IncidentTwo npm Packages Hijacked in One Week
On January 13, 2025, AsyncAPI discovered that several of its npm packages had been compromised and were distributing malware. Three days later, Jscrambler reported a similar incident affecting its pac
Expert perspectives on application security, compliance, and emerging threats
IncidentOn January 13, 2025, AsyncAPI discovered that several of its npm packages had been compromised and were distributing malware. Three days later, Jscrambler reported a similar incident affecting its pac
IncidentOn July 14, a misconfigured GitHub Actions workflow turned AsyncAPI s npm packages into a distribution channel for credential-stealing malware. The attack lasted just over four hours, but the packages
IncidentThousands of organizations have been shipping vulnerable software, treating security as a post-development checkbox rather than an integrated practice. NIST SP 800-218 Version 1.1 was developed becaus
IncidentOn January 17, 2025, Gitea maintainers disclosed CVE-2026-20896, a critical authentication bypass in their Docker images. This flaw allows anyone to send a crafted HTTP header and gain admin access to
Get weekly security insights and compliance updates delivered to your inbox.
IncidentOverview The official Node.js Docker image from Docker Hub contains 567 vulnerable system libraries in its base layer. This is not due to an exploit or breach—it s the default state of one of the most
IncidentOn December 11, 2019, security researcher Daniel Ruf disclosed a vulnerability that allowed any malicious npm package to overwrite arbitrary files on your system during installation. No exploit code w
IncidentWhat Happened On February 9, 2021, security researcher Alex Birsan disclosed a dependency confusion attack that compromised build systems at 35 organizations, including major technology companies. The
IncidentWhat Happened On January 18, 2022, security researchers disclosed CVE-2022-24348 , a directory/path traversal vulnerability in Argo CD, a continuous delivery platform used to automate Kubernetes deplo
IncidentWhat Happened Socket discovered 19 compromised packages on PyPI, downloaded hundreds of thousands of times, delivering malware designed to steal developer credentials. These packages targeted scientif
IncidentOn December 18, 2024, security researchers disclosed a vulnerability in Microsoft Visual Studio Code that allowed attackers to steal GitHub OAuth tokens with a single user click. This attack exploited
IncidentWhat Happened Imperva researchers discovered two command injection vulnerabilities in Snyk s CLI and IDE plugins, both rated CVSSv3 5.8. These flaws allowed attackers to execute arbitrary code when de
IncidentA compromised Red Hat employee GitHub account led to malicious code being published across at least 32 npm packages under the @redhat-cloud-services namespace. These packages, with roughly 80,000 comb
IncidentWhat Happened Between April and May 2026, attackers compromised Red Hat s GitHub credentials and injected malicious code into npm packages maintained by the company. The malware, dubbed Miasma: The Sp
IncidentWhat Happened Three years after Log4Shell was disclosed, 21% of companies still run projects with this critical vulnerability. Spring4Shell fares worse: 35% of companies haven t patched it. This isn t
IncidentOn December 4, 2024, attackers published malicious versions of Ultralytics, a widely-used Python library for YOLO object detection models, to the Python Package Index (PyPI). The attack exploited GitH
IncidentWhat Happened In early 2024, an attacker with write access to the tj-actions/changed-files repository modified the GitHub Action to expose encrypted secrets in plaintext within workflow logs. This Act