Trivy Security Scanner GitHub Actions Breached, 75 Tags Hijacked to Steal CI/CD SecretsThe Hacker News·Mar 24, 06:31 UTC · Mar 24, 2026Data breach57
TeamPCP Hacks Checkmarx GitHub Actions Using Stolen CI CredentialsThe Hacker News·Mar 25, 06:34 UTC · Mar 25, 2026Data breachCVE-2026-33634160
Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM ServersThe Hacker News·Jul 23, 11:28 UTC · Jul 23, 2026Data breachCVE-2026-41940160
Popular GitHub Action Tags Redirected to Imposter Commit to Steal CI/CD CredentialsThe Hacker News·May 19, 09:12 UTC · May 19, 2026Data breach57
Chainguard locks down CI/CD with secure-by-default actionsHelp Net Security·Mar 17, 00:00 UTC · Mar 17, 2026Data breach157
Checkmarx supply chain attack impacts Bitwarden npm distribution pathSecurity Affairs·Apr 25, 21:59 UTC · Apr 25, 2026Data breach57
Five Malicious Rust Crates and AI Bot Exploit CI/CD Pipelines to Steal Developer SecretsThe Hacker News·Mar 11, 12:57 UTC · Mar 11, 2026Data breachCVE-2026-28353160
IronWorm and New Miasma Worm Variant Hit npm in Supply Chain AttacksThe Hacker News·Jun 6, 06:23 UTC · Jun 6, 2026Data breach57
Poisoned Ruby Gems and Go Modules Exploit CI Pipelines for Credential TheftThe Hacker News·May 1, 09:43 UTC · May 1, 2026Data breach57
Self-replicating worm hits 180+ npm packages in (largely) automated supply chain attackHelp Net Security·Sep 16, 00:00 UTC · Sep 16, 2025Data breach57
Self-Replicating Worm Hits 180+ npm Packages to Steal Credentials in Latest Supply Chain AttackThe Hacker News·Sep 22, 15:17 UTC · Sep 22, 2025Data breach157
Malicious LiteLLM versions linked to TeamPCP supply chain attackSecurity Affairs·Mar 25, 08:50 UTC · Mar 25, 2026Data breach57
Mini Shai-Hulud Hits Hundreds of npm Packages in AntV EcosystemInfosecurity Magazine·May 20, 15:00 UTC · May 20, 2026Data breach57
Nothing to steal? Let’s wipe. We’re analyzing the Shai Hulud 2.0 npm wormKaspersky Securelist·Dec 4, 15:46 UTC · Dec 4, 2025Data breach157
Self-Propagating Supply Chain Worm Hijacks npm Packages to Steal Developer TokensThe Hacker News·Apr 24, 17:03 UTC · Apr 24, 2026Data breach157
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer MachinesThe Hacker News·Jul 20, 05:15 UTC · Jul 20, 2026Data breach157
Attackers Hijack Red Hat npm Scope to Steal Cloud SecretsInfosecurity Magazine·Jun 2, 10:00 UTC · Jun 2, 2026Data breach57
Self-Replicating Worm Hits 180+ Software PackagesKrebs on Security·Sep 15, 00:00 UTC · Sep 15, 2025Data breach257
AI agent deception moves from theory to reality in UK cyber testsHelp Net Security·Aug 5, 00:00 UTC · Aug 5, 2026Data breach57
Anthropic AI agent faked identities, phished real developers in UK government hacking testThe Record·Aug 5, 13:05 UTC · Aug 5, 2026Data breach157
A Malicious VS Code Extension Just Breached GitHub 's Internal RepositoriesSecurity Affairs·May 20, 08:50 UTC · May 20, 2026Data breach57
Docker Hub Suffers a Data Breach, Asks Users to Reset PasswordThe Hacker News·Apr 27, 11:47 UTC · Apr 27, 2019Data breach57
Akeyless introduces AI Agent Identity Security for safer AI operationsHelp Net Security·Oct 30, 00:00 UTC · Oct 30, 2025Data breach57
Microsoft Restores Some GitHub Repos, Keeps Others Offline as Miasma Probe ContinuesThe Hacker News·Jun 10, 04:50 UTC · Jun 10, 2026Data breach157
LastPass Admits to Severe Data Breach, Encrypted Password Vaults StolenThe Hacker News·Dec 29, 06:12 UTC · Dec 29, 2022Data breach57
GlassWorm Attack Uses Stolen GitHub Tokens to ForceThe Hacker News·Mar 21, 07:03 UTC · Mar 21, 2026Data breach57
Sensitive Data Sharing Risks Heightened as GenAI SurgesInfosecurity Magazine·Jul 17, 12:10 UTC · Jul 17, 2024Data breach57
Handling people's personal data is sensitive businessTroy Hunt·Nov 22, 10:50 UTC · Nov 22, 2016Data breach57
How to Tackle the Top SaaS Challenges of 2023The Hacker News·Feb 24, 14:01 UTC · Feb 24, 2023Data breach57
The FBI will feed hacked passwords directly into Have I Been PwnedThe Record·Dec 12, 00:00 UTC · Dec 12, 2022Data breach57
Former Amazon Employee Found Guilty in 2019 Capital One Data BreachThe Hacker News·Jun 21, 13:05 UTC · Jun 21, 2022Data breach57
35% of exposed API keys still active, posing major security risksHelp Net Security·Aug 13, 00:00 UTC · Aug 13, 2024Data breach57
LexisNexis Risk Solutions says 364,000 impacted by breach involving GitHub dataThe Record·May 28, 16:05 UTC · May 28, 2025Data breach57
It Might Be Our Data, But It’s Not Our BreachKrebs on Security·Aug 11, 18:52 UTC · Aug 11, 2022Data breach57
Supply chains, AI, and the cloud: The biggest failures (and one success) of 2025Ars Technica · Security·Dec 31, 13:15 UTC · Dec 31, 2025Data breach57
Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak DataThe Hacker News·Jun 30, 17:46 UTC · Jun 30, 2026Data breach57
Netflix releases the Stethoscope tool to improve securitySecurity Affairs·Feb 23, 11:48 UTC · Feb 23, 2017Data breach57