Editorial Calendar
Fast-Moving Shai-Hulud Attack Infects npm Packages with 2 Billion Monthly Downloads
Researchers at Aikido Security and Endor Labs are tracking a fast-spreading supply-chain attack that is compromising a wide range of npm software packages that combined have more than 2 billion installs a ...
N. Korea Group Behind Multiple Open Source Supply-Chain Attacks: Amazon
Amazon’s recent report attributing a series of compromises of open source software libraries to a North Korea-backed threat group encapsulates many of the expanding cyber risks increasingly facing developers, from the growing ...
Common Risks of Outsourcing Software Development, and How to Tackle Them
Both SMBs and large enterprises often choose software development outsourcing over developing software in-house. It is no surprise, as partnering with external developers enables companies to bridge IT talent gaps that cannot ...
GitHub Brings Stacked Pull Requests Out of the Shadows
GitHub introduces native stacked pull requests, helping development teams break large changes into smaller, dependency-ordered PRs that are faster and easier to review ...
OpenAI Open Sources Codex Security CLI for the Merge Path
OpenAI has released its Codex Security command-line interface and software development kit as open source software under the Apache 2.0 license, providing a new way to bring its AI security scanner into ...
These are 10 CI/CD Pipeline Mistakes That Slow Down Engineering Teams
Continuous software delivery in the digital age has come to depend on CI/CD pipelines. They enable engineering teams to rapidly develop, test, and deploy code while keeping it highly usable and consistent ...
Black Duck Extends Scope and Reach of Code Scanning Tool
Black Duck has updated its Coverity static analysis code scanning tool to provide deeper integrations with artificial intelligence (AI) tools along with updates to its user interface that make it simpler to ...
FakeGit Targets AI Coding Agents with Malicious GitHub Repos
Threat actors continue to find new ways to incorporate AI into schemes aimed at luring developers into downloading malware from fake repositories. The latest example involves almost 7,600 malicious GitHub repositories that ...
Security Risks from AI Coding Agents Expand Beyond the Sandbox: Pillar
AI coding assistants have become an essential part of developers’ work, automating many of the repetitive tasks – think boilerplate coding and scaffolding – that in the past ate up a lot ...
Why You Need AI Agent Security Validation in Software Testing
Engineering teams have been racing for the last two years to deploy AI agents that can find bugs faster than any QA team ever could. Autonomous testing agents can crawl through codebases, ...
GitHub API Abuse, ‘Ghost’ Accounts Part of Malicious Efforts to Map Organizations
Datadog researchers uncover months-long overlapping campaigns to scrape data about companies and their developers ...
Why Developer Workstations Have Become a Critical Part of the Software Supply Chain
For years, software supply-chain security discussions focused on centralized infrastructure such as build servers, package registries, and CI/CD systems. Recent attacks suggest that this view is incomplete. The Megalodon campaign injected malicious ...

