Attackers published a malicious command-line version of the popular open-source password manager to the npm registry and may ...
A malicious version of the Bitwarden command-line interface (CLI) password manager was briefly distributed via the Node ...
VS Code 1.117 adds bring-your-own model key support for Copilot Business and Enterprise users and introduces a set of chat, agent, terminal, and TypeScript updates.
Three supply chain attacks hit npm, PyPI, and Docker Hub between April 21–23, 2026. All three targeted secrets: API keys, cloud credentials, SSH keys, and tokens from developer environments and CI/CD ...
Hackers have compromised Docker images, VSCode and Open VSX extensions for the Checkmarx KICS analysis tool to harvest ...
Built for a hostile internet: Canonical VP of Engineering on Ubuntu 26.04 LTS ...
Cloudsmith raises a $72M Series C led by TCV and Insight Partners to govern and secure the AI-generated software supply chain.
Checkmarx suffers a second supply chain attack in a month, resulting in hackers injecting credential-stealing malware into ...
Malicious KICS Docker tags and VS Code versions 1.17.0, 1.19.0 enabled data exfiltration, risking exposed infrastructure ...
Yet another npm supply-chain attack is worming its way through compromised packages, stealing secrets and sensitive data as ...
After exclusively sharing details with 9to5Mac last September on ModStealer, a cross-platform infostealer invisible to every major antivirus engine ...
CVE-2026-5752 CVSS 9.3 flaw in Terrarium enables root code execution via Pyodide prototype traversal, risking container ...