Bumblebee from Perplexity scans developer machines for compromised packages and AI tool configs, without triggering malware.
On May 11, 2026, a self-replicating worm called Mini Shai-Hulud quietly slipped into 42 widely used TanStack open-source packages, corrupting 84 npm artifacts before anyone noticed. Within hours, the ...
On April 29, 2026, someone slipped malicious code into four widely used SAP software packages. Within days, the infection had spread to at least 169 packages across the npm registry, the world’s ...
UiPath is downgraded to Hold due to revenue growth and risks around business model transition and competitive threats. Read ...
Late last year, software automation firm UiPath, Inc. (PATH) traded as close as around $20. In January, sellers emerged, continuing to dump the stock in February. In March, when the company posted ...
Google has released a new CLI for Google Workspace, offering a unified interface for various services like Drive, Gmail, and ...
A Bugcrowd researcher has unveiled ExploitBench, an independent benchmark of AI models for vulnerability exploitation ...
TanStack had 2FA, OIDC publishing, and Sigstore provenance on every release. The Mini Shai-Hulud worm published 84 malicious versions anyway. The CI/CD Trust-Chain Audit Grid maps the six gaps it ...
Cybersecurity researchers at Aikido Security have uncovered a malicious supply chain attack targeting OpenAI Codex developers via the npm package “codexui-android”. While the associated GitHub ...
Call options grant the right to buy stocks at a set price until expiration; puts allow selling. Options expire worthless if stock doesn't reach breakeven, risking the premium paid. Selling options can ...