A new report out today from cybersecurity company Forcepoint LLC’s X-Labs research team details a supply chain attack that ...
Open source software with more than 1 million monthly downloads was compromised after a threat actor exploited a vulnerability in the developers’ account workflow that gave access to its signing keys ...
GitHub is just the latest victim of TeamPCP, a gang that has carried out a spree of software supply chain attacks that has impacted hundreds of organizations.
GitHub confirms breach of 3,800 internal repos after employee installs poisoned VS Code extension - SiliconANGLE ...
Google says attackers are using AI for zero-day research, malware development, reconnaissance, and access to premium AI tools ...
An attacker pushed a malicious version of the popular elementary-data package Python Package Index (PyPI) to steal sensitive developer data and cryptocurrency wallets. The dangerous release is 0.23.3, ...
If Python developers have one consistent gripe about their beloved language, it tends to be this: Why is it so hard to take a Python program and deploy it as a standalone artifact, the way C, C++, ...
A widely used PyPI package was recently compromised through a malicious update The attack leveraged a GitHub Actions workflow to push infostealer code into a release Maintainers quickly issued a clean ...
Sometime around the last week of May 2026, attackers uploaded poisoned packages to three of the most widely used software ...
A Microsoft-branded beanie at the company store at the tech giant’s Redmond, Wash., headquarters. (GeekWire File Photo / Todd Bishop) Microsoft employees eligible for the company’s first-ever ...
Some Microsoft employees will be offered a package of healthcare, cash, and stock vesting if they voluntarily retire. Some Microsoft employees will be offered a package of healthcare, cash, and stock ...