Fake Laravel Packages Spread RAT Malware
Read More: buff.ly/gOmOIpX
#LaravelSecurity #Packagist #SupplyChainAttack #RATmalware #PHPsecurity #OpenSourceRisk #DeveloperSecurity #InfosecAlert
Latest posts tagged with #DeveloperSecurity on Bluesky
Fake Laravel Packages Spread RAT Malware
Read More: buff.ly/gOmOIpX
#LaravelSecurity #Packagist #SupplyChainAttack #RATmalware #PHPsecurity #OpenSourceRisk #DeveloperSecurity #InfosecAlert
The result? Your Slack history, API keys, and private files are laid bare—all without you ever clicking "Allow."
Read the full Alert : www.synergyit.com/openclaw-vul...
#AI #OpenClaw #InfoSec #AppSec #SynergyITUSA #DeveloperSecurity #CyberAlert #OpenSource #SecurityUpdate #2026Tech
North Korean Hackers Hide RAT In npm
Read More: buff.ly/hueDNJ7
#StegaBin #npmSecurity #SupplyChainAttack #FamousChollima #Steganography #RemoteAccessTrojan #DeveloperSecurity #InfosecAlert
Fake Next.js Job Repos Spread Malware AI
Read More: buff.ly/tGWKeKt
#NextJS #MaliciousRepo #DeveloperSecurity #SupplyChainAttack #GitHubAbuse #AIenabledThreats #Infostealer #ThreatIntel
Rogue StripeApi NuGet Stole API Keys
Read More: buff.ly/Yc6IvGP
#NuGetSecurity #Typosquatting #StripeApiNet #APITokenTheft #SoftwareSupplyChain #OpenSourceRisk #DeveloperSecurity #InfosecAlert
Full Article: www.technadu.com/open-vsx-reg...
Are your teams auditing IDE extensions and registries regularly?
Comment with your mitigation strategies 👇
#CyberSecurity #SupplyChainSecurity #OpenVSX #GlassWorm #MalwareAnalysis #DeveloperSecurity
Malicious VS Code AI Extensions Steal Code
Read More: buff.ly/DyL92xE
#VSCode #SupplyChainAttack #DeveloperSecurity #MaliciousExtensions #AIThreats #SourceCode #Infosec #CyberEspionage #SoftwareSecurity
VS Code Forks Expose Open VSX Risks
Read More: buff.ly/rutSsMr
#OpenVSX #VSCodeForks #DeveloperSecurity #SupplyChainRisk #MaliciousExtensions #AppSec #DevSecOps #ThreatResearch
27 Malicious Npm Phishing Packages Steal
Rad More: buff.ly/TNtJ2id
#NPMSupplyChain #MaliciousPackages #PhishingCampaign #DeveloperSecurity #OpenSourceAbuse #CredentialTheft #CriticalInfrastructure #ThreatResearch
New MacSync Stealer Bypasses Gatekeeper
Read More: buff.ly/3eaW1HH
#WebRAT #GitHubMalware #SupplyChainAttack #OpenSourceAbuse #DeveloperSecurity #MalwareDistribution #ThreatCampaign #Infosec
Webrat Malware Spreads On Github
Read Now: buff.ly/RiSDTpz
#WebRAT #GitHubMalware #SupplyChainAttack #OpenSourceAbuse #DeveloperSecurity #MalwareDistribution #ThreatCampaign #Infosec
And of course, as always, we appreciate the support of Microsoft and OpenVSX, both of whom responded promptly and professionally.
#SupplyChainSecurity #MaliciousPackages #DeveloperSecurity #SoftwareSupplyChain #ExtensionSecurity #VisualStudioCode
We took down 6 more malicious #VSCode packages that seem to be an evolved brandjacking attack similar the attack on Prettier we previously took down.
List of extensions and additional info: buff.ly/wxviY9d
#SupplyChainSecurity #DeveloperSecurity #ExtensionSecurity #VisualStudioCode
It’s worth understanding how this attack worked—and how to protect your organization. It’s off the Marketplace, but adversaries will absolutely try again.
buff.ly/TRAMPpN
#OpenSourceSecurity #DeveloperSecurity #CheckmarxZero 🧵5/5
Channel9 What's your preferred method for managing dependencies in your projects?: At Microsoft Build 2025, we asked attendees and some special guests about developer security. Learn more about developer security and the Secure Future Initiative… #DeveloperSecurity #SecureFuture #MicrosoftBuild2025
Channel9 Should people move old C++ to modern C++? #CPlusPlus #ModernCPP #DeveloperSecurity
📖 Read the full story:
www.technadu.com/tigerjack-ma...
#CyberSecurity #VSCode #Malware #SupplyChainAttack #DeveloperSecurity #TigerJack #Infosec
Channel9 What would make your life easier and your code more secure? #DeveloperSecurity #MicrosoftBuild #SecureCode
Channel9 Write your own meta prompt or default? #DeveloperSecurity #MicrosoftBuild #Coding
Channel9 What's your worst security related coding mistake? #CyberSecurity #CodingMistakes #DeveloperSecurity
Channel9 Developer Security Quick Fire Questions with Mark Russinovich and Scott Hanselman #DeveloperSecurity #MarkRussinovich #ScottHanselman
Amazon Q was silently hacked and no one noticed for 6 days. In our new #CybersideChats, we break down the attack & what it means for your org. youtu.be/qHQ4jdZ7mwI
#Cybersecurity #SupplyChain #AItools #DeveloperSecurity #CybersideChats #Infosec #GitHub #CISO
🆕 research on #genAI challenges for modern #appsec. as they need to support developer adoption of #AI, genAI and #chatbots
This is available for @esg_global clients but ping me to learn more
#cloudnativesecurity #applicationsecurity #developersecurity #devsecops
www.techtarget.com/esg-global/r...
Did you know that some of the popular VSCode extensions, have serious security vulnerabilities, and worse, some of them are actively trying to degrade the security posture of the host?
Developers have zero control
#vulnerability #developerSecurity #supplychainattack #permissionmodels #lackofsandbox