The signature that proves a Firefox update is real got exposed — and there's no way to know who saw it
Software Updates
+6
A hidden comment in a pull request is all it takes to hijack the AI gatekeeper your team trusts to ship safe code
Zero Trust
Symlink attacks, hallucinated packages, and prompt injection are turning your AI pair programmer into an attacker's easiest way in
NHI
Malicious code is now delivered as helpful app features — and 26,000 AI agents just installed one.
third-party integrations
+3
CISA left live AWS GovCloud credentials in a public repo named "Private." It sat there for six months. Nobody inside the agency noticed.
Credential Security
+5
Convention files, prompt injection, and why the line between productivity tool and data pipeline just disappeared
A self-spreading worm just ran through the tools developers use to build every app you touch. Here's what that means for you — and what to do about it.
AppSec
+7