The GhostAction attack on GitHub saw 3,325 secrets stolen from 327 accounts, as attackers planted a malicious Actions workflow to snatch keys and tokens—here’s what happened and how it was stopped.
More than a dozen high-profile npm packages were compromised in a sweeping supply chain attack, affecting 2 billion weekly downloads and targeting crypto users—here’s what happened and how it works.