security
The Claude Code Source Leak: fake tools, frustration regexes, undercover mode
https://alex000kim.com/posts/2026-03-31-claude-code-source-leak/
Added 4 months ago
Claude Code's source code has been leaked via a map file in their NPM registry
https://twitter.com/Fried_rice/status/2038894956459290963
Added 4 months ago
[email protected] and [email protected] are compromised · Issue #10604 · axios/axios · GitHub
https://github.com/axios/axios/issues/10604#issuecomment-4160410930
Added 4 months ago
Claude Code's Entire Source Code Was Just Leaked via npm Source Maps — Here's What's Inside - DEV Community
https://dev.to/gabrielanhaia/claude-codes-entire-source-code-was-just-leaked-via-npm-source-maps-heres-whats-inside-cjo
Added 4 months ago
Iran-linked hackers deliver ultimatum to Lockheed Martin staff – Australian Aviation
https://australianaviation.com.au/2026/03/iran-linked-hackers-deliver-ultimatum-to-lockheed-martin-staff/
Added 4 months ago
FBI confirms hack of Director Patel's personal email inbox
https://www.bleepingcomputer.com/news/security/fbi-confirms-hack-of-director-patels-personal-email-inbox/
Added 4 months ago
Trivy under attack again: Widespread GitHub Actions tag compromise secrets
https://socket.dev/blog/trivy-under-attack-again-github-actions-compromise
Added 4 months ago
Attempts to post the latest Trivy security incident have been marked [dead]
https://news.ycombinator.com/from?site=github.com%2Faquasecurity
Added 4 months ago
Trivy ecosystem supply chain briefly compromised
https://github.com/aquasecurity/trivy/security/advisories/GHSA-69fq-xp46-6x23
Added 4 months ago
Trivy Security incident 2026-03-19
https://github.com/aquasecurity/trivy/discussions/10425
Added 4 months ago
TeamPCP deploys CanisterWorm on NPM following Trivy compromise
https://www.aikido.dev/blog/teampcp-deploys-worm-npm-trivy-compromise
Added 4 months ago
Switzerland built an alternative to BGP. Nobody noticed • The Register
https://www.theregister.com/2026/03/17/switzerland_bgp_alternative/
Added 4 months ago
VulHunt: Open-source vulnerability detection framework - Help Net Security
https://www.helpnetsecurity.com/2026/03/16/vulhunt-open-source-vulnerability-detection-framework/
Added 4 months ago
I found 39 Algolia admin keys exposed across open source documentation sites
https://benzimmermann.dev/blog/algolia-docsearch-admin-keys
Added 4 months ago
Bucketsquatting is (finally) dead
https://onecloudplease.com/blog/bucketsquatting-is-finally-dead
Added 4 months ago
Google closes deal to acquire Wiz
https://www.wiz.io/blog/google-closes-deal-to-acquire-wiz
Added 4 months ago
Wikipedia was in read-only mode following mass admin account compromise
https://www.wikimediastatus.net
Added 4 months ago
A GitHub Issue Title Compromised 4k Developer Machines
https://grith.ai/blog/clinejection-when-your-ai-tool-installs-another
Added 4 months ago
The Israeli Spyware Firm That Accidentally Just Exposed Itself
https://ahmedeldin.substack.com/p/the-israeli-spyware-firm-that-accidentally
Added 5 months ago
Sandwich Bill of Materials
https://nesbitt.io/2026/02/08/sandwich-bill-of-materials.html
Added 5 months ago
Windows Notepad App Remote Code Execution Vulnerability
https://www.cve.org/CVERecord?id=CVE-2026-20841
Added 5 months ago
The Day the Telnet Died
https://www.labs.greynoise.io/grimoire/2026-02-10-telnet-falls-silent/
Added 5 months ago