Hacker Newsnew | past | comments | ask | show | jobs | submit | fromlogin
RubyGems Supply Chain Attack (aikido.dev)
2 points by knappe 5 hours ago | past | discuss
Aikido Code Audit (aikido.dev)
38 points by ilreb 31 days ago | past | 14 comments
Multiple JetBrains IDE plugins caught stealing AI keys (aikido.dev)
34 points by sschueller 33 days ago | past | 5 comments
Critical auth bypass vulnerability in phpBB (aikido.dev)
2 points by Tiberium 39 days ago | past | 1 comment
Red Hat NPM Packages Compromised to Spread a Credential-Stealing Worm (aikido.dev)
2 points by oidong1 49 days ago | past
Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer (aikido.dev)
2 points by nullbio 58 days ago | past | 1 comment
Google API keys keep working after you delete them (aikido.dev)
3 points by dsr12 59 days ago | past
Google API keys will keep working after you delete them (aikido.dev)
4 points by berlianta 60 days ago | past
Microsoft's Durabletask Package on PyPI Compromised. Mini Shai Hulud (aikido.dev)
3 points by mjtk 62 days ago | past
Mini Shai-Hulud Is Back: NPM Worm Hits over 160 Packages, Including Mistral (aikido.dev)
2 points by cebert 69 days ago | past | 1 comment
NPM supply-chain attack is targeting the SAP developer ecosystem (aikido.dev)
1 point by raffael_de 81 days ago | past | 1 comment
GPT-Proxy Backdoor in NPM and PyPI Turns Servers into Chinese LLM Relays (aikido.dev)
4 points by lschueller 89 days ago | past
Axios vulnerability with CVSS 10 over stated? (aikido.dev)
1 point by oofbey 3 months ago | past | 1 comment
[dupe] Telnyx package compromised on PyPI (aikido.dev)
85 points by overflowy 3 months ago | past | 1 comment
TeamPCP deploys CanisterWorm on NPM following Trivy compromise (aikido.dev)
3 points by Shank 3 months ago | past
Glassworm is back: A new wave of invisible Unicode attacks hits repositories (aikido.dev)
303 points by robinhouston 4 months ago | past | 193 comments
I wrote Gitleaks, now I'm maintaining Betterleaks (aikido.dev)
15 points by zricethezav 4 months ago | past | 3 comments
Aikido launches infinite pentesting – Automated pentesting on every release (aikido.dev)
11 points by advocatemack 4 months ago | past
AI Agents discovered a cache deception bug affecting SvelteKit on Vercel (aikido.dev)
2 points by advocatemack 5 months ago | past
Fake Clawdbot VS Code Extension Installs ScreenConnect Rat (aikido.dev)
1 point by askl 5 months ago | past
Malicious PyPI Packages Spellcheckpy and Spellcheckerpy Deliver Python Rat (aikido.dev)
1 point by birdculture 5 months ago | past
Shai Hulud strikes again – The golden path (aikido.dev)
4 points by gpi 6 months ago | past
PromptPwnd: Prompt Injection Vulnerabilities in GitHub Actions Using AI Agents (aikido.dev)
2 points by devy 7 months ago | past | 1 comment
Prompt injection through GitHub Action workflow impacts Gemini and others (aikido.dev)
4 points by advocatemack 7 months ago | past | 1 comment
Safe Chain: Stopping Malicious NPM Packages Before They Wreck Your Project (aikido.dev)
16 points by nailer 7 months ago | past | 2 comments
Shai Hulud launches second supply-chain attack (aikido.dev)
352 points by birdculture 7 months ago | past | 23 comments
Self-Replicating NPM Package Supply Chain Worm 'Shai Hulud' (aikido.dev)
2 points by oli5679 10 months ago | past
Safe Chain: Stopping Malicious NPM Packages Before They Wreck Your Project (aikido.dev)
2 points by danfritz 10 months ago | past
S1ngularity/nx attackers strike again (aikido.dev)
1 point by ebfe1 10 months ago | past | 1 comment
Popular NX packages compromised on NPM (aikido.dev)
3 points by xtracto 10 months ago | past

Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: