Threat actors abused trusted Trivy distribution channels to inject credential‑stealing malware into CI/CD pipelines worldwide ...
Supply chain attacks feel like they're becoming more and more common.
North Korean hackers exploit VS Code tasks.json auto-run since Dec 2025 to deploy StoatWaffle malware, stealing data and ...
The Trivy vulnerability scanner was compromised in a supply-chain attack by threat actors known as TeamPCP, which distributed ...
GitLab Inc., the intelligent orchestration platform for DevSecOps, today released GitLab 18.10, making it easier and more ...
Chainguard is expanding beyond open-source security to protect open-core software, AI agent skills, and GitHub Actions.
MultiEndpointTox is a machine learning-powered REST API for predicting multiple drug toxicity endpoints from molecular structures. It provides interpretable predictions with SHAP explanations, ...