Skip to content
Tech News
clear
Topics: Today This Week This Month This Year
1.
Microsoft links Mastra AI supply chain attack to North Korean hackers (bleepingcomputer.com)
2.
AUR Packages Compromised with Infostealer and Rootkit (news.ycombinator.com)
3.
GitHub announces npm security changes to tackle supply-chain attacks (bleepingcomputer.com)
4.
New IronWorm malware hits 36 packages in npm supply-chain attack (bleepingcomputer.com)
5.
Red Hat hit by npm supply‑chain attack - here's how to stay safe (zdnet.com)
6.
Agentic Mfw (news.ycombinator.com)
7.
Dozens of Red Hat packages backdoored through its official NPM channel (arstechnica.com)
8.
Dozens of Red Hat packages backdoored through its offical NPM channel (arstechnica.com)
9.
Red Hat npm packages compromised to steal developer credentials (bleepingcomputer.com)
10.
Red Hat npm Packages Compromised to Spread a Credential-Stealing Worm (slashdot.org)
11.
Show HN: DepsGuard – one command to harden NPM/pnpm/yarn/bun/uv configs (news.ycombinator.com)
12.
Malicious npm packages detected across Red Hat Cloud Services (news.ycombinator.com)
13.
NPM packages from Red Hat have been compromised (news.ycombinator.com)
14.
NPM packages from RedHat have been compromised (news.ycombinator.com)
15.
Npm-scan: Modern supply chain security for the npm ecosystem (news.ycombinator.com)
16.
Claude Code – Everything You Can Configure That the Docs Don't Tell You (news.ycombinator.com)
17.
Perplexity launches Bumblebee: How its new read-only dev scanner differs from Chainguard (zdnet.com)
18.
You Should Not Update Your Dependencies (news.ycombinator.com)
19.
Valid certificates, stolen accounts: how attackers broke npm's last trust signal (venturebeat.com)
20.
GitHub introduces staged publishing and new install-time controls for NPM (news.ycombinator.com)
21.
Deno 2.8 (news.ycombinator.com)
22.
Uv is fantastic, but its package management UX is a mess (news.ycombinator.com)
23.
GitHub links repo breach to TanStack npm supply-chain attack (bleepingcomputer.com)
24.
GitHub confirms 3,800 internal repos stolen through poisoned VS Code extension as supply chain worm hits Microsoft’s Python SDK (venturebeat.com)
25.
Grafana breach caused by missed token rotation after TanStack attack (bleepingcomputer.com)
26.
Dumb ways for an open source project to die (news.ycombinator.com)
27.
Dumb Ways for an Open Source Project to Die (news.ycombinator.com)
28.
Show HN: Id-agent – Token efficient UUID alternative for AI agents (news.ycombinator.com)
29.
New Shai-Hulud malware wave compromises 600 npm packages (bleepingcomputer.com)
30.
Mini Shai-Hulud Strikes Again: 314 npm Packages Compromised (news.ycombinator.com)
Today's top topics: prime day amazon samsung android authority openai zdnet apple oracle galaxy ai android 16
View all today's topics →