Visualização de leitura
Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain
Attackers are targeting CI/CD pipelines and developer tools instead of application code, requiring total SDLC visibility and strict security controls
The post Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain appeared first on Unit 42.

77 Counterfeit Open VSX Extensions Collected Developer and CI/CD Data
Security researchers found 150 lookalike Open VSX extensions published under trusted names, highlighting how extension marketplaces can expose developer credentials, source code, and CI/CD systems to supply-chain risk.
The post 77 Counterfeit Open VSX Extensions Collected Developer and CI/CD Data appeared first on TechRepublic.
CrowdStrike Warns AI Adoption Is Creating ‘Underdefended’ Attack Surfaces
CrowdStrike warns that AI adoption, rapid vulnerability exploitation, cloud attacks, and malicious npm packages are creating new enterprise security risks.
The post CrowdStrike Warns AI Adoption Is Creating ‘Underdefended’ Attack Surfaces appeared first on TechRepublic.
Shai-Hulud npm Worm Returns, Poisoning Over 1,280 npm Packages
Hugging Face Deepfake Tests Raise New Risks for AI Procurement
Researchers found that seven of nine tested Hugging Face image-editing tools produced sexualized alterations, highlighting gaps in model oversight, provenance, and enterprise vendor controls.
The post Hugging Face Deepfake Tests Raise New Risks for AI Procurement appeared first on TechRepublic.
GitHub Automatically Holds Suspicious Actions Runs, but Repository Owners Must Approve Them
GitHub’s new Actions safeguard pauses potentially malicious workflow runs before execution, leaving repository owners to decide who can approve them and what checks must come first.
The post GitHub Automatically Holds Suspicious Actions Runs, but Repository Owners Must Approve Them appeared first on TechRepublic.
Cursor Quietly Patches High-Severity Git Vulnerability After Seven-Month Delay
Cursor has patched a high-severity Windows vulnerability that allowed malicious Git repositories to execute code, highlighting security risks in AI coding environments.
The post Cursor Quietly Patches High-Severity Git Vulnerability After Seven-Month Delay appeared first on TechRepublic.
Critical TeamCity Flaw Could Let Unauthenticated Attackers Execute Server Commands
JetBrains has patched CVE-2026-63077, a critical TeamCity flaw that could let unauthenticated attackers execute server commands and compromise connected CI/CD pipelines.
The post Critical TeamCity Flaw Could Let Unauthenticated Attackers Execute Server Commands appeared first on TechRepublic.
Third-Party SDKs Raise Privacy Questions for Apps Marketed to U.S. Military
Researchers found Chinese and Russian SDKs in Android apps marketed to U.S. military users, highlighting software supply chain and enterprise privacy risks.
The post Third-Party SDKs Raise Privacy Questions for Apps Marketed to U.S. Military appeared first on TechRepublic.
Upwind Finds Coordinated Supply Chain Campaign Compromising Multiple AsyncAPI npm Packages
Siggen Backdoor Hits Windows Developers Via Infected Visual Studio Projects
China Warns of Claude Code ‘Backdoor’ Security Risk
China warned organizations to remove certain Claude Code versions over alleged backdoor risks, while Anthropic called the feature anti-abuse protection.
The post China Warns of Claude Code ‘Backdoor’ Security Risk appeared first on TechRepublic.
Smashing Security podcast #474: Polymarket can predict the future. So how did it miss this hack?
Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector
Attackers can exploit LLM domain hallucinations through phantom squatting to target supply chains. Read the analysis to learn more.
The post Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector appeared first on Unit 42.

iPhone 18 Leak: Apple’s Next Pro Design May Have Appeared Online
Leaked Tata files reportedly show possible iPhone 18 Pro design details, factory images, and supplier records ahead of Apple’s expected September launch.
The post iPhone 18 Leak: Apple’s Next Pro Design May Have Appeared Online appeared first on TechRepublic.
‘Cordyceps’ CI/CD Flaw Exposes Microsoft, Google, Apache Repos to Pipeline Hijacking
Salesforce Disables Klue Integration After OAuth Token Theft Hits Customer Data
Trust No Skill: Integrity Verification for AI Agent Supply Chains
Protect enterprise AI agents from supply chain risks by auditing third-party skills for hidden vulnerabilities and multi-stage attack chains.
The post Trust No Skill: Integrity Verification for AI Agent Supply Chains appeared first on Unit 42.
