
Crypto wallets targeted in widespread hack of npm, GitHub
A phishing campaign against maintainers resulted in malware distribution via Javascript in top open-source packages.
Learn More about Crypto wallets targeted in widespread hack of npm, GitHubA phishing campaign against maintainers resulted in malware distribution via Javascript in top open-source packages.
Learn More about Crypto wallets targeted in widespread hack of npm, GitHubRL’s Ransomware Feed data from the first half of the year shows a jump in early-stage threats like infostealers — and a drop in Trojans.
Learn More about Ransomware 2025: Infostealers on the MarchLearn how ActiveState and ReversingLabs integration automates secure component sourcing, secure software releases, remediation guidance, and policy enforcement.
Learn More about ActiveState and RL: Unlocking Software Supply Chain SecurityLearn how ActiveState and ReversingLabs integration automates secure component sourcing, secure software releases, remediation guidance, and policy enforcement.
Read More about ActiveState and RL: Unlocking Software Supply Chain SecurityRL’s Ransomware Feed data from the first half of the year shows a jump in early-stage threats like infostealers — and a drop in Trojans.
Read More about Ransomware 2025: Infostealers on the MarchA phishing campaign against maintainers resulted in malware distribution via Javascript in top open-source packages.
Read More about Crypto wallets targeted in widespread hack of npm, GitHubWith attacks on popular repositories on the rise, PyPI has moved to head off a common technique for duping developers. Here’s what it accomplishes — and where there’s room for improvement.
Read More about PyPI tackles domain resurrection: Why it matters — and what’s missingRL discovered how the crypto contracts were abused — and how this incident is tied to a larger campaign to promote malicious packages on top repositories.
Read More about Ethereum smart contracts used to push malicious code on npmESET researchers have discovered malware that taps into OpenAI’s large language model to assist in ransomware attacks.
Read More about The future is here: AI-borne ransomware has arrivedRL has discovered a loophole on VS Code Marketplace that allows threat actors to reuse legitimate, removed package names for malicious purposes.
Read More about Loophole allows threat actors to claim VS Code extension namesDeveloper Productivity Engineering provides a framework to boost code production and creativity — and can help to improve application security.
Read More about How DPE can speed development — and boost your AppSecHere are six lessons learned from the near-miss that was the Amazon Q Developer incident. Don't let luck be your security strategy.
Read More about How AWS averted an AI coding supply chain disasterIntegrated security in AI assistants could help to catch code flaws — but they are only one layer in a comprehensive AppSec strategy.
Read More about AI coding tools gain security — but the controls do not cut itScott Culp’s formulation still holds true — though some additions are needed that account for software supply chain security.
Read More about ‘The Immutable Laws of Security’ at 25: 5 corollaries for a new eraHere's how to integrate AI-specific risks into your existing security incident response (IR) playbook.
Read More about OWASP GenAI Incident Response Guide 1.0: How to put it to workThe eslint-config-prettier package exposed more than 10,000 dependent projects. The incident highlights the growing risks in automated dependency updating.
Read More about Compromised npm package threatens developer projectsResearchers at Black Hat discussed how these tools can leave development teams vulnerable to hacks like remote-code execution.
Read More about Speed kills: AI coding tools revive old-school hacksLeading firms are using DevEx to achieve application security gains at speed. Here's how it works — and how to get started.
Read More about Move over, DevSecOps — DevEx is the new darlingGet your 14-day free trial of Spectra Assure
Get Free TrialMore about Spectra Assure Free Trial