|
You are here |
words.filippo.io | ||
| | | | |
securitylabs.datadoghq.com
|
|
| | | | | A look at recent npm supply chain compromises and how we can learn from them to better prepare for future incidents. | |
| | | | |
socket.dev
|
|
| | | | | Socket detected multiple compromised CrowdStrike npm packages, continuing the "Shai-Hulud" supply chain attack that has now impacted nearly 500 packag... | |
| | | | |
grith.ai
|
|
| | | | | A prompt injection in a GitHub issue triggered a chain reaction that ended with 4,000 developers getting OpenClaw installed without consent. The attack composes well-understood vulnerabilities into something new: one AI tool bootstrapping another. | |
| | | | |
thehackernews.com
|
|
| | | Shai-Hulud v2 breached npm and Maven, impacting 28,000+ repos and leaking 11,858 secrets. | ||