Socket and Endor Labs discovered a new TeamPCP campaign leading to the delivery of credential-stealing malware ...
OpenAI revoked its macOS signing certificate after a malicious Axios dependency incident on March 31, 2026, preventing ...
Facepalm: GitHub serves as a colossal hub for software development, hosting nearly half a billion code projects created by hundreds of millions of developers worldwide. Given its extensive reach and ...
Language package managers like pip, npm, and others pose a high risk during active supply chain attacks. However, OS updates ...
The typosquatted “@acitons/artifact” package targeted GitHub’s CI/CD workflows, stealing tokens and publishing malicious artifacts under GitHub’s own name. A ...
A critical supply chain attack has compromised the popular JavaScript library axios, leading to developers unknowingly ...