Axios npm supply chain attack: Malicious updates add remote access trojanLaura FrenchMarch 31, 2026The axios npm package, with about 100 million weekly downloads, was compromised via a maintainer’s account.
China-linked groups conduct sophisticated cyber espionage against Southeast Asian governmentSC StaffMarch 31, 2026
AI/MLOpenAI fixes Codex flaw that could lead to GitHub token theftLaura FrenchMarch 31, 2026A command injection hidden in a branch name could cause an OAuth token to be exfiltrated.
Network SecurityF5 BIG-IP APM DoS bug exploited as an RCE, added to CISA listSteve ZurierMarch 30, 2026Flaw upgraded to an actively exploited RCE, experts advise teams to patch right away.
RSACBSides SF: SaaS, cloud assets vulnerable to identity-based ransomware attacksPaul WagenseilMarch 28, 2026It's easy to mount ransomware attacks upon SaaS and cloud assets, a researcher said at the BSides SF 2026 hacker conference.
RSACWormsign, RSAC 2026: More auto-updating supply chain attacks on the wayPaul WagenseilMarch 28, 2026The Shai-Hulud worms that exploited automatic updates in open-source software repositories may be only the beginning, two researchers said at RSAC 2026.
RSACRSAC 2026: Treat AI like a ‘junior developer’ to catch coding errorsLaura FrenchMarch 27, 2026OX Security found AI coding assistants make the same common mistakes as humans.
Vulnerability ManagementCritical Langflow AI bug exploited within 20 hours added to CISA listSteve ZurierMarch 27, 2026Experts warn that the timeframe between disclosure and exploitation will continue to shrink, so teams must prepare.
RSACIdentity at RSAC 2026: Continuous, AI-ready and quantum-safeLaura FrenchMarch 27, 2026Identity talks in San Francisco focused on new realities challenging traditional authentication schemes.
RSACRSAC 2026: We’re entering the age of ‘integrous’ systemsPaul WagenseilMarch 26, 2026In an AI-driven world, says Bruce Schneier, guaranteeing the integrity of data is more important than ever.