OpenAI推出新项目以AI强化软件安全防御
OpenAI 正在推出 Daybreak,这是一项专注于在攻击者发现漏洞之前检测并修补它们的AI计划。Daybreak使用三月推出的Codex安全AI智能体,基于一家组织的代码创建威胁模型,聚焦可能的
A significant supply-chain compromise affecting 84 npm package artifacts across the TanStack namespace. The malicious versions, published to the npm registry at approximately 19:20 and 19:26 UTC, contain a suspected credential-stealing payload targeting CI systems, including GitHub Actions. According to Socket, the compromise spans 42 TanStack packages — two malicious versions each including widely used […]
The post 84 TanStack npm Packages Hacked in Ongoing Supply-Chain Attack Targeting CI Credentials appeared first on Cyber Security News.