Explore real-world engineering experiences from top tech companies.
Receive daily AI-curated summaries of engineering articles from top tech companies worldwide.
Researchers uncovered a malicious npm campaign called Ghost/GhostClaw using 7 fake packages to steal cryptocurrency wallets and developer credentials.
TeamPCP, the threat actor behind the Trivy supply chain attack, has compromised two Checkmarx GitHub Actions workflows using credentials stolen from the earlier breach.
This article argues that cybersecurity specialization, without foundational context, leads to fragmented risk understanding and program drift.
Google Chrome Enterprise showcases five security enhancements at RSA to protect corporate data in the AI era.
A Russian hacker was sentenced to 6.75 years in U.S.
Citrix has released security updates for two vulnerabilities in NetScaler ADC and NetScaler Gateway, including a critical memory leak flaw.
Stripe Radar now offers a one-click solution to prevent free trial abuse, powered by a new AI model trained on payment and device data across Stripe's network.
This article covers a supply chain compromise involving Trivy, a widely-used open-source security scanning tool, and its implications for Docker Hub users.
This article covers a new malware campaign by North Korean threat actors (WaterPlum/Contagious Interview) using malicious VS Code projects to deploy the StoatWaffle malware.
Google Threat Intelligence introduces a new dark web intelligence capability powered by Gemini to filter noise and surface relevant threats automatically.
Google Security unveils AI-powered agentic defense capabilities at RSAC 2026, built on Gemini models to help defenders respond at machine speed.
Mandiant's M-Trends 2026 report analyzes over 500,000 hours of frontline incident investigations in 2025, revealing major shifts in adversary tactics and cyber threat trends.