Incident$500k Lost to a Malicious IDE Extension
A developer installed what seemed to be a legitimate Solidity language extension for Cursor IDE. Within hours, their cryptocurrency wallet was drained of $500,000. The malware spread through the Open
Expert perspectives on application security, compliance, and emerging threats
IncidentA developer installed what seemed to be a legitimate Solidity language extension for Cursor IDE. Within hours, their cryptocurrency wallet was drained of $500,000. The malware spread through the Open
IncidentWhat Happened In early 2025, two critical vulnerabilities in NGINX emerged within weeks of each other, both with CVSS v3x scores of 8.1. CVE-2026-42945, known as NGINX Rift, allows remote code executi
IncidentA critical authentication bypass in Gitea s container registry exposed private images to unauthorized users across more than 30,000 deployments worldwide. No credentials were needed, leaving what team
IncidentOn May 20, 2026, Drupal disclosed CVE-2026-9082 , a critical SQL injection vulnerability with a CVSS score of 9.8. Two days later, CISA added it to the Known Exploited Vulnerabilities catalog. This vu
Get weekly security insights and compliance updates delivered to your inbox.
IncidentWhat Happened On August 21, 2024, an attacker merged a pull request that altered the GitHub Actions workflow for the Nx monorepo toolchain, compromising the CI/CD pipeline. This led to the publication
IncidentOn July 19th, 2024, maintainers of eslint-config-prettier discovered their package had been compromised. Attackers published malicious versions containing credential-stealing malware. With 30,000,000
IncidentOn September 8th, an attacker compromised the npm account of ~qix, a prolific open source maintainer, through a phishing attack. The attacker injected malicious code into widely-used npm packages, red
IncidentWhat Happened In November 2025, researchers detected a surge in NPM package publications. Thousands of packages appeared within a 48-hour period, all following similar naming patterns and structural t
IncidentWhat Happened On September 15, 2025, attackers published malicious versions of ngx-bootstrap and ng2-file-upload to the npm registry. These compromised packages were designed to exfiltrate cloud crede
IncidentWhat Happened Between late 2024 and early 2025, a worm named SHA1-Hulud infiltrated the npm ecosystem through trojanized packages with hidden preinstall scripts. Snyk identified over 600 compromised n
IncidentWhat Happened On May 22, 2026, at 8:20 p.m. UTC, attackers launched a coordinated supply chain attack across three major package registries. The TrapDoor operation deployed 34 malicious packages spann
IncidentYour fraud detection system just made 847 LLM calls to process a single transaction. The request timed out. Your observability dashboard shows nothing unusual. Welcome to multi-agent system failure in
IncidentOver 700 websites using Ghost CMS were compromised in February and March 2026 due to CVE-2026-26980, a critical SQL injection vulnerability in the platform s Content API. Attackers exploited this flaw
IncidentOverview of the Issue This analysis explores the pitfalls when security teams deploy AI-powered vulnerability scanners without understanding their limitations. OpenHack, an MIT-licensed tool by Hadria
IncidentWhat Happened CVE-2025-55182 enables unauthenticated remote code execution through unsafe deserialization in React Server Components (RSC). Security researcher Lachlan Davidson reported the vulnerabil
IncidentThe Challenge of AI-Accelerated Development Your development team is moving fast with tools like GitHub Copilot or Cursor, shipping features in hours instead of days. However, this speed comes with ri