI-Driven Discovery Creates Remediation Backlog
- AWS Launches S3 Files for Shared Bucket Mounts
- Axios Infrastructure Targeted in Coordinated DDoS