SolarWinds releases security updates for Access Rights Manager to fix a high severity vulnerability that could enable unauthenticated remote code execution.
Awan Distribution conducts Huawei eKit Partner Enablement Session covering IP Networks and IT Storage solutions to enhance partner knowledge and opportunities.
A security flaw in Anthropic’s Claude Code GitHub Action allowed attackers to potentially hijack public repositories through a single malicious GitHub issue.
Threat actors compromised popular GitHub Actions workflows to exfiltrate CI/CD credentials through malicious code, raising concerns around software supply chain security and GitHub repository integrity.
A Mini Shai Hulud worm linked to TeamPCP has compromised npm and PyPI packages across TanStack, Mistral AI, Guardrails AI and others, deploying credential stealers, CI/CD exploits, and cross ecosystem propagation techniques.
Security researchers report malicious Docker images and VS Code extensions tied to Checkmarx supply chain compromise, exposing developer credentials, cloud tokens, and CI/CD secrets through multi-stage malware and npm propagation.
OpenAI revokes its macOS app signing certificate after a malicious Axios supply chain attack, confirming no user data compromise while outlining security measures and broader ecosystem risks.
A compromised npm publish token was used to release Cline CLI version 2.3.0, triggering unauthorized installation of OpenClaw on developer systems during an eight hour supply chain attack window.