Incident1.8M Malicious Packages in Six Months
What Happened By the end of Q2 2026, Sonatype Research logged 1.8 million malicious packages across public registries. This wasn t a single sophisticated attack. It was industrial-scale pollution of t
Expert perspectives on application security, compliance, and emerging threats
IncidentWhat Happened By the end of Q2 2026, Sonatype Research logged 1.8 million malicious packages across public registries. This wasn t a single sophisticated attack. It was industrial-scale pollution of t
GeneralYour vendor just sent you an SBOM. You need to know if it s actually useful or just compliance theater. CISA updated their SBOM guidance to require information for all components with no minimum depth
IncidentWhat Happened In early 2025, Wiz security researchers disclosed GhostApproval, a vulnerability affecting six major AI coding assistants: Amazon Q Developer, Google Antigravity, Cursor, Codeium, JetBra
ResearchThe Challenge Your compliance team just finished mapping your organization s software dependencies. The audit revealed something uncomfortable: seventeen of your critical libraries are maintained by s
Get weekly security insights and compliance updates delivered to your inbox.
IncidentOn December 20, 2024, attackers compromised the GitHub repository for Injective Labs SDK and published a malicious npm package designed to steal cryptocurrency wallet private keys. The malicious versi
GeneralYour build broke this morning. Not because of a bug or a failed test, but because npm 12 now requires your explicit permission to run install scripts in your dependency tree. Welcome to the new defaul
IncidentYour AI coding assistant just suggested a package that doesn t exist. You accept the suggestion. Moments later, malware is running on your machine. This isn t theoretical. Researchers at Tel Aviv Univ
IncidentFederal agencies have just 72 hours to patch a critical authentication bypass in Langflow, the open-source AI workflow framework. CVE-2026-55255 is being actively exploited by threat actors to steal d
IncidentWhat Happened Attackers are actively exploiting CVE-2026-55255 , an Insecure Direct Object Reference (IDOR) vulnerability in Langflow s /api/v1/responses endpoint. This flaw allows anyone to execute w
ResearchYour security scanning tool flags a malicious commit. You block it by hash. Two hours later, the same code appears under a different hash with GitHub s green Verified checkmark intact. The signature d
IncidentYour security tooling just became an attack vector. Researchers have demonstrated a proof-of-concept attack called Friendly Fire that turns AI coding agents into unwitting accomplices. Tools like Anth
IncidentWhat Happened Noma Security discovered GitLost, a prompt injection attack exploiting GitHub s preview Agentic Workflows to leak private repository data. The attack is simple: an attacker submits a cra
GeneralScope This guide covers how to detect, prevent, and respond to malicious packages targeting payment integration SDKs on npm and PyPI . You ll find steps for validating package authenticity, monitoring
IncidentWhat Happened On June 30, 2026, Adobe released emergency patches for CVE-2026-48282, a path traversal vulnerability in ColdFusion s Remote Development Services (RDS) component. This vulnerability has
ResearchWhen Wiz published the GhostApproval pattern on July 8, they exposed a significant security issue: six major AI coding assistants were allowing malicious repositories to trick developers into granting
ResearchThese questions come from security engineers and developers who ve sat through too many supply chain security is important presentations without getting practical answers. You re building software tha