Back to Blog

#Developer Security

7 posts
One-Click github.dev Attack Lets Malicious Repos Steal Full GitHub Tokens

One-Click github.dev Attack Lets Malicious Repos Steal Full GitHub Tokens

One-Click github.dev Attack Lets Malicious Repos Steal Full GitHub Tokens | 2026 Executive Summary Security researcher Ammar Askar disclosed a one-click attack...

June 3, 2026
7 min read
GlassWorm takedown shows how developer malware becomes supply-chain risk

GlassWorm takedown shows how developer malware becomes supply-chain risk

GlassWorm takedown shows how developer malware becomes supply-chain risk Executive Summary The coordinated disruption of GlassWorm on May 26, 2026 is useful bec...

May 30, 2026
6 min read
GitHub GHES Signing Key Rotation Puts Admins on the Clock

GitHub GHES Signing Key Rotation Puts Admins on the Clock

GitHub GHES Signing Key Rotation Puts Admins on the Clock Executive Summary GitHub warned on May 26, 2026 that administrators running GitHub Enterprise Server (...

May 29, 2026
6 min read
GitHub Action tag hijack turns CI/CD runs into credential theft

GitHub Action tag hijack turns CI/CD runs into credential theft

GitHub Action tag hijack turns CI/CD runs into credential theft A fresh GitHub Actions supply chain incident is a good reminder that "pinned" does not mean safe...

May 19, 2026
6 min read
GlassWorm sleeper extensions turn Open VSX updates into a malware delivery path

GlassWorm sleeper extensions turn Open VSX updates into a malware delivery path

GlassWorm sleeper extensions turn Open VSX updates into a malware delivery path The newest GlassWorm wave matters because it turns the normal extension update p...

April 28, 2026
5 min read
GlassWorm Shifts to Transitive Open VSX Dependencies in Developer Supply-Chain Push

GlassWorm Shifts to Transitive Open VSX Dependencies in Developer Supply-Chain Push

GlassWorm Shifts to Transitive Open VSX Dependencies in Developer Supply-Chain Push GlassWorm is no longer just a story about obviously malicious extensions. Th...

March 21, 2026
5 min read
Cline CLI 2.3.0 supply chain attack silently installed OpenClaw on developer systems

Cline CLI 2.3.0 supply chain attack silently installed OpenClaw on developer systems

Cline CLI 2.3.0 supply chain attack silently installed OpenClaw on developer systems Executive summary The Cline CLI supply chain incident is a practical remind...

March 19, 2026
5 min read