pkgradar.com
Flagged-first coverage
18 malicious packages flagged across npm, before their public advisories.
#supplychainsecurity is an active hashtag on Bluesky. In the last 30 days, 31 people shared 95 posts with it β around 3 a day. Activity is down 28% versus the previous week, peaking on Sep 9 with 10 posts.
Tags most often used together with #supplychainsecurity.
pkgradar.com
Flagged-first coverage
18 malicious packages flagged across npm, before their public advisories.
python-basics-tutorial.readthedocs.io
Upload package
Finally, you can deploy the package on the Python Package Index( PyPI) or another index, for example GitLab Package Registry or devpi. For the Python Package Index, you must register with Test PyPI...
pkgradar.com
This week in supply-chain malware
PkgRadar's live view of malicious-package activity across nine ecosystems.
pkgradar.com
Flagged-first coverage
3 malicious packages flagged across npm, before their public advisories.
twp.ai
youtu.be
Emergency DevSec Station drop: NPM Worm in the Wild
www.air.security
Plugin4Shell - Zero Click RCE Vulnerability found in top 4 most popular coding agents, millions of agents affected
Plugin4Shell is a zero-click, high-severity RCE affecting all four major AI coding agents - Claude Code, Codex, Copilot, and Gemini. In this first-of-its-kind AI supply-chain attack, a trusted plugin ...
blog.packagist.com
An Update on Composer & Packagist Supply Chain Security
The last months, and even more so the last weeks, saw an increasing amount of software supply chain attacks targeting open-source ecosystems. A handful of these have hit the PHP ecosystem too, via tak...
www.docker.com
Hardened Images for Everyone | Docker
Security for everyone. Docker Hardened Images are now free to use, share, and build on with no licensing surprises.
twp.ai
youtu.be
Emergency DevSec Station drop: NPM Worm in the Wild
pkgradar.com
This week in supply-chain malware
PkgRadar's live view of malicious-package activity across nine ecosystems.
pkgradar.com
Flagged first: npm [email protected]
PkgRadar flagged this 1 day before MAL-2026-16332 was published. See the dated receipt and static evidence.
pkgradar.com
Flagged-first coverage
18 malicious packages flagged across npm, before their public advisories.
dlvr.it
β‘ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks
A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week. The trouble keeps showing up inside things people already trust: code that takes a bad turn, old payloads coming back, exposed systems, weak checks, fake fixes, and attack paths that look almost too easy. Even the research side is getting messy, with more findings, more automation, and not
blog.rust-lang.org
Be alert: targeted attacks on prominent Rustaceans | Rust Blog
Empowering everyone to build reliable and efficient software.
citizenportal.ai
Incoming council president of the European Union signs framework with the United States on critical minerals supply chains
A framework signed at a brief ceremony commits the United States and Lithuania to jointly identify priority projects and to "mobilize government and the private sector financing within 6 months" to secure supply and processing of critical minerals, which speakers tied to economic and national security.
thehackernews.com
Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents
Four AI coding agents let repository owners swap pinned plugin code; Claude Code and Codex are fixed, while Copilot and Gemini CLI remain unfixed.
pkgradar.com
Flagged first: npm [email protected]
PkgRadar flagged this 29 days before MAL-2026-16255 was published. See the dated receipt and static evidence.
pkgradar.com
Flagged-first coverage
3 malicious packages flagged across npm, before their public advisories.
www.air.security
Plugin4Shell - Zero Click RCE Vulnerability found in top 4 most popular coding agents, millions of agents affected
Plugin4Shell is a zero-click, high-severity RCE affecting all four major AI coding agents - Claude Code, Codex, Copilot, and Gemini. In this first-of-its-kind AI supply-chain attack, a trusted plugin ...
www.crowdsec.net
CrowdSec Statement: Source Code Exposure in May 2026
CrowdSec update on a source code exposure that occurred in May 2026, including the scope, impact, investigation, and security measures taken.
Posts are pulled live from Bluesky and cached briefly. Posts with content labels are hidden.