BleepingComputer·16h ago highGitHub Actions re-enabled with Mini Shai-Hulud payload still active#github-actions#supply-chain#mini-shai-hulud 2 sources in the wild 2 min
Ars Technica · AI·1d agoCourt rules Trump can blacklist Anthropic for refusing to enable Claude features#anthropic#claude#supply-chain 2 min
Ars Technica · AI·1d agoTesla workers balk at training Optimus humanoid robots as replacements#tesla#optimus#humanoid-robots 2 min
The Decoder·1d agoPentagon was right to slap Anthropic with a security supply chain risk label, federal court says#ai-policy#anthropic#court
The Hacker News·1d ago highPlaceholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content#clickfix#pastejacking#social-engineering 4 sources in the wild 4 min
SecurityWeek·1d ago highIn Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure#shinyhunters#cl0p#sckit in the wild 6 min
The Hacker News·1d ago highA Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You#gitlab#supply-chain#ci-cd 6 sources 4 min
Malwarebytes Labs·1d agoKothamine malware uses Tailscale’s tailcat to evade network detection#kothamine#rat#npm in the wild 11 min1
oss-security·2d ago highRe: CVE-2026-95831: Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL#cpan#perl#supply-chainCVE-2026-95831 4 sources in the wild
The Record·2d agoDigital forensics firm with US federal contracts covered up ties to Russia, DOJ alleges#oxygen-forensics#doj#russiaPolicy & legal 2 sources 4 min
Google Threat Intelligence·2d agoProactive Defense: Hardening Code Pipelines and CI/CD Infrastructure#google#ci-cd#supply-chain in the wild 15 min
BleepingComputer·2d ago highMalicious npm packages evade install-script defenses at runtime#checkmarx#ethereum#javascript 8 sources in the wild 3 min
SecurityWeek·2d agoOT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators#ot-security#ics#nist 2 sources 2 min
Help Net Security·3d agoEurope’s technology backbone is becoming a cyber target#enisa#eu#threat-landscape 5 min
DataBreaches.net·3d ago highCanva hacked via vendor’s Salesforce instance; Other customers affected as well#canva#salesforce#extortionRansomware
The Hacker News·3d ago highCompromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI#credential-stealer#exfiltration#github-actions 4 sources in the wild 3 min1
oss-security·3d agoCVE-2026-82331: Apache BuildStream: tar source extraction escape#cve-2026-82331#apache#buildstreamCVE-2026-82331
oss-security·3d agonpm registry keeps removed-version timestamps but drops the reason (Sept 2025 campaign as evidence)#npm#supply-chain#package-registryResearch
CSO Online·3d ago highGitHub App keys can still enable takeovers long after they are forgotten#github#github-apps#leaked-keys 2 sources 4 min
Lobsters · security·3d ago highLatest BGP hijack targets hosting software vendor#bgp-hijack#rpki#tls in the wild 8 min
Help Net Security·4d agoPrismor: Open-source runtime control plane for AI agents#prismor#prismorsec#ai-agents 2 min
Lobsters · security·4d agoGitHub Actions leaking secrets when Miri output is cached#rust#miri#github-actions 4 min
Lobsters · security·4d agoFifty Years of Open Source Software Supply Chain Security#open-source#supply-chain#software-supply-chainResearch
SecurityWeek·4d ago highBigCommerce Data Stolen via Ribon Apps Hack#bigcommerce#ribon#supply-chain 3 sources in the wild 2 min