Developer tooling is now part of the attack surface
Unit 42 says software supply chain attacks are moving deeper into the software development lifecycle, beyond finished application code. Its August 2026 research describes attackers targeting CI/CD pipelines, package ecosystems, developer...
A supply chain worm targets developer trust
Unit 42 says a self-propagating npm worm called ChainDrop infected more than 400 packages and reached software used at very large scale. The reported campaign is significant because it targets the systems developers rely on to build, test and publish...
Stolen AI API Keys Become a Billing and Abuse Risk
Unit 42 says cybercriminals are stealing developer API keys for AI platforms and using them to consume or resell model access. The security team describes the activity as token jacking, an AI-focused version of stealing access to paid computing...
Open source packages move to the center of supply chain risk
Google Threat Intelligence Group and Mandiant say large-scale open source software supply chain compromise expanded sharply across 2025 and early 2026. The report points to package repositories, developer tools and CI/CD workflows as...
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.