GitHub Actions will hold potentially malicious workflows until a collaborator with write access approves them.
GitHub Code Quality billing starts today as the free preview ends, with immediate $10-per-active-committer monthly charges hitting more than 10,000 enterprises and no grace period. The three-part bill ...
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems ...
GitHub Actions security enforcement went live today: actions/checkout now refuses by default to execute untrusted fork code inside privileged CI/CD workflows, closing the pwn request attack vector ...
A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. The change makes malicious infrastructure harder to detect while ...
GitHub now automatically holds suspicious Actions workflows in public repositories, but maintainers must still review ...
Gemini CLI and Claude Code flaws let untrusted GitHub input reach CI workflows, including host command execution and API key ...
A Keyv-linked npm worm poisoned 353 versions across 79 package names, stealing developer and CI credentials while repository ...
Latest update to Microsoft’s code editor improves dictation, introduces side chats, and adds support for comments to provide ...
Upwind identified a malicious release of keyv@6.0.0 that harvested AWS, GitHub, and npm credentials via a hidden preinstall script. With 154 million weekly downloads, the compromise had ecosystem-wide ...
A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory. The operation has been ...
Version 2.0 of Microsoft’s official C# SDK for Model Context Protocol servers and clients implements the recent revision of ...