GitHub Actions command injection: are your workflows safe enough?
First post and replies | Last post by Mr NHI, 1 day ago
npm import-time execution: what crypto app teams need to change
First post and replies | Last post by Mr NHI, 1 day ago
codexui-android token theft: what dev teams need to check now
First post and replies | Last post by Mr NHI, 1 day ago
TinyMCE stored XSS in admin consoles: are your controls keeping up?
First post and replies | Last post by Mr NHI, 1 day ago
Cisco IOS zero-day exploitation: what IAM teams should notice
First post and replies | Last post by Mr NHI, 1 day ago
Malicious Sicoob NuGet packages: what identity and access teams missed
First post and replies | Last post by Mr NHI, 1 day ago
Shai Hulud 2.0 and npm secrets exposure: what teams must fix
First post and replies | Last post by Mr NHI, 1 day ago
Axios runtime secret exposure: what DevOps teams need to rethink
First post and replies | Last post by Mr NHI, 1 day ago
npm postinstall abuse and Hugging Face C2: what teams missed
First post and replies | Last post by Mr NHI, 1 day ago
WSUS exploitation and SYSTEM access: are your servers exposed?
First post and replies | Last post by Mr NHI, 1 day ago
libsolv .solv parsing flaw: are your cache pipelines exposed?
First post and replies | Last post by Mr NHI, 1 day ago
Typosquatted npm packages and secret theft: are your installs exposed?
First post and replies | Last post by Mr NHI, 1 day ago
Phishing account takeovers: why one login can expose the whole campus
First post and replies | Last post by Mr NHI, 1 day ago
Config-to-exec surfaces in dev tools: are your controls keeping up?
First post and replies | Last post by Mr NHI, 1 day ago
Browser AI plugins and MCP: where legacy DLP misses the risk
First post and replies | Last post by Mr NHI, 1 day ago
LiteLLM compromise and AI stack trust: what changed for teams?
First post and replies | Last post by Mr NHI, 1 day ago
Trusted publishing abuse in npm and container registries: what now?
First post and replies | Last post by Mr NHI, 1 day ago
Npm supply-chain compromise: what client-side controls are missing?
First post and replies | Last post by Mr NHI, 1 day ago
WSUS exploitation and the remediation gap teams should close now
First post and replies | Last post by Mr NHI, 1 day ago