security
Insights and guidance from our engineering team on how Astral secures its tools.
A new open-source penetration testing framework called METATRON is gaining attention in the security research community for its fully offline, AI-driven approach to vulnerability assessment.
Anthropic accidentally shipped a source map in their npm package, exposing the full Claude Code source. Here's what I found inside.
more details: https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan Most likely, a maintainer's GitHub and npm accounts are compromised as these issues are getting deleted. I have also rep...
A security researcher found Anthropic's full CLI source code exposed through a source map file. 1,900 files. 512,000+ lines. Everything. Tagged with claudecode, security, typescript, ai.
The named Lockheed Martin employees have been given a deadline of 48 hours to “cease cooperation with the Zionist regime and leave the occupied territories immediately”.
The Handala hackers associated with Iran have breached the personal email account of FBI Director Kash Patel and published photos and documents.
GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects.
Trivy Security incident 2026-03-19
Feature: SCION: Proven in banking and healthcare, slow to spread everywhere else
Binarly has published VulHunt Community Edition, making the core scanning engine from Binarly's commercial Transparency Platform available to independent
A systematic audit of Algolia DocSearch found 39 admin API keys exposed across projects like Home Assistant, KEDA, and vcluster.
For a decade, I have been working with AWS and third-party security teams to resolve bucketsquatting / bucketsniping issues in AWS S3. Finally, I am happy to say AWS now has a solution to the problem, and it changes the way you should name your buckets.
Welcome to Wikimedia's home for real-time and historical data on system performance.
A prompt injection in a GitHub issue triggered a chain reaction that ended with 4,000 developers getting OpenClaw installed without consent. The attack composes well-understood vulnerabilities into something new: one AI tool bootstrapping another.
I recommend turning Dependabot off and replacing it with a pair of scheduled GitHub Actions, one running govulncheck, and the other running CI against the latest version of your dependencies.
Ghidra is a software reverse engineering (SRE) framework - NationalSecurityAgency/ghidra
Israeli surveillance company Paragon Solutions briefly exposed its own spyware dashboard on LinkedIn, revealing the hidden architecture of a billion-dollar surveillance empire built on the backs of journalists, activists, and ordinary people.