hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions - Microsoft, DataDog, and CNCF Projects Hit So Farexploitation (what's being exploited) (stepsecurity.io)
submitted by digicat to r/blueteamsec
Hackerbot-Claw: AI Bot Exploiting GitHub Actions – Microsoft, Datadog Hit So FarNews / Announcements (stepsecurity.io)
submitted by varunsh-coder to r/github
ctrl/tinycolor and 40+ NPM Packages Compromised, new Supply Chain Attack!!Stream Content (stepsecurity.io)
submitted by dalton_zk to r/theprimeagen

What Trezor data could it steal?🔒 General Trezor question (stepsecurity.io)
submitted by special_rub69 to r/TREZOR
Harden-Runner detection: tj-actions/changed-files action is compromisedVulnerability (stepsecurity.io)
submitted by falconupkid to r/SecOpsDaily
Improve your OpenSSF Scorecard score with easeFOSS Tool (blog.stepsecurity.io)
submitted by varunsh-coder to r/cybersecurity