News

Hackers used the secrets stolen in the recent Nx supply chain attack to publish over 6,700 private repositories publicly.
The leaked token, accidentally embedded by the company’s employee in a public repository, might have provided an attacker ...
At least 18 popular JavaScript code packages that are collectively downloaded more than two billion times each week were ...
A new supply chain attack on GitHub, dubbed 'GhostAction,' has compromised 3,325 secrets, including PyPI, npm, DockerHub, ...
The new variant of Docker-targeting malware skips cryptomining in favor of persistence, backdoors, and even blocking rivals ...
Thousands of secrets such as PyPI and AWS keys, GitHub tokens, and more, were stolen recently during a supply-chain attack ...
This week, one story stands out above the rest: the Salesloft–Drift breach, where attackers stole OAuth tokens and accessed ...