惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

MyScale Blog
MyScale Blog
T
The Blog of Author Tim Ferriss
The GitHub Blog
The GitHub Blog
V
Vulnerabilities – Threatpost
N
Netflix TechBlog - Medium
Recent Announcements
Recent Announcements
T
Troy Hunt's Blog
博客园_首页
博客园 - 三生石上(FineUI控件)
S
Schneier on Security
I
InfoQ
P
Palo Alto Networks Blog
博客园 - 叶小钗
P
Privacy International News Feed
T
Tenable Blog
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Vercel News
Vercel News
Cyberwarzone
Cyberwarzone
C
Cybersecurity and Infrastructure Security Agency CISA
量子位
J
Java Code Geeks
Scott Helme
Scott Helme
阮一峰的网络日志
阮一峰的网络日志
S
SegmentFault 最新的问题
Stack Overflow Blog
Stack Overflow Blog
Latest news
Latest news
P
Proofpoint News Feed
V
Visual Studio Blog
小众软件
小众软件
WordPress大学
WordPress大学
Security Latest
Security Latest
A
Arctic Wolf
L
Lohrmann on Cybersecurity
Engineering at Meta
Engineering at Meta
雷峰网
雷峰网
Microsoft Security Blog
Microsoft Security Blog
Microsoft Azure Blog
Microsoft Azure Blog
M
MIT News - Artificial intelligence
NISL@THU
NISL@THU
Simon Willison's Weblog
Simon Willison's Weblog
C
Cisco Blogs
A
About on SuperTechFans
V
V2EX - 技术
F
Full Disclosure
T
Tor Project blog
Hacker News: Ask HN
Hacker News: Ask HN
罗磊的独立博客
Know Your Adversary
Know Your Adversary
Project Zero
Project Zero
B
Blog

2024 Sonatype Blog

Atomic Arch npm Campaign Adds Malicious Dependency From SBOMs to AI BOMs: Why SPDX 3.0 Matters Mythos Found 10,000 Vulnerabilities. The Bigger Challenge Is Fixing Them New Shai-Hulud Miasma Wave Hits Hundreds of npm Packages Lazarus Group's Latest: Brandjacking Campaign on npm 5 Steps to Turn Your RMF Backlog Into a Continuous ATO: The CSRMC Migration Playbook The AI Race Is Becoming a Remediation Race Inside a 176-Package npm Campaign Built to Beat Your Internal Dependencies AI Is Making Software Autonomous, and Governance Must Follow Your Outdated Repository Still Works, But It May Not Be Safe Hijacked npm Package Attempts to Deliver PolinRider-Linked RAT AppSec Tools Explained: SAST vs SCA vs DAST | Sonatype Managing Open Source Software Risks With the HeroDevs EOL Dashboard Shai-Hulud is Back: Maintainer Accounts Are Still the Soft Target Building Trusted AI Development With Kiro and Sonatype Guide How to Build a Software Supply Chain Security Playbook The Evolution of Open Source Malware: From Volume to Trust Abuse The Mythos AI Vulnerability Storm: What to Do Next Malicious PyTorch Lightning Packages Found on PyPI Why Developer Experience Is the Foundation of DevSecOps Success Open is Not Costless: Reclaiming Sustainable Infrastructure Q1 Updates in Nexus Repository: More Formats, Stronger Operations, and a Better Day-to-Day Experience Self-Propagating npm Malware Turns Trusted Packages Into Attack Paths The Time Is Now to Prepare for CRA Enforcement Sonatype Innovate: Real Peer Connections, Real Product Influence, Real Recognition Mythos and the AI Vulnerability Storm: Exploring the Control Point When AI Writes Code, Who Governs the Dependencies? Why Software Supply Chain Security Requires a New Playbook Q1 2026 Open Source Malware Index: Adaptive Attacks Exploit Trust Modernizing Nexus Repository: Moving Beyond OrientDB AI, DevSecOps, and the Future of Application Security: The Gartner® Report How Sonatype's Container Scanning Protects You From Zero-Days Axios Compromise on npm Introduces Hidden Malicious Package Is Your Repository Ready for What's Next? Autonomous Development and AI: Speed vs. Security Grounded Intelligence Ensures Safe AI Software Development Compromised litellm PyPI Package Delivers Multi-Stage Credential Stealer Golden Pull Requests: Automating Trusted Remediation Without Breaking Builds Sonatype Discovers Two Malicious npm Packages
Red Hat Cloud Services npm Packages Hijacked
Sonatype Security Research Team · 2026-06-02 · via 2024 Sonatype Blog
A new wave of malicious npm activity has been reported involving multiple packages in t he legitimate @redhat…