A recent compromise of the widely-used axios HTTP client library: npm supply chains can be leveraged to drop cross-platform RATs
Tomer Filiba
|
min read
A deep dive into the Trivy supply chain attack and how CI/CD pipelines were exploited to steal credentials. Learn key indicators, risks, and
Sweet team
5
A standard Kubernetes permission has been identified as a direct path to a cluster-wide RCE.
3
A massive supply-chain attack is affecting npm packages.