Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

DEV Community
dev.to > uhltak > die-xz-backdoor-weckruf-fur-die-open-source-sicherheit-4ph9

Die XZ-Backdoor: Weckruf für die Open-Source-Sicherheit

2+ day, 20+ hour ago   (249+ words) Um das Ausmaß des Vorfalls zu verstehen, müssen wir die Ereignisse Schritt für Schritt nachvollziehen. Es ist eine Geschichte, die sich wie ein Cyber-Thriller liest, aber bittere Realität ist. Hätte Freund diese kleine Anomalie ignoriert, wäre die Backdoor unentdeckt in…...

SC Media
scworld.com > brief > shai-hulud-npm-worm-resurfaces-bypassing-security-scans

Shai-Hulud npm worm resurfaces, bypassing security scans

3+ day, 3+ hour ago   (80+ words) As outlined in IT Pro, the Shai-Hulud npm worm, previously thought to be neutralized, has reappeared in a new campaign that successfully bypassed npm's recently implemented security measures. The targeted entities are developers and organizations relying on the npm registry…...

DEV Community
dev.to > sravansk > we-analyzed-a-malicious-pypl-package-targeting-developers-279o

We Analyzed a Malicious PyPl Package Targeting Developers

3+ day, 17+ hour ago   (196+ words) A developer runs pip install. Nothing crashes. No ransomware appears. No antivirus alert fires. Thirty seconds later, a Python process makes an outbound connection to infrastructure nobody on the team recognizes. Recent 2026 incidents show how quickly this can become a…...

MarketScreener
marketscreener.com > news > ltimindtree-ltm-collaborates-with-ibm-and-red-hat-on-lightwell-to-advance-ai-driven-open-source-so-ce785bd9db8ff02d

LTIMindtree: LTM Collaborates with IBM and Red Hat on Lightwell to Advance AI-Driven Open-Source Software Remediation

3+ day, 21+ hour ago   (133+ words) Published on 09/09/2026 at 01:46 am EDT Mumbai, India, Sept 9, 2026: LTM, the Business Creativity partner to the world's largest enterprises, today announced that it has collaborated with IBM and Red Hat on Lightwell to help enterprises safeguard the open-source software supply chain…...

DevOps.com
devops.com > eu-funded-codesupply-offers-grants-for-open-source-software-supply-chain-rd

EU-Funded CodeSupply Offers Grants for Open Source Software Supply Chain R&D

4+ day, 6+ hour ago   (48+ words) Software supply chain, security and compliance tools all depend on accurate information about the packages they analyze, but that data is often fragmented EU-funded CodeSupply is making €400,000 in grants available for open source R&D projects focused on software supply…...

Cyber Security News
cyberpress.org > dormant-npm-worm-returns

npm Supply Chain Worm Returns After Four-Month Dormancy With Same Malicious Payload

4+ day, 21+ hour ago   (330+ words) A previously documented Shai-Hulud npm supply-chain worm payload has reportedly reappeared after 111 days of inactivity, using the exact same malicious file linked to the May 19 compromise of hundreds of @AntV package versions. The reactivation raises concerns about registry-level malware detection…...

kobaran.com
kobaran.com > shai-hulud-malware-returns-to-npm-unchanged-111-days-after-its-hash-was-fingerprinted

Shai-Hulud Malware Returns to npm Unchanged, 111 Days After Its Hash Was Fingerprinted

4+ day, 17+ hour ago   (507+ words) Four packages is a small blast radius next to the 639 malicious versions pushed during the May campaign. The significance sits elsewhere. npm rolled out publish-time scanning in July, a control that briefly holds new publications for automated analysis before they…...

Tech Insider
tech-insider.org

How to Generate an SBOM: 12 Steps, 90 Min [2026]

5+ day, 5+ hour ago   (1662+ words) This tutorial walks through generating, validating, and operationalizing SBOMs using the same open-source tools that dominate the space right now: Syft, Grype, Trivy, and Dependency-Track. By the end you will have a working pipeline that produces a CycloneDX or SPDX…...

Aikido Security
aikido.dev > blog > shai-hulud-npm-resurfaces

A Shai-Hulud npm payload came back 111 days later

5+ day, 13+ hour ago   (396+ words) Advanced AppSec suite, built for devs. in-app runtime defense and threat detection. Real-time malware & vuln threats Since then, npm has introduced publish-time malware scanning. So you can imagine my surprise when I was going through our triage queue this morning…...

Security Affairs
securityaffairs.com > 198573 > malware > jsceal-hides-crypto-malware-in-v8-bytecode.html

JSCeal Hides Crypto Malware in V8 Bytecode

5+ day, 16+ hour ago   (764+ words) Why AI Agent Sandboxes Are Failing Security Tests Berlin Ransomware Leak Exposes State Secrets Your MikroTik Router May Already Be Compromised: Look for SSH User “-2” AI Agents Hijacked German Wiki to Cheat, OpenAI Delayed Disclosure Security Affairs newsletter Round 593 by…...