A breach tied to stored personal data shows how old infrastructure can become a privacy liability long after teams stop thinking about it.
Red Hat's confirmed package compromise is a reminder that software supply chains often fail at identity first, not code.
A compromise tied to GitHub and npm shows how quickly source-control identity problems can turn into package-trust problems, even when the registry itself is not the original target.