Google Releases New Framework to Prevent Software Supply Chain AttacksThe Hacker News·Jun 18, 10:19 UTC · Jun 18, 2021Data breach57
Google Spices Up Supply Chain Security with SLSA FrameworkInfosecurity Magazine·Jun 18, 10:32 UTC · Jun 18, 2021Industry42
GitLab enhances Security and Governance solution to strengthen software supply chain securityHelp Net Security·Oct 27, 00:00 UTC · Oct 27, 2022Vulnerability42
Miasma Worm Compromises 73 Microsoft GitHub RepositoriesSecurity Affairs·Jun 9, 16:08 UTC · Jun 9, 2026Malware142
Three Ways To Supercharge Your Software Supply Chain SecurityThe Hacker News·Jan 4, 12:13 UTC · Jan 4, 2024Vulnerability142
Google Expands Its Bug Bounty Program to Tackle Artificial Intelligence ThreatsThe Hacker News·Oct 27, 14:38 UTC · Oct 27, 2023Vulnerability42
Chalk: Open-source software security and infrastructure visibility toolHelp Net Security·Oct 3, 00:00 UTC · Oct 3, 2023Tools42
Google Launches OSV-Scanner Tool to Identify Open Source VulnerabilitiesThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2022Vulnerability42
Google Unveils Open Source Project to Improve Software Supply Chain SecurityInfosecurity Magazine·Oct 21, 17:00 UTC · Oct 21, 2022Exploit / PoC57
GUAC - A Google Open Source Project to secure software supply chainSecurity Affairs·Oct 21, 10:15 UTC · Oct 21, 2022Exploit / PoC57
Chainloop: Open-source evidence store and policy engine for the software supply chainHelp Net Security·Aug 10, 00:00 UTC · Aug 10, 2026Policy & legal42
Cybersecurity jobs available right now: March 24, 2026Help Net Security·Aug 6, 12:19 UTC · Aug 6, 2026Vulnerability142
Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code HooksThe Hacker News·Aug 4, 15:03 UTC · Aug 4, 2026Malware142
Compromised AsyncAPI npm Packages Deliver MultiThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Exploit / PoC157
145 Mastra npm Packages Compromised via Hijacked Contributor AccountThe Hacker News·Jun 22, 05:41 UTC · Jun 22, 2026Malware42
For the 2nd time in weeks, Microsoft packages laced with credential stealerArs Technica · Security·Jun 8, 18:34 UTC · Jun 8, 2026Malware42
IronWorm and New Miasma Worm Variant Hit npm in Supply Chain AttacksThe Hacker News·Jun 6, 06:23 UTC · Jun 6, 2026Data breach57
Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential StealerThe Hacker News·May 25, 09:00 UTC · May 25, 2026Malware142
Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer AccountThe Hacker News·May 21, 05:56 UTC · May 21, 2026Malware42
OpenAI hit by supply chain attack linked to malicious TanStack packagesSecurity Affairs·May 16, 09:31 UTC · May 16, 2026Malware42
Chainguard Libraries for JavaScript provides developers with malware-free dependenciesHelp Net Security·Sep 25, 00:00 UTC · Sep 25, 2025Malware42
Google Launches OSS Rebuild to Expose Malicious Code in Widely Used OpenThe Hacker News·Jul 23, 09:28 UTC · Jul 23, 2025Vulnerability42
Google expands bug bounty program to cover AI-related threatsHelp Net Security·Oct 30, 00:00 UTC · Oct 30, 2023Vulnerability42
Google Launches Framework to Secure Generative AIInfosecurity Magazine·Jun 9, 12:00 UTC · Jun 9, 2023Vulnerability42
GUAC 0.1 Beta: Google's Breakthrough Framework for Secure Software Supply ChainsThe Hacker News·May 25, 05:45 UTC · May 25, 2023Vulnerability42
Scribe Security's evidence-based security trust hub validates software integrityHelp Net Security·Oct 26, 00:00 UTC · Oct 26, 2022Vulnerability42
Codenotary Trustcenter v3.0 mitigates risks by sifting through billions of software artifactsHelp Net Security·Oct 21, 00:00 UTC · Oct 21, 2022Vulnerability42
Google Launches GUAC Open Source Project to Secure Software Supply ChainThe Hacker News·Oct 20, 17:09 UTC · Oct 20, 2022Vulnerability42
ActiveState Artifact Repository reduces the risk of securing Python supply chainHelp Net Security·Sep 21, 00:00 UTC · Sep 21, 2022Industry42
Government guide for supply chain security: The good, the bad and the uglyHelp Net Security·Sep 6, 00:00 UTC · Sep 6, 2022Vulnerability42
Codenotary SBOM Operator for Kubernetes provides continuously updated info on software supply chainHelp Net Security·Jun 29, 00:00 UTC · Jun 29, 2022Policy & legal42
Here's a New Tool That Scans Open-Source Repositories for Malicious PackagesThe Hacker News·May 3, 03:59 UTC · May 3, 2022Malware42