1.
2.
'No way to prevent this,' says only package manager where this regularly happens
(news.ycombinator.com)
3.
Popular node-ipc npm package compromised to steal credentials
(bleepingcomputer.com)
4.
Checkbox Assessments Aren't Fit to Measure Risk
(darkreading.com)
5.
JDownloader site hacked to replace installers with Python RAT malware
(bleepingcomputer.com)
6.
DAEMON Tools devs confirm breach, release malware-free version
(bleepingcomputer.com)
7.
8.
Shai-Hulud Themed Malware Found in the PyTorch Lightning AI Training Library
(news.ycombinator.com)
9.
Dependency cooldowns turn you into a free-rider
(news.ycombinator.com)
10.
How the Trivy supply chain attack harvested credentials from secrets managers
(news.ycombinator.com)
11.
12.
13.
14.
Widely used Trivy scanner compromised in ongoing supply-chain attack
(arstechnica.com)