4 articles and related resources
The compromise of the widely-used npm package keyv in August 2026 exposed millions to potential credential theft, highlighting critical software supply chain vu
The UK's NCSC warns of a surge in software supply chain attacks targeting open source dependencies, urging organizations to strengthen their security practices.
The NCSC warns of escalating software supply chain attacks exploiting open source dependencies, urging organizations to enhance security measures.
A 42-line npm package was exploited to infiltrate multiple production environments, highlighting critical supply chain vulnerabilities.
The 'Mini Shai-Hulud' campaign compromised Mistral AI and Tan ... , exposing sensitive credentials and highlighting software supply chain vulnerabilities.
Researchers unveil 'Java-Class-Hijack,' a novel supply chain attack exploiting Java's dependency resolution and classloading, posing significant risks to applic