Twelve npm packages hijacked via compromised maintainer accounts to exfiltrate secrets using obfuscated scripts.
Drawing lessons from the trials of 2025, some of the maturing methodologies behind those very considerable software supply ...
A potential supply chain attack on GitHub CodeQL started simply: a publicly exposed secret, valid for 1.022 seconds at a time. In that second, an attacker could take a series of steps that would allow ...
Recently, Coinbase, the largest cryptocurrency exchange in the United States, successfully navigated a potential supply chain attack targeting its open-source infrastructure. This article will delve ...
The re-issuance of the 70 billion CRO tokens “permanently” burned in 2021 is “no different from a scam,” according to onchain ...
"Nation-state hacking has become more in your face," says Cleveland – who now works for network intel infosec outfit ExtraHop ...
The endgame of the recent cascading supply chain attack on GitHub was to breach Coinbase, one of the world’s most popular ...
The report originated from Unit 42, the threat intelligence division of Palo Alto Networks, which identified that the attacker had specifically targeted ‘agentkit’, an open-source toolkit managed by ...
Coinbase successfully thwarted a supply chain attack targeting its open-source AI toolkit, agentkit. However, Coinbase’s swift response, along with support from security experts, prevented any serious ...
According to the cybersecurity firms analyzing the incident, the attacker initially tried to compromise the Coinbase ...
More details have come to light on the recent supply chain attack targeting GitHub Actions, including its root cause.
Researchers from Palo Alto Networks said the hackers likely planned to leverage an open source project of the company for ...