Supply chain attacks are evolving faster than defenders can respond with one-off controls. Every week brings another variation of the same basic pattern: an infected package, a compromised download, a ...
The software supply chain has had a brutal run. In the past few months, we’ve seen attacks against Axios, Trivy, LiteLLM, SAP, Vercel, and a new Mini Shai-Hulud campaign that has impacted a long list ...
GitGuardian is introducing Developer Endpoint Protection, extending its secrets and non-human identity (NHI) security platform coverage to developer workstations. After 12 months of supply-chain ...
Several AI coding assistants were tricked into facilitating developer machine hacking via an attack technique that has been ...
Attackers are realizing that instead of hacking a hardened server, they can just trick one developer into installing a malicious plugin to steal all the keys to the kingdom. I spent the first week of ...