A reported Doctor Web finding shows how C++ and C# project files can become a supply-chain attack surface, turning ordinary development workflows into a distribution risk.
The supply-chain risk is no longer only about third-party libraries. If AI is part of the build path, it becomes another upstream source that security teams must be able to inspect, constrain, and prove.
A supply-chain campaign tied to PolinRider shows how package ecosystems can turn routine development work into a high-risk execution path.
Microsoft has released GDK plug-ins for Unreal Engine 5.8 to simplify Xbox PC game development.
A new security-focused explainer on CI/CD pipelines underscores a simple but uncomfortable truth: the systems that move code fastest can also concentrate trust in one place.
Epic Games has put its next engine generation into view, with Rocket League named as the first confirmed title, and that makes the real security story one of migration, tooling, and trust.
UK employees have formed the Rockstar Game Workers Union months before Grand Theft Auto 6's planned November release, a reminder that major software launches are shaped by people, process, and pressure as much as code.
A compromised package publisher in the JavaScript ecosystem can turn routine installs into a path for secret theft, with CI/CD systems bearing the highest risk.
A validation bug in a PHP toolchain turned a routine authentication failure into a secrets-disclosure risk inside CI logs, showing how upstream token changes can ripple into downstream security.
GitLab’s pricing pivot is a warning shot for the rest of DevOps: as agentic tools do more work, the bill stops looking like a per-seat subscription and starts behaving like a metered machine workload.
An ongoing compromise of 84 npm packages in the TanStack ecosystem shows how a poisoned dependency can turn automated builds into a high-value target for credential theft.
A fresh supply-chain wave involving hundreds of malicious package versions shows how quickly routine dependency installs can turn into an enterprise risk.
A rogue Checkmarx-related plugin release on the Jenkins Marketplace shows how quickly CI/CD trust can become an attack surface.
A new build-time control model is trying to spot suspicious behavior where software is assembled, not just in the code that eventually ships.
A malicious Checkmarx Jenkins AST Plugin release shows how a security tool can become part of the attack path when software distribution itself is tampered with.