Australian police charged two Western Australian men over the TeamPCP syndicate's open-source supply chain attacks.
The Rust project yanked three poisoned crates after a compromised account shipped a build-time backdoor.
Endor Labs shows a type confusion in isolated-vm lets sandboxed code take over the host process.
Scanners are hammering MLflow and FUXA servers as attackers chase cloud credentials and code execution.
Fresh GPG key now signs Firefox and Thunderbird Linux builds.
The Mini Shai-Hulud worm stole publisher credentials, republished tainted packages, and burrowed into AI coding tools.
A large-scale supply chain attack dubbed FakeGit uses thousands of deceptive GitHub repositories to distribute SmartLoader malware.
Multiple Notepad++ vulnerabilities including PowerShell command injection and Zip Slip disclosed before patch