2026 marks Jeff Burt's 40th year in journalism, including more than two decades reporting on the technology industry. He spent 16-plus years at eWEEK (2000–2017), where he covered data center infrastructure, networking, collaboration technology, cloud computing, processors, PCs, and — later — AI, quantum computing, and cybersecurity, eventually serving as Senior Editor and helping oversee the eWEEK Labs analyst group. Since 2017 he has worked as a freelance technology journalist and as Senior Editor at The Next Platform, covering HPC, supercomputing, hyperscale and enterprise computing, processors, and systems software. His byline has also appeared at The Register, The New Stack, eSecurity Planet, Enterprise Storage Forum, Enterprise Networking Planet, Channel Insider, Channel Futures, ITPro Today, and MSSP Alert, spanning enterprise infrastructure, cybersecurity, and emerging compute technologies. Before moving into technology reporting, Jeff spent 14 years covering courts, crime, politics, and environmental issues for general-circulation newspapers in Massachusetts. He holds a B.A. in Public Affairs/Journalism from Keene State College. Jeff is a contributing author at Security Boulevard, DevOps.com, and Techstrong.ai, where he covers cybersecurity threats including ransomware and nation-state hacking groups, data breaches, DOJ/law enforcement actions, and software supply chain attacks.
A dangerous vulnerability found in Anthropic’s popular Claude Code developer model could have allowed bad actors to grab control of a victim’s system by luring them into clicking on a crafted malicious ...
The latest series of attacks using the notorious Shai-Hulud worm puts into sharp focus the threats facing software developers and their CI/CD pipelines, an issue that has been raised in recent months ...
A critical vulnerability in a popular Microsoft GitHub repository could allow a threat actor to easily exploit its CI/CD infrastructure to run arbitrary code in the repository and gain access to secrets, ...
The npm code repository is again being used by a bad actor to launch a supply chain attack that includes three dozen malicious packages that appear as Strapi CMS plugins but deliver ...
The supply chain attack that compromised Aqua Security’s Trivy open source security vulnerability scanner and its associated GitHub Actions earlier this month continues to expand, with software development tools from Checkmarx and ...
Bad actors took over a npm maintainer account and have published two malicious packages designed to steal credentials, API keys, and other secrets from the computers of victims who download them from ...
A group of more than two dozen malicious npm packages used to steal secrets and credentials from software developers has all the hallmarks – from infrastructure to operations – of Famous Chollima, ...