Latest Tech News
Daily updates from AI, software, hardware and more.
Microsoft details ChainDrop worm spreading through compromised npm packages
Microsoft says ChainDrop used compromised npm packages to steal developer credentials and spread through software supply...
GitHub restricts npm 2FA-bypass tokens to reduce package supply chain risk
GitHub restricted npm 2FA-bypass granular access tokens and plans more publish controls for January 2027.
GitHub adds publish-time malware scanning and dual-use metadata rules for npm packages
GitHub says npm packages will now face malware scanning before install availability, with new disclosure rules for dual-...
Microsoft frames Black Hat 2026 security agenda around AI and software supply chain trust
Microsoft's Black Hat USA 2026 agenda focuses on AI agents, npm supply chain attacks, identity and trusted workflow abus...
AsyncAPI npm package compromise shows provenance is not a complete supply-chain defense
Microsoft, Datadog and StepSecurity detail a July 14 AsyncAPI npm compromise that used legitimate CI releases to ship ma...