2026 marks Jeff Burt's 40th year in journalism, including more than two decades reporting on the technology industry. He spent 16-plus years at eWEEK (2000–2017), where he covered data center infrastructure, networking, collaboration technology, cloud computing, processors, PCs, and — later — AI, quantum computing, and cybersecurity, eventually serving as Senior Editor and helping oversee the eWEEK Labs analyst group. Since 2017 he has worked as a freelance technology journalist and as Senior Editor at The Next Platform, covering HPC, supercomputing, hyperscale and enterprise computing, processors, and systems software. His byline has also appeared at The Register, The New Stack, eSecurity Planet, Enterprise Storage Forum, Enterprise Networking Planet, Channel Insider, Channel Futures, ITPro Today, and MSSP Alert, spanning enterprise infrastructure, cybersecurity, and emerging compute technologies. Before moving into technology reporting, Jeff spent 14 years covering courts, crime, politics, and environmental issues for general-circulation newspapers in Massachusetts. He holds a B.A. in Public Affairs/Journalism from Keene State College. Jeff is a contributing author at Security Boulevard, DevOps.com, and Techstrong.ai, where he covers cybersecurity threats including ransomware and nation-state hacking groups, data breaches, DOJ/law enforcement actions, and software supply chain attacks.
Security researchers are sorting through a complex, stealthy, and fast-moving supply-chain attack aimed at pushing information-stealing malware by compromising the account of the maintainer of multiple Rust crates and introducing four more ...
Developers for years have been using vm2, an open-source Node.js library, to run untrusted JavaScript inside a secure and isolated sandbox environment. It uses Node.js’s built-in modules and JavaScript Proxies and lets ...
The massive supply-chain attack that compromised LiteLLM in the spring affected more than 2,500 companies and exposed about 434,000 CI/CD pipelines, with victims ranging from top-tier IT and AI companies to cybersecurity ...
Threat researchers at Sonatype are warning developers of an expanding campaign that is generating a wide range of npm accounts and dropping small numbers of malicious packages from each one, essentially flooding ...
Researchers at Aikido Security and Endor Labs are tracking a fast-spreading supply-chain attack that is compromising a wide range of npm software packages that combined have more than 2 billion installs a ...
Amazon’s recent report attributing a series of compromises of open source software libraries to a North Korea-backed threat group encapsulates many of the expanding cyber risks increasingly facing developers, from the growing ...
Threat actors continue to find new ways to incorporate AI into schemes aimed at luring developers into downloading malware from fake repositories. The latest example involves almost 7,600 malicious GitHub repositories that ...
AI coding assistants have become an essential part of developers’ work, automating many of the repetitive tasks – think boilerplate coding and scaffolding – that in the past ate up a lot ...
Hallucinations have been an ongoing problem since OpenAI first introduced its ChatGPT chatbot in November 2022, highlighting generative AI’s tendency to generate plausible but false or misleading information and its inability to ...