📰 Incidents récents
Supply Chain
GitHub Security
Wed, 29 Ju
Tame Dependabot: Group your updates, slow the cadence, keep security fast
Dependabot keeps your dependencies current, but its defaults can flood your repository with pull requests. Here's how grouping updates, slowing the cadence, and keeping security fixes fast cut the noise on a Microsoft open source project.
The post Tame Dependabot: Group your u
Supply Chain
OpenSSF
Wed, 26 Au
Case Study: Conquering the EU Cyber Resilience Act (CRA) with 1,400 Upstream Security Fixes
Ericsson Software Technology successfully met the stringent obligations of the EU Cyber Resilience Act (CRA) by fundamentally shifting to upstream collaboration. Guided by OpenSSF principles, they eliminated private forks and contributed over 1,400 dependency updates and security
Backdoor
TheHackerNews
Wed, 26 Au
Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler
Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC).
Group-IB, in a new analysis published
Backdoor
TheHackerNews
Wed, 26 Au
New SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode
Supply Chain
DarkReading
Wed, 26 Au
'HTTP Terminator' Hunts for Novel Desync Attacks
James Kettle of PortSwigger talks with the Dark Reading News Desk about his AI-powered open source tool, which found new HTTP request-smuggling techniques.
Package Compromise
GitHub Security
Tue, 28 Ju
Disrupting supply chain attacks on npm and GitHub Actions
Explore the changes we've shipped across npm and GitHub Actions over the past few months to disrupt supply chain attack techniques and limit their impact.
The post Disrupting supply chain attacks on npm and GitHub Actions appeared first on The GitHub Blog .
Supply Chain
OpenSSF
Tue, 25 Au
What’s in the SOSS? Podcast #70 – S3E22 Private Forks, CRA Deadlines, and the True Cost of Open Source Compliance with Dave Russo
In this episode of What's in the SOSS, host Sally Cooper and Red Hat's Dave Russo unpack the European Union’s Cyber Resilience Act (CRA). Discover the hidden financial toll of private forks, the crucial legal distinction between manufacturers and open source stewards, and actiona
Package Compromise
TheHackerNews
Tue, 25 Au
24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages
Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages.
"While the malware is simply a single HTML page inside the npm package, and while downl
Supply Chain
DarkReading
Tue, 25 Au
Is Cyber Facing an Affordability Crisis?
As breach costs reach record highs and defense spending nears $240 billion, small businesses are dangerously exposed, threatening supply chain security.
Supply Chain
OpenSSF
Tue, 18 Au
What’s in the SOSS? Podcast #69 – S3E21 Watering the Community Garden: Navigating the EU CRA for Open Source with Roman Zhukov
Supply Chain
OpenSSF
Tue, 11 Au
What’s in the SOSS? Podcast #68 – S3E20 CRA Readiness: Practical Strategies for Open Source Communities with Megan Knight
Join Megan Knight on the What's in the SOSS podcast as she breaks down the upcoming EU Cyber Resilience Act (CRA) and shares practical compliance strategies for open source maintainers and organizations.
Supply Chain
OpenSSF
Tue, 04 Au
What’s in the SOSS? Podcast #67 – S3E19 Funding the Future: Community Collaboration and the Spirit of Open Source with Mila Zhou
Supply Chain
Snyk Blog
Tue, 04 Au
A First Look at Evo Agentic AppSec: Agentic Remediation and Malicious Code Defense
Explore Snyk’s first Agentic AppSec capabilities: an autonomous Remediation Agent that fixes vulnerabilities and Malicious Code Defense that blocks risky packages before they ship.
Package Compromise
Snyk Blog
Tue, 04 Au
Inside the keyv npm Compromise: preinstall Malware, Trusted Provenance, and IDE Hooks
keyv 6.0.0 and ten related npm releases shipped install-time malware. See affected versions, hashes, detection steps, and safe remediation order.
Supply Chain
BleepingComputer
Thu, 27 Au
Australia arrests alleged TeamPCP hackers behind supply-chain attacks
Australian authorities have arrested and charged two young men accused of being part of the TeamPCP hacking group linked to a string of far-reaching developer supply chain attacks. [...]
Supply Chain
TheHackerNews
Thu, 27 Au
Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks
The Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences over their alleged role in TeamPCP, the cybercrime group behind the March 2026 compromise of the open-source security scanners Trivy and Checkmarx KICS and the AI gatew
Backdoor
DarkReading
Thu, 27 Au
Chinese Routers Sold Worldwide Contain Backdoors
An untold number of ZBT routers sold around the world as white-label products come with several implants built by the manufacturer.
Supply Chain
GitHub Security
Thu, 13 Au
What 50 open source projects taught us about security in the AI era
See how the open source projects in Session 4 of the GitHub Secure Open Source Fund combined AI-assisted workflows, maintainer expertise, GitHub security tools, expert guidance, and funding to improve project security.
The post What 50 open source projects taught us about sec
Package Compromise
GitHub Security
Thu, 06 Au
How we took malware advisories beyond npm
GitHub malware advisories no longer stop at npm. Here's how we wired OpenSSF's malicious-packages data into the Advisory Database, and why we built the pipeline paranoid.
The post How we took malware advisories beyond npm appeared first on The GitHub Blog .
Supply Chain
TheHackerNews
Mon, 24 Au
Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt
If your developers are using AI coding tools, you are probably already seeing the upside: faster development, more code, and less time spent on routine work.
The harder part is what comes after. AI can also introduce open-source packages at a pace your security team was never bu
Supply Chain
TheHackerNews
Mon, 24 Au
⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet.
That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit work cheaper, and researchers keep finding attacks t
Backdoor
TheHackerNews
Fri, 28 Au
APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations
Cybersecurity researchers have flagged a fresh set of campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026.
These campaigns, per Recorded Future Insikt Group, have led to the deployment of a p