WebNews

Please enter a web search for web results.

NewsWeb

Tech Times
techtimes. com > articles > 317209 > 20/26/0526 > npm-supply-chain-attacks-hit-github-2fa-approval-gate-now-blocks-stolen-ci-tokens. htm

npm Supply Chain Attacks Hit Git Hub: 2 FA Approval Gate Now Blocks Stolen CI Tokens

1+ day, 9+ hour ago  (379+ words) Git Hub calls the new control "proof of presence" " evidence that a real, authenticated human reviewed and approved code before it reached developers. The approval step cannot be completed with automation credentials, Open ID Connect (OIDC) tokens, or any non-interactive…...

Symbols: node.js
Frontier News. ai
frontiernews. ai > news > article > claude-code-under-fire-how-a-poisoned-vs-code-exte-0d4355b1

Claude Code Under Fire: How a Poisoned VS Code Extension Exposed the Supply Chain Weakness

1+ day, 1+ hour ago  (175+ words) What made this attack particularly alarming was its scope and speed. In a single 48-hour window, Team PCP executed coordinated attacks across five different surfaces: Git Hub's statement emphasized that "the activity involved exfiltration of Git Hub-internal repositories only," but…...

Symbols: btc-usd
@Bnk Info Security
bankinfosecurity. com > socket-raises-60m-for-wider-software-supply-chain-defense-a-31785

Socket Raises $60 M for Wider Software Supply-Chain Defense

1+ day, 1+ hour ago  (553+ words) 3rd Party Risk Management, Agentic AI, Application Security A startup led by a former Stanford University lecturer raised $60 million to bring security controls to endpoints, laptops, notebooks and local developer environments. See Also: Know Thy Enemy: Threats to Cyber Resilience "Security…...

Symbols: btc-usd
Amazon Web Services
aws. amazon. com > blogs > security > well-architected-best-practices-for-software-supply-chain-security

Well-architected best practices for software supply chain security

1+ day, 5+ hour ago  (658+ words) There have been multiple notable supply chain attacks using the npm Registry since September: Shai-Hulud, Chalk/Debug, one abusing tea. xyz tokens, and recently axios. Thanks to community efforts involving the Amazon Inspector team, the Open Source Security Foundation, and…...

Symbols: btc-usd
wiz. io
wiz. io > reports > sdlc-security-report-2026

State of SDLC Security 2026 | Wiz

1+ day, 8+ hour ago  (188+ words) How software reuse, automation, and AI are reshaping risk across the SDLC. Across ecosystems, dependency adoption follows a power-law distribution, where a relatively small set of packages appears across a disproportionate share of organizations. As a result, weaknesses in widely…...

Symbols: btc-usd,eth-usd,tsx:csco,nasdaq:smx,nasdaq:codx
AI CERTs News
aicerts. ai > news > trapdoor-supply-chain-hits-npm-pypi-and-crates-io

Trap Door Supply Chain Hits npm, Py PI and Crates. io

1+ day, 9+ hour ago  (512+ words) Unlike prior attacks, Trap Door combines classic credential stealing modules with a novel twist targeting AI coding assistants. Attackers embedded invisible directives inside Cursor rules and Claude config files to hijack trusted workflows. Socket researchers linked 34 distinct package names and…...

Symbols: index.js
guardsix
guardsix. com > blog > quasar-linux-qlnx-a-developer-targeted-linux-rat-and-detection-strategy

Quasar Linux (QLNX): A Developer-Targeted Linux RAT and Detection Strategy

2+ day, 7+ hour ago  (117+ words) Discover how QLNX, targets developer workstations and CI/CD pipelines to execute supply-chain compromises, its tactics, and detection with Guardsix SIEM....

Symbols: btc-usd
Cyber Security News
cybersecuritynews. com > angular-extension-vulnerabilities

Multiple Angular Language Service Extension Vulnerabilities Enable RCE Attacks

1+ day, 4+ hour ago  (409+ words) The vulnerabilities arise from insecure handling of user-controlled input and unsafe configuration loading within the extension. Researchers found that attackers can exploit trusted development workflows, such as opening a project or reviewing source code, to execute arbitrary commands on a…...

Symbols: index.js,cwe-94,cwe-95
Help Net Security
helpnetsecurity. com > 05/26/2026 > detectify-mcp-server

Detectify brings App Sec automation to AI agents with MCP Server and continuous testing

1+ day, 8+ hour ago  (372+ words) Detectify has unveiled the Detectify MCP (Model Context Protocol) Server, a new integration layer that brings Detectify's security testing engines directly into AI-driven development workflows, helping coding agents find and validate exploitable vulnerabilities and interpret attack surface data with greater…...

Symbols: btc-usd,nasdaq:ddog
@Bnk Info Security
bankinfosecurity. com > microsoft-code-editor-flaw-lets-attackers-hijack-developer-pcs-a-31775

Microsoft Code Editor Flaw Lets Attackers Hijack Developer PCs

1+ day, 4+ hour ago  (513+ words) Developers using Microsoft's code editor could hand an attacker full control of their machine by clicking a single install link, with nothing in the confirmation screen to warn them. Microsoft has since patched the flaw. See Also: Know Thy Enemy:…...

Symbols: cwe-22