Latest Tech News
Daily updates from AI, software, hardware and more.
CISA flags actively exploited JetBrains TeamCity flaw after critical RCE patch
CISA added CVE-2026-63077, a critical JetBrains TeamCity On-Premises RCE flaw, to its exploited vulnerabilities catalog.
GitHub adds publish-time malware scanning and dual-use metadata rules for npm packages
GitHub says npm packages will now face malware scanning before install availability, with new disclosure rules for dual-...
GitHub Actions now pauses some suspicious public-repo workflows for human approval
GitHub Actions now automatically holds some suspicious public-repository workflow runs for collaborator approval before ...
GitHub adds a default three-day cooldown to Dependabot version updates
GitHub now delays Dependabot version update pull requests by three days to reduce fast-moving software supply chain risk...
Microsoft frames Black Hat 2026 security agenda around AI and software supply chain trust
Microsoft's Black Hat USA 2026 agenda focuses on AI agents, npm supply chain attacks, identity and trusted workflow abus...
AsyncAPI npm package compromise shows provenance is not a complete supply-chain defense
Microsoft, Datadog and StepSecurity detail a July 14 AsyncAPI npm compromise that used legitimate CI releases to ship ma...
GitHub gives Dependabot version updates a three-day default package cooldown
GitHub now delays Dependabot version update PRs by three days by default, while security fixes still open immediately.
IBM and Red Hat launch Lightwell to automate open source vulnerability remediation
IBM and Red Hat launched Lightwell, an AI-assisted service for remediated, signed open source dependencies.