AISI details AI agent GitHub supply chain attack attempt
The UK AI Security Institute (AISI) has disclosed that agents under evaluation took unsanctioned actions on the internet, including an attempted supply […]
npm supply-chain attack hits 400+ packages and steals developer credentials
A supply-chain attack has affected more than 400 npm packages maintained by unrelated publishers, using compromised package releases to steal developer credentials […]
Microsoft adds AI and DevSecOps pillars to zero trust tools
Microsoft has added an AI pillar to its Zero Trust Assessment tool and a DevSecOps pillar to its Zero Trust Workshop. Development […]
Aikido Security tracks Shai-Hulud npm package infection surge
Aikido Security says an npm supply chain attack has infected Keyv packages with a variant of the credential-stealing Shai-Hulud malware. The security […]
Alibaba Qwen3.8-Max claims 16-day autonomous coding run
Alibaba’s Qwen team has released Qwen3.8-Max, a 2.4 trillion parameter model with 95 billion active parameters, pitched at coding, office work, research, […]
Amazon ties DPRK hackers to axios and three other NPM attacks
Amazon Threat Intelligence has tied a DPRK hacking group to four separate NPM package supply chain attacks, including axios. The company’s security […]
VulnCheck data questions AI vulnerability discovery risk
New research from VulnCheck complicates warnings that AI-assisted vulnerability discovery is making exploitation more dangerous. The vulnerability research firm published its H1 […]
GitHub adds approval checks for suspicious Actions workflows
GitHub has introduced an automatic approval step for certain GitHub Actions workflow runs in public repositories. The measure is intended to stop […]
Microsoft targets vulnerability scanning costs
Microsoft has released MAI-Cyber-1-Flash, a security model built into MDASH that finds vulnerabilities at half the cost of alternatives. Redmond announced the […]
Open Secure AI Alliance aims to open-source AI security defences
A new group of major firms, the Open Secure AI Alliance, are setting out to build open-source AI tools for security defences. […]
Codeberg members vote to reject LLM training and vibe coding
Codeberg members voted to reject LLM training on platform data and to restrict vibe-coded projects hosted on the forge. The German non-profit […]
GitHub Actions abuse turned Packagist repos into scanners
According to Socket, GitHub Actions abuse in Packagist repos ran cPanel scanning from temporary cloud runners. The incident began with malicious development […]