The 9-Second Disaster: What a Rogue AI Coding Agent Teaches Us About Production Access

A Claude-powered agent deleted an entire production database in 9 seconds. Here's why it happened and what it means for anyone using AI coding tools.

Read More

Administrative Betrayal: The Bitwarden CLI Supply Chain Hijack

A malicious npm package impersonating the Bitwarden CLI installed its own runtime to steal secrets. When security tools are the attack vector, the whole CI/CD pipeline becomes a weapon.

Read More

AI Code Gets CVEs Now.

The UK's NCSC called AI-generated code an 'intolerable risk,' researchers found all seven major MCP clients vulnerable to attack, and 35 CVEs in March alone traced directly back to AI-written code.

Read More

This Malware Hides Its Command Server in the Blockchain, and Borrows Google Calendar Too

GlassWorm targets developers through compromised npm, PyPI, and GitHub packages. Its C2 address is hidden in a Solana blockchain memo. You can't take down a blockchain transaction.

Read More

The npm Ghost: That Install Log Looked Normal Because It Was Built to Fool You

Seven malicious npm packages have been stealing sudo passwords and crypto wallet data from developer machines since February. The trick: they generate fake terminal output so convincing that developers don't look twice.

Read More

GlassWorm Is Hiding Malware in Invisible Code and Pushing It Into Your Python Repos

GlassWorm steals GitHub tokens, then injects malicious code written in invisible Unicode characters into repos developers already trust. 151 packages hit in one week.

Read More

The Software You Trust Is Becoming the Attack: Two Supply-Chain Strikes in One Week

GlassWorm hijacked VS Code extension dependencies. AppsFlyer's SDK got compromised to serve crypto stealers. Both attacks exploited trust, not carelessness.

Read More

Developer Supply Chains Under Coordinated Assault: 88 Malicious npm Packages and a CVSS 9.8 in simple-git

PhantomRaven dropped 88 malicious npm packages targeting AWS credentials and CI secrets. A critical RCE in simple-git threatens millions of dev environments. Your developer toolchain is a target.

Read More