Abdullah Brothers & Co. has onboarded FlowHCM to enhance HR operations through a connected platform designed to support workforce management and business growth.
Microtech Inc. has received the Authorized Distributor Certificate from ZKTeco Inc., strengthening their partnership to expand security and smart technology solutions.
GitHub has introduced a default three day cooldown for Dependabot version updates to help reduce the risk of poisoned software packages spreading through supply chains.
Researchers have uncovered the FakeGit campaign using nearly 7,600 malicious GitHub repositories, including AI skills and MCP servers, to distribute SmartLoader and StealC malware.
Security researchers have uncovered malicious npm packages linked to North Korea that impersonate Rollup polyfill tools to deliver remote access malware and steal developer credentials and sensitive data.
Adversa AI has disclosed GuardFall, a shell injection bypass affecting 10 of 11 tested open source AI coding agents, exposing systems to command execution and credential theft risks.
GitHub has updated actions/checkout to block common pwn request attack patterns by default, helping protect repositories from software supply chain threats linked to pull_request_target workflows.
Researchers uncover a malicious Go module impersonating golang.org/x/crypto that steals terminal passwords, installs SSH persistence, and deploys the Rekoobe Linux backdoor.