惯性聚合
高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文
在惯性聚合中打开
即将跳转到惯性聚合
3
在聚合应用中查看完整内容和互动
立即跳转
取消
推荐订阅源
WordPress大学
Engineering at Meta
D
DataBreaches.Net
月光博客
Recent Announcements
Google DeepMind News
U
Unit 42
腾
腾讯CDC
爱范儿
J
Java Code Geeks
有赞技术团队
Blog — PlanetScale
N
Netflix TechBlog - Medium
B
Blog
Stack Overflow Blog
GbyAI
T
The Blog of Author Tim Ferriss
小众软件
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Y
Y Combinator Blog
大猫的无限游戏
Microsoft Azure Blog
T
Tailwind CSS Blog
钛媒体:引领未来商业与生活新知
Step Security Blog
Announcing Dependabot Configuration Enhancements: Cooldown and Group Support - StepSecurity
Securing Vibe Coding and AI Coding Agents: An End-to-End Approach with StepSecurity - StepSecurity
Introducing StepSecurity Dev Machine Guard: Protecting Developer Machines from Supply Chain Attacks - StepSecurity
Top 2024 Predictions for CI/CD Security - StepSecurity
Dev Machine Guard Is Now Open Source: See What's Really Running on Your Developer Machine - StepSecurity
Datadog's DevSecOps 2026 Report Validates What We've Been Building - StepSecurity
hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions - Microsoft, DataDog, and CNCF Projects Hit So Far - StepSecurity
Cline Supply Chain Attack Detected: cline@2.3.0 Silently Installs OpenClaw - StepSecurity
StepSecurity’s Unified Protection Across the SDLC Infrastructure Threat Framework (SITF) - StepSecurity
@velora-dex/sdk Compromised on npm: Malicious Version Drops macOS Backdoor via launchctl Persistence - StepSecurity
axios Compromised on npm - Malicious Versions Drop Remote Access Trojan - StepSecurity
Behind the Scenes: How StepSecurity Detected and Helped Remediate the Largest npm Supply Chain Attack - StepSecurity
10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Supply Chain Attack on GitHub Actions - StepSecurity
Malicious IoliteLabs VSCode Extensions Target Solidity Developers on Windows, macOS, and Linux with Backdoor - StepSecurity
TeamPCP Plants WAV Steganography Credential Stealer in telnyx PyPI Package - StepSecurity
litellm: Credential Stealer Hidden in PyPI Wheel - StepSecurity
Checkmarx KICS GitHub Action Compromised: Malware Injected in All Git Tags - StepSecurity
CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Ecosystem - StepSecurity
Trivy Compromised a Second Time - Malicious v0.69.4 Release, aquasecurity/setup-trivy, aquasecurity/trivy-action GitHub Actions Compromised - StepSecurity
bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys - StepSecurity
Malicious npm Releases Found in Popular React Native Packages - 130K+ Monthly Downloads Compromised - StepSecurity
Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wallet Keys - StepSecurity
ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push - StepSecurity
xygeni-action Compromised: C2 Reverse Shell Backdoor Injected via Tag Poisoning - StepSecurity
kubernetes-el Compromised: How a Pwn Request Exploited a Popular Emacs Package - StepSecurity
How StepSecurity Caught a Release Storm in Microsoft’s @types Packages - StepSecurity
Harden Runner Now Supports Windows and macOS GitHub Actions Runners - StepSecurity
10,000 Open-Source Projects Now Secured by Harden-Runner Community-Tier: A Milestone Three Years in the Making - StepSecurity
20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) - StepSecurity
2024 in Review: The Evolution of CI/CD Security & What's Next - StepSecurity
reviewdog GitHub Actions are compromised - StepSecurity
2025-07-08
·
via
Step Security Blog
reviewdog GitHub Actions are compromised
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。
原文来自
— 版权归原作者所有。