The threat situation in the software supply chain is intensifying. Securing it belongs at the top of the CISO’s agenda.
A critical vm2 Node.js vulnerability (CVE-2026-22709, CVSS 9.8) allows sandbox escape via Promise handler bypass.
A critical-severity vulnerability in the vm2 Node.js sandbox library, tracked as CVE-2026-22709, allows escaping the sandbox and executing arbitrary code on the underlying host system.
Vulnerabilities in the NPM, PNPM, VLT, and Bun package managers could lead to protection bypasses and arbitrary code ...
A new breed of malware uses various dynamic techniques to avoid detection and create customized phishing webpages.
The Good Boy delves into the mind games that ensue when a seemingly respectable married couple (Emmy and Golden Globe winner ...
According to Sam Altman (@sama), a much faster version of OpenAI Codex is coming soon, signaling a significant leap in AI-powered code generation speed and efficiency (source: Twitter, 2026-01-16).
We’ve held off on discussing AI as long as we could, but we’re only human. It was the topic of 2025 (not only in retail), and its impact on the industry’s ecosystem looks set to expand even further in ...