In a joint operation, CrowdStrike, Google and Shadowserver Foundation disrupted infrastructure used by the Glassworm ...
A single browser tab, a single click on “Install,” and a cybercriminal group called TeamPCP was inside GitHub’s own house.
As AI-generated code becomes increasingly embedded across enterprise and government systems, cybersecurity startups are ...
The Glassworm botnet, a global operation targeting software developers through the open-source supply chain, was disrupted ...
CrowdStrike, Google and the Shadowserver Foundation worked together to take down a botnet that poisoned over 300 GitHub ...
GlassWorm poisoned 300 GitHub repositories since 2025, enabling supply chain attacks against developers and organizations.
RevEng.AI, a cybersecurity company building the binary-native verification layer for the software supply chain, today announced it has raised a $15 million Series A round led by NATO Innovation Fund ...
Sonatype®, the control plane for agentic software development, today expanded Sonatype Firewall protections to help organizations block malicious open source packages before they enter any repository ...
DeepSWE puts GPT-5.5 atop the AI coding leaderboard while raising new questions about Claude Opus, SWE-Bench Pro, and ...
A proposed class action targets not just Meta and Mark Zuckerberg but the research scientists who allegedly carried out the ...
CISA GitHub credential leak exposed AWS GovCloud admin keys, plaintext passwords, and an RSA private key for six months via a ...