GitGuardian found 321 n8n instances accepting leaked GitHub tokens that could expose workflows, data, and downstream ...
GitGuardian found thousands of leaked n8n API tokens, with hundreds still granting access to live automation servers, ...
NuGet API key expiration 2026: Microsoft caps new NuGet.org API keys at 30 days starting August 17, forcing all existing keys ...
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems ...
npm granular access tokens configured to bypass 2FA can no longer create tokens, change maintainers, or manage org membership ...
Aikido Security says an npm supply chain attack has infected Keyv packages with a variant of the credential-stealing ...
Malicious LiteLLM PyPI releases stole cloud and SSH keys, Kubernetes tokens, and other secrets, potentially exposing 2,500+ ...
More than 400 NPM packages have been infected with the Mini Shai-Hulud worm in the ChainDrop supply chain attack.
GitHub now automatically holds suspicious Actions workflows in public repositories, but maintainers must still review approvals, permissions, and risks.
Security researchers have warned of a major new Shai-Hulud-based campaign which has already compromised more than 430 ...
Upwind identified a malicious release of [email protected] that harvested AWS, GitHub, and npm credentials via a hidden preinstall script. With 154 million weekly downloads, the compromise had ecosystem-wide ...
A low-privilege Google ADK for Python agent could be abused to inject prompts into privileged agents, leading to PR poisoning ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results