keyv npm supply chain attack on August 4, 2026 let the Shai-Hulud worm compromise 400-plus packages and more than two billion monthly downloads. The Wave Six payload hid inside AI agent config files ...
Next iteration of the Rust compiler component that enforces rules on references is being enabled on nightly releases for ...
A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. The change makes malicious infrastructure harder to detect while ...
UTC on Monday, saying it was investigating reports of performance problems across several GitHub services. Within minutes, ...
GitHub's CI/CD layer — the service engineering teams depend on to build, test, and ship software automatically — has accumulated more than fourteen hours of downtime in the past 90 days and has now ...
Cursor launched Origin, a new AI-native code hosting platform, as a major GitHub outage exposed growing risks for engineering teams and intensified the battle over code repositories, AI agents, and ...
Authentication issues lingered as GitHub worked through a sprawling disruption that affected key developer services and enterprise workflows across its platform.
GitHub now automatically holds suspicious Actions workflows in public repositories, but maintainers must still review approvals, permissions, and risks.
GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact.
A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory. The operation has been ...
New controls for model reasoning and Copilot code-review depth let developers decide how much AI effort a task warrants, with speed, depth and credit consumption all part of the tradeoff.