Sigstore is a tool tracked across 6 threat clusters and 7 intelligence report mentions on ThreatCluster. First observed April 21, 2026; most recent activity July 8, 2026.
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
On May 20, 2026, GitHub confirmed a significant security breach involving a poisoned Visual Studio Code (VS Code) extension that compromised an employee's device. The attack, attributed to the TeamPCP hacking group,…
On May 19, 2026, GitHub announced an investigation into unauthorized access to internal repositories after a malicious Visual Studio Code extension was executed on an employee's device. The attack, attributed to the…
OpenAI has introduced GPT-5.4-Cyber, a specialized AI model for defensive cybersecurity, available only to vetted professionals through its Trusted Access for Cyber (TAC) program. This model is designed to facilitate…
Chainguard and Cursor have partnered to improve security in agentic software development by providing secure-by-default open source artifacts. This collaboration aims to close the software supply chain trust gap, as 84%…
On May 21, 2026, the Open Source Security Foundation (OpenSSF) announced the addition of five new members and the launch of new security resources during its Community Day in Minneapolis. The foundation aims to enhance…