04/08 03:38 AM dev.to Why Your Open-Source Dependencies Are a Ticking Time Bomb (And How to Defuse Them) #open-source #dependencies #vulnerabilities #AI security audit #software supply chain #npm audit
04/06 11:55 PM darkreading.com Axios Attack Shows Social Complex Engineering Is Industrialized #Axios #NPM #social engineering #software supply chain #cyber threat #industrialized attacks
04/06 07:43 PM techcrunch.com North Korea’s hijack of one of the web’s most used open source projects was likely weeks in the making #North Korea #cyberattack #open‑source #malicious updates #state‑sponsored hacking #developer compromise
04/04 08:10 PM dev.to MCP Connector Poisoning: How Compromised npm Packages Hijack Your AI Agent #npm security #axios hijack #remote access trojan #AI development risk #supply‑chain attack #JavaScript libraries
04/04 12:15 AM dev.to Security news weekly round-up - 3rd April 2026 #GitHub #phishing #malware #VS Code #developer security #email notifications
04/03 04:00 PM darkreading.com Source Code Leaks Highlight Lack of Supply Chain Oversight #software supply chain #source‑code leaks #critical infrastructure #cybersecurity #guardrails #oversight
04/03 03:57 PM darkreading.com Chainguard Unveils Factory 2.0 to Automate Hardening the Software Supply Chain #Chainguard #Factory 2.0 #software supply chain #hardening #open‑source security #automation