Heykuki News
Top
New
Best
Ask
Show
Jobs
Toggle theme
Login
Top
New
Best
Ask
Show
Jobs
1.
▲
Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised
(socket.dev)
1233 points
jamesberthoty
9 months ago
1019 comments
2.
▲
Shai-Hulud Returns: Over 300 NPM Packages Infected
(helixguard.ai)
1038 points
mrdosija
6 months ago
775 comments
3.
▲
Telnyx package compromised on PyPI
(telnyx.com)
133 points
ramimac
2 months ago
135 comments
4.
▲
Show HN: Just raised $17M for a no BS application security platform
15 points
flxga
2 years ago
10 comments
5.
▲
NPM debug and chalk packages compromised
(aikido.dev)
1372 points
universesquid
9 months ago
757 comments
6.
▲
Shai Hulud launches second supply-chain attack
(aikido.dev)
352 points
birdculture
6 months ago
23 comments
7.
▲
Glassworm is back: A new wave of invisible Unicode attacks hits repositories
(aikido.dev)
303 points
robinhouston
3 months ago
193 comments
8.
▲
Telnyx package compromised on PyPI
(aikido.dev)
85 points
overflowy
2 months ago
1 comment
9.
▲
Offical XRP NPM package has been compromised and key stealing malware introduced
(aikido.dev)
55 points
flxga
a year ago
17 comments
10.
▲
Safe Chain: Stopping Malicious NPM Packages Before They Wreck Your Project
(aikido.dev)
16 points
nailer
6 months ago
2 comments
11.
▲
I wrote Gitleaks, now I'm maintaining Betterleaks
(aikido.dev)
15 points
zricethezav
3 months ago
3 comments
12.
▲
Aikido launches infinite pentesting – Automated pentesting on every release
(aikido.dev)
11 points
advocatemack
3 months ago
discuss
13.
▲
Malware hiding in plain sight: Spying on North Korean Hackers
(aikido.dev)
8 points
thunderbong
a year ago
discuss
14.
▲
RATatouille: A Malicious Recipe Hidden in rand-user-agent
(aikido.dev)
6 points
thunderbong
a year ago
discuss
15.
▲
The State of SQL Injection Today
(aikido.dev)
5 points
advocatemack
2 years ago
discuss
16.
▲
Prompt injection through GitHub Action workflow impacts Gemini and others
(aikido.dev)
4 points
advocatemack
6 months ago
1 comment
17.
▲
GPT-Proxy Backdoor in NPM and PyPI Turns Servers into Chinese LLM Relays
(aikido.dev)
4 points
lschueller
a month ago
discuss
18.
▲
Shai Hulud strikes again – The golden path
(aikido.dev)
4 points
gpi
5 months ago
discuss
19.
▲
Delivering malware via Google Calendar invites and PUAs in an NPM package
(aikido.dev)
4 points
todsacerdoti
a year ago
discuss
20.
▲
Microsoft's Durabletask Package on PyPI Compromised. Mini Shai Hulud
(aikido.dev)
3 points
mjtk
16 days ago
discuss
21.
▲
TeamPCP deploys CanisterWorm on NPM following Trivy compromise
(aikido.dev)
3 points
Shank
2 months ago
discuss
22.
▲
Popular NX packages compromised on NPM
(aikido.dev)
3 points
xtracto
9 months ago
discuss
23.
▲
What is OWASP Top 10, and do you need it to secure your application?
(aikido.dev)
3 points
flxga
3 years ago
discuss
24.
▲
Mini Shai-Hulud Is Back: NPM Worm Hits over 160 Packages, Including Mistral
(aikido.dev)
2 points
cebert
22 days ago
1 comment
25.
▲
PromptPwnd: Prompt Injection Vulnerabilities in GitHub Actions Using AI Agents
(aikido.dev)
2 points
devy
6 months ago
1 comment
26.
▲
AI Agents discovered a cache deception bug affecting SvelteKit on Vercel
(aikido.dev)
2 points
advocatemack
4 months ago
discuss
27.
▲
Self-Replicating NPM Package Supply Chain Worm 'Shai Hulud'
(aikido.dev)
2 points
oli5679
8 months ago
discuss
28.
▲
Safe Chain: Stopping Malicious NPM Packages Before They Wreck Your Project
(aikido.dev)
2 points
danfritz
9 months ago
discuss
29.
▲
NPM supply-chain attack is targeting the SAP developer ecosystem
(aikido.dev)
1 point
raffael_de
a month ago
1 comment
30.
▲
Axios vulnerability with CVSS 10 over stated?
(aikido.dev)
1 point
oofbey
2 months ago
1 comment
More