
I just watched a video about this yesterday. At the start of the video I immediately thought "It's Russia".
17 bugs in 10 weeks from AI security scanning
9d 13h ago by programming.dev/u/codeinabox in security@programming.dev from lalitm.comWhy Hardened Images are Suddenly Everywhere
15d 13h ago by programming.dev/u/codeinabox in security@programming.dev from redmonk.comTyposquatted npm packages used to steal cloud and CI/CD secrets
19d 19h ago by programming.dev/u/codeinabox in security@programming.dev from www.microsoft.comThe approval prompt is lying: a critical coding agent security flaw
20d 19h ago by programming.dev/u/codeinabox in security@programming.dev from adversa.aiGitHub Actions Cache Poisoning is eating open source
1mon 1d ago by programming.dev/u/codeinabox in security@programming.dev from neciudan.devMythos finds a curl vulnerability
1mon 7d ago by programming.dev/u/codeinabox in security@programming.dev from daniel.haxx.seWhy “Trusted Publishing” Can’t Save Us from Social Engineering
1mon 11d ago by programming.dev/u/codeinabox in security@programming.dev from adventures.nodeland.devYour Container Is Not a Sandbox
1mon 12d ago by programming.dev/u/codeinabox in security@programming.dev from emirb.github.ioArbitrary code execution and Claude Code CLI: How Claude executed code before you click 'trust'
1mon 18d ago by programming.dev/u/codeinabox in security@programming.dev from www.sonarsource.comAt Machine Speed
1mon 19d ago by programming.dev/u/codeinabox in security@programming.dev from matthiasott.comOpen source package with 1 million monthly downloads stole user credentials
1mon 21d ago by discuss.tchncs.de/u/schnurrito in security@programming.dev from arstechnica.comNpm Slop & Wonky Software Supply Chains
1mon 22d ago by programming.dev/u/codeinabox in security@programming.dev from simonramstedt.comMythos Mystery in Mozilla Numbers: How 22 Vulns Became 271 or Maybe 3 in April
1mon 24d ago by programming.dev/u/codeinabox in security@programming.dev from www.flyingpenguin.comThe Vercel breach started at a tool nobody was watching
1mon 27d ago by programming.dev/u/codeinabox in security@programming.dev from siddhantkhare.compompelmi – ClamAV antivirus scanning for Node.js, zero dependencies
1mon 27d ago by programming.dev/u/justsouichi in security@programming.dev from github.comAnthropic secretly installs spyware when you install Claude Desktop
1mon 28d ago by programming.dev/u/codeinabox in security@programming.dev from www.thatprivacyguy.comWe Reproduced Anthropic's Mythos Findings With Public Models
2mon 1d ago by programming.dev/u/codeinabox in security@programming.dev from blog.vidocsecurity.comThe Boy That Cried Mythos: Verification is Collapsing Trust in Anthropic
2mon 2d ago by programming.dev/u/codeinabox in security@programming.dev from www.flyingpenguin.comCybersecurity Looks Like Proof of Work Now
2mon 3d ago by programming.dev/u/codeinabox in security@programming.dev from www.dbreunig.comDependency cooldowns turn you into a free-rider
2mon 3d ago by programming.dev/u/codeinabox in security@programming.dev from calpaterson.comAI “Watershed Moment” or expensive pen tester? The AISI Mythos Data
2mon 4d ago by programming.dev/u/codeinabox in security@programming.dev from blog.robbowley.netOur evaluation of Claude Mythos Preview’s cyber capabilities
2mon 4d ago by programming.dev/u/codeinabox in security@programming.dev from www.aisi.gov.ukNo one owes you supply-chain security
2mon 6d ago by programming.dev/u/codeinabox in security@programming.dev from purplesyringa.moeGoogle rolls out end-to-end encryption for Gmail on Android and iOS devices for enterprise users, letting them read and compose emails without additional tools
2mon 7d ago by lemmy.world/u/Innerworld in security@programming.dev from www.bleepingcomputer.comPackage Security Problems for AI Agents
2mon 9d ago by programming.dev/u/codeinabox in security@programming.dev from nesbitt.ioAssessing Claude Mythos Preview’s cybersecurity capabilities
2mon 10d ago by programming.dev/u/codeinabox in security@programming.dev from red.anthropic.comMinimum Release Age is an Underrated Supply Chain Defense
2mon 10d ago by programming.dev/u/codeinabox in security@programming.dev from daniakash.comBounty Available (>$2,000) for QubesOS BusKill package
2mon 11d ago by lemdro.id/u/buskill in security@programming.dev from www.buskill.inOpenClaw gives users yet another reason to be freaked out about security
2mon 14d ago by programming.dev/u/codeinabox in security@programming.dev from arstechnica.comStop Committing Your Secrets (You Know Who You Are)
2mon 14d ago by programming.dev/u/codeinabox in security@programming.dev from jfmaes.meDon’t let A.I. read your .env files
2mon 15d ago by programming.dev/u/codeinabox in security@programming.dev from filiphric.comAfterPack: Claude Code's Source Didn't Leak. It Was Already Public for Years.
2mon 17d ago by lemmy.world/u/artwork in security@programming.devSupply Chain Attack on Axios Pulls Malicious Dependency from npm
2mon 18d ago by programming.dev/u/codeinabox in security@programming.dev from socket.devShinyHunters says it stole 350GB+ of data in a cyberattack on the European Commission, detected on March 24; the EC says its internal systems were not affected
2mon 20d ago by lemmy.world/u/Innerworld in security@programming.dev from securityaffairs.comHundreds of Millions of iPhones Can Be Hacked With a New Tool Found in the Wild
2mon 22d ago by lemmy.world/u/Innerworld in security@programming.dev from www.wired.comIranian-linked hackers claimed responsibility for the breach of FBI Direct Kash Patel’s personal email account
2mon 22d ago by lemmy.world/u/Innerworld in security@programming.dev from www.reuters.comTrivy Under Attack Again: Widespread GitHub Actions Tag Compromise Exposes CI/CD Secrets
2mon 22d ago by programming.dev/u/Kissaki in security@programming.dev from socket.devCompromised telnyx on PyPI: WAV Steganography and Credential Theft
2mon 22d ago by programming.dev/u/Kissaki in security@programming.dev from safedep.ioHackers have exposed more than 8.3 million supposedly confidential reports to tip lines like Crime Stoppers
2mon 22d ago by lemmy.world/u/Innerworld in security@programming.dev from san.comTeamPCP deploys CanisterWorm on NPM following Trivy compromise
2mon 23d ago by programming.dev/u/codeinabox in security@programming.dev from www.aikido.devThousands of websites are accidentally broadcasting sensitive data
2mon 23d ago by lemmy.world/u/Innerworld in security@programming.dev from techxplore.comDelve - Fake Compliance as a Service
2mon 25d ago by programming.dev/u/Kissaki in security@programming.dev from deepdelver.substack.comUS State Department launches the Bureau of Emerging Threats to tackle current and future threats, including cyberattacks and AI weaponization by adversaries
2mon 25d ago by lemmy.world/u/Innerworld in security@programming.dev from abcnews.comDoJ has taken down botnets behind the largest-ever DDoS attack
2mon 29d ago by lemmy.world/u/Innerworld in security@programming.dev from www.wired.comCountries with Most Personal Records Leaked in Data Breaches (2004-2025)
3mon 10d ago by lemmy.world/u/Innerworld in security@programming.dev from www.voronoiapp.comMicrosoft, working with Europol, authorities from 6 countries, and 11 security organizations, disrupted the Tycoon 2FA phishing-as-a-service platform on seizing 330 domains
3mon 13d ago by lemmy.world/u/Innerworld in security@programming.dev from www.microsoft.comA ransomware attack on August 31, 2025, compromised the data of 1.2 million at the University of Hawaiʻi Cancer Center, targeting research servers but sparing clinical operations
3mon 14d ago by lemmy.world/u/Innerworld in security@programming.dev from www.securityweek.comFrance's health ministry has confirmed a data breach involving the exposure of administrative information for 15.8 million patients and sensitive doctors' notes for approximately 165,000 individuals
3mon 14d ago by lemmy.world/u/Innerworld in security@programming.dev from www.france24.comAuthorities from 14 countries shut down LeakBase, seize its domains, and arrest multiple people allegedly tied to the cybercrime forum, which had 142K+ members
3mon 14d ago by lemmy.world/u/Innerworld in security@programming.dev from cyberscoop.com



































