LLM-native IDE security risks centre on system controls, according to a study of developer reports. Researchers from York ...
A Mini Shai-Hulud worm spread through more than 400 npm packages, stealing npm, GitHub, cloud, and CI/CD credentials.
Microsoft has added an AI pillar to its Zero Trust Assessment tool and a DevSecOps pillar to its Zero Trust Workshop.
Aikido Security says an npm supply chain attack has infected Keyv packages with a variant of the credential-stealing ...
Alibaba’s Qwen team has released Qwen3.8-Max, a 2.4 trillion parameter model with 95 billion active parameters, pitched at ...
Amazon Threat Intelligence has tied a DPRK hacking group to four separate npm package supply chain attacks, including axios. The company’s security teams have connected the axios, debug, chalk, and ...
New research from VulnCheck complicates warnings that AI-assisted vulnerability discovery is making exploitation more ...
GitHub Actions will hold potentially malicious workflows until a collaborator with write access approves them.
Flash, a security model built into MDASH that finds vulnerabilities at half the cost of alternatives. Redmond announced the ...
A new group of major firms, the Open Secure AI Alliance, are setting out to build open-source AI tools for security defences.
Hugging Face confirmed attackers used an autonomous AI agent to breach its production infrastructure and steal cloud credentials. The platform, which hosts more than 45,000 models and serves over ...
Socket has identified a software supply chain attack involving compromised AsyncAPI npm packages distributing a Miasma botnet loader.