Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Accidental Exposure in Private Repo
Mozilla has revoked the cryptographic signing key used for Firefox and Thunderbird downloads on Linux after an unencrypted copy of the key…
Mozilla has revoked the cryptographic signing key used for Firefox and Thunderbird downloads on Linux after an unencrypted copy of the key…
AI is enabling development teams to ship 10 to 50 times more code, but security teams still operate at human speed, creating…
Open source software is undergoing a forced maturation, driven by a convergence of threats and regulatory pressures. The article argues that while…
Google has removed three AI agent workflows from its Agent Development Kit (ADK) Python repository after researchers at Pillar Security demonstrated that…
GitHub has announced a new cooldown mechanism for Dependabot that introduces a mandatory three-day waiting period before opening pull requests for version…
Mend.io disclosed details of an undocumented software supply chain attack using 14 RubyGems packages to store stolen credential data.
Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm…
Chainguard is a software supply chain security company that provides solutions for secure base images, SBOM management, and policy enforcement. The company…
New research from Carnegie Mellon University PhD student Jacob Ginesin, also a cryptographic auditor at Cure53, reveals that GitHub's 'Verified' commit badge…
Researchers at Noma Security have demonstrated a novel prompt injection attack, dubbed GitLost, that exploits GitHub Agentic Workflows to leak private repository…