JFrog Artifactory hit by an authentication bypass exploited immediately after disclosure
JFrog Artifactory, one of the most widely used repository managers in DevOps pipelines and package distribution, has come under scrutiny after the disclosure of CVE-2026-82329. The
Ransomware on Japan’s cold chain
A ransomware attack hit a Japanese food logistics company, causing delays and disruptions in the distribution chain for frozen products to thousands of customers. Among those affec
Backdoored AI code completions need forensic analysis as poisoned training data becomes a supply-chain risk
A Help Net Security piece describes a forensic tool designed to trace backdoored code completions generated by AI assistants. The concern is that code used to train large models ma
AsyncAPI npm supply-chain compromise spreads malware through trusted packages
Attackers compromised the AsyncAPI npm organization and injected malicious code into multiple widely used packages, including generator and specs packages with more than two millio

