1.
2.
Polymarket customers lose $3 million in supply-chain attack
(bleepingcomputer.com)
3.
OptinMonster WordPress plugin hacked in CDN supply-chain attack
(bleepingcomputer.com)
4.
New IronWorm malware hits 36 packages in npm supply-chain attack
(bleepingcomputer.com)
5.
6.
Dozens of Red Hat packages backdoored through its official NPM channel
(arstechnica.com)
7.
Red Hat npm packages compromised to steal developer credentials
(bleepingcomputer.com)
8.
GitHub introduces staged publishing and new install-time controls for NPM
(news.ycombinator.com)
9.
10.
SecurityScorecard Snags Driftnet to Level Up Threat Intelligence
(darkreading.com)
11.
Postmortem: TanStack NPM supply-chain compromise
(news.ycombinator.com)
12.
Postmortem: TanStack npm supply-chain compromise
(news.ycombinator.com)
13.
14.
DAEMON Tools trojanized in supply-chain attack to deploy backdoor
(bleepingcomputer.com)
15.
16.
17.
19.
AI has suddenly become more useful to open-source developers
(news.ycombinator.com)
20.
Opinion | Anthropic and Hegseth Need a Truce
(feeds.content.dowjones.io)
21.
22.
24.
Trivy supply-chain attack spreads to Docker, GitHub repos
(bleepingcomputer.com)
25.
AppsFlyer Web SDK hijacked to spread crypto-stealing JavaScript code
(bleepingcomputer.com)
26.
27.
28.
Anthropic’s Pentagon Battle Matters to Every Business
(feeds.content.dowjones.io)
29.
30.
Pentagon Formally Labels Anthropic Supply-Chain Risk
(news.ycombinator.com)