A cluster of leased servers disguised as harmless GitHub-style redirects shows how modern crimeware can hide control traffic behind familiar web patterns.
A three-day Dependabot delay and a 14-day PyPI upload cutoff show how software platforms are turning timing into a supply-chain defense.
A new three-day cooldown in Dependabot changes automated updates from instant reaction to release-age vetting, aiming to blunt fast-moving supply chain abuse.
A new default cooldown for Dependabot version updates is designed to slow the automatic adoption of newly released packages and narrow the window for supply-chain abuse.
A default three-day cooldown for version updates changes how quickly automation can promote newly published dependencies into a maintainer’s review queue.
A new default cooldown in Dependabot shows how open-source defenders are using age, not just signatures, to slow risky dependency updates.
A campaign involving compromised GitHub repositories and tainted Packagist releases shows how software delivery systems can be turned against cPanel and WHM operators.
A reported Redis vulnerability hunt by Moonshot AI's Kimi K3 points to a harder question for defenders: how quickly can agentic AI turn software behavior into a reproducible exploit hypothesis?
A credential-hunting campaign is turning GitHub Actions into a distribution layer for probing cPanel systems, showing how trusted automation can be repurposed into offensive infrastructure.
Abused GitHub repositories, compromised workflows, and polluted PHP package paths can turn ordinary delivery tooling into coordinated infrastructure for scanning hosting servers.
A public GitHub collection tied to the name Exploitarium has grown to 204 proof-of-concept files, a reminder that exploit research can quickly become a defender’s triage problem.
A sprawling repository-abuse campaign linked to FakeGit used roughly 7,600 GitHub repos and more than 14 million downloads to push SmartLoader and StealC, showing how platform trust can become malware transport.
A reported package-publishing compromise in the AsyncAPI ecosystem shows how GitHub Actions, npm trust, and generator tooling can become a malware delivery path when release controls are subverted.
A malware campaign used deceptive GitHub repositories and AI-facing registry surfaces to make a loader look like a useful project, showing how quickly trusted setup paths can be turned against developers and agents.
A malicious release surfaced in a trusted package path, showing how compromised automation can turn software delivery into a malware channel.
A modular malware framework is being tied to fake GitHub lures and ClickFix-style prompts, but the real prize is not the device - it is the recovery seed typed into the wrong screen.
A government disclosure tied to AWS GovCloud keys in a public GitHub repository shows how exposed secrets can shift from a housekeeping issue to an urgent identity and access problem.
A staged abuse pattern built on public code hosting, Go, PowerShell, and dead-drop indirection shows how ordinary developer infrastructure can be repurposed for malware delivery.
A newly described jailbreak pattern shows how ordinary IDE interactions can be chained into unsafe AI-generated code, even when a single bad prompt is blocked.
Research tied to signed commits suggests that a trusted-looking hash can change while GitHub still shows “Verified,” forcing teams to rethink what their review process really proves.