A reported compromise in the Jscrambler package shows how install-time code can turn developer machines and CI pipelines into high-value targets for cloud and wallet secrets.
A demonstrated image-based prompt injection shows how a harmless-looking file can steer an AI coding workflow toward sensitive repository data.
A reported Vidar technique shows how browser hardening can push infostealers toward live Windows process abuse instead of simple file theft.
A macOS-focused intrusion campaign attributed to Sapphire Sleet puts the spotlight on a familiar cybercrime prize: secrets that can be reused far beyond one laptop.
Edamame is pitching runtime verification for coding agents, a sign that AI security is moving from prompt filtering to watching what autonomous tools actually do on a machine.
A large repository campaign shows how CI files can become the real target when attackers aim for credentials, tokens, and trust in the build pipeline.
يمكن لناشر حزمة مخترق في منظومة JavaScript أن يحوّل عمليات التثبيت الروتينية إلى مسار لسرقة الأسرار، مع تحمّل أنظمة CI/CD أعلى مستوى من المخاطر.
يُقال إن GitHub Action تابعًا لجهة خارجية أُعيد توجيهه عبر وسوم قابلة للتغيير، ما حوّل اعتمادًا روتينيًا في سير العمل إلى مسار لتنفيذ التعليمات البرمجية وسرقة أسرار CI/CD.
يكشف اختراق مستمر لـ 84 حزمة npm ضمن منظومة TanStack كيف يمكن لاعتماد مُلوَّث أن يحوّل عمليات البناء الآلية إلى هدف عالي القيمة لسرقة الاعتمادات.
أداة لسرقة الاعتمادات يُقال إنها وصلت عبر حزمة برمجية تسلط الضوء على خطوط أنابيب البناء، حيث قد يكون لإصدار سيئ واحد أثر أكبر من التطبيق الذي يشغّله.