Posts Tagged ‘Developer Security’
Keyv npm Supply Chain Attack Hits 2 Billion Installs
The Keyv npm supply chain attack compromised a single GitHub maintainer account and used it to push a credential-stealing worm into hundreds of widely used caching packages. By August 5, trackers put the count at 868 packages and 1,381 versions, spanning a combined 2 billion-plus monthly installs — the largest software supply-chain incident DIESEC has…
Read MoreGitLab Oj Spill RCE Exploit Goes Public
The GitLab Oj Spill RCE is now public: a working exploit chain and full technical writeup were released on July 24 for a remote-code-execution flaw that GitLab quietly patched six weeks earlier, on June 10. If your self-managed GitLab instance is still on 18.10.7 or older, any developer who can push a commit can now…
Read MoreTop 5 Cybersecurity News Stories March 13, 2026
This is a strategic read on the top cybersecurity news stories March 13, 2026, and what they reveal about where systemic risk is shifting. Across legal data brokers, healthcare processors, browser‑based AI, phishing‑as‑a‑service platforms, and developer‑tool ecosystems, the common thread this week is simple: attackers are going after the control planes of the digital economy, not…
Read More
