keyv npm supply chain attack on August 4, 2026 let the Shai-Hulud worm compromise 400-plus packages and more than two billion monthly downloads. The Wave Six payload hid inside AI agent config files ...
Next iteration of the Rust compiler component that enforces rules on references is being enabled on nightly releases for ...
A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. The change makes malicious infrastructure harder to detect while ...
ChainDrop has turned routine software installs into a route for credential theft. The self-propagating worm infected more than 400 npm packages, putting developer laptops, build systems and cloud ...
Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family. The list of affected ...
UTC on Monday, saying it was investigating reports of performance problems across several GitHub services. Within minutes, ...
GitHub's CI/CD layer — the service engineering teams depend on to build, test, and ship software automatically — has accumulated more than fourteen hours of downtime in the past 90 days and has now ...
Cursor launched Origin, a new AI-native code hosting platform, as a major GitHub outage exposed growing risks for engineering teams and intensified the battle over code repositories, AI agents, and ...
Authentication issues lingered as GitHub worked through a sprawling disruption that affected key developer services and enterprise workflows across its platform.