The npm incident frightened everyone, but ended up being nothing to fret about
A social-engineering compromise of an npm maintainer briefly poisoned 18 popular packages, but quick detection and response limited the supply-chain attack’s impact and damage.
Rayhunter detects cell-site simulators on mobile hotspots and community deployments have found CSS elsewhere but not evidence of CSS spying on US protests so far.
Google Veles is a New Open-source Secret Scanner Powering GCP
Google released Veles, an open-source secret scanner that detects exposed credentials across artifacts and integrates with OSV-SCALIBR and Google Cloud security products.