GitHub, PyPI add time-based defenses against supply chain attacks
(bleepingcomputer.com)
1.
2.
Attackers Are Learning to Live Off the AI Toolchain
(darkreading.com)
3.
4.
Microsoft patches bug in video game Age of Empires II
(techcrunch.com)
5.
AsyncAPI npm packages infected with credential-stealing malware
(bleepingcomputer.com)
6.
AsyncAPI npm packages infected with credential-stealing malware
(bleepingcomputer.com)
8.
Hackers backdoor Jscrambler npm package with infostealer malware
(bleepingcomputer.com)
9.
Injective SDK on npm infected with cryptocurrency wallet stealer
(bleepingcomputer.com)
10.
11.
'Phantom Squatting': An Emerging AI-Driven Supply Chain Threat
(darkreading.com)
12.
Amazon Q VS Extension Flaw Leads to Cloud Credential Theft
(darkreading.com)
13.
SocGholish Takedown Highlights Malicious TDS Threats
(darkreading.com)
14.
Malicious JetBrains Marketplace plugins steal AI API keys from developers
(bleepingcomputer.com)
15.
16.
AUR packages compromised with Infostealer and Rootkit
(news.ycombinator.com)
17.
Malicious npm packages detected across Red Hat Cloud Services
(news.ycombinator.com)
18.
After fixing a family friend’s phone, I realized Google Play Protect is not doing enough
(androidauthority.com)
19.
GrapheneOS closes an Android VPN loophole before Google does (Updated: Google statement)
(androidauthority.com)
21.
Fresh Wave of GlassWorm VS Code Extensions Slices Through Supply Chain
(darkreading.com)
22.
RedSun: System user access on Win 11/10 and Server with the April 2026 Update
(news.ycombinator.com)
23.
24.
Bad influence: LLMs can transmit malicious traits using hidden signals
(feeds.nature.com)
25.
26.
A new spam policy for “back button hijacking”
(news.ycombinator.com)
27.
A new spam policy for "back button hijacking"
(news.ycombinator.com)
28.
29.
How to Find Out Whether Your Computer Is Part of a Botnet—and What to Do About It
(feeds.content.dowjones.io)
30.
Residential proxies evaded IP reputation checks in 78% of 4B sessions
(bleepingcomputer.com)