|
You are here |
www.sysdig.com | ||
| | | | |
www.sonatype.com
|
|
| | | | | Sonatype uncovers a wormable npm software supply chain attack compromising over 180 packages, following S1ngularity and Chalk/Debug campaigns. | |
| | | | |
www.endorlabs.com
|
|
| | | | | [AI summary] The article discusses the risks and security measures related to AI code assistants in software development, focusing on supply chain attacks and secure coding practices. | |
| | | | |
socket.dev
|
|
| | | | | Malicious update to @ctrl/tinycolor on npm is part of a supply-chain attack hitting 40+ packages across maintainers | |
| | | | |
thehackernews.com
|
|
| | | Czechia and Germany reveal they were targets of a massive cyber espionage campaign by Russia-linked APT28 hacker group. | ||