Fake Claude Code installer campaigns are abusing trusted developer workflows instead of exploiting software vulnerabilities.
Rhys Downing of Ontinue explains how attackers used fake documentation pages, modified install commands, PowerShell loaders, and browser compromise techniques to steal credentials and establish persistence.

“Developers are becoming a preferred target because they sit at the intersection of trust and access.”

Read more:
https://www.technadu.com/copy-paste-compromise-why-developer-workflows-need-new-guardrails/628593/

#Cybersecurity #ThreatResearch #Developers #ApplicationSecurity #Ontinue #SecureCoding

Vulnerable Code Proliferates as AI Exploits Rise in Supply Chains

The alarming truth is that 75% of organizations are knowingly shipping vulnerable code, despite the risks, with the window from disclosure to exploit shrinking dramatically from 840 days in 2018 to just under two days today. This trend is expected to accelerate, with exploits potentially available in as little as one minute by 2028.

https://osintsights.com/vulnerable-code-proliferates-as-ai-exploits-rise-in-supply-chains?utm_source=mastodon&utm_medium=social

#VulnerableCode #AiExploits #SupplyChain #ApplicationSecurity #ZeroDay

Vulnerable Code Proliferates as AI Exploits Rise in Supply Chains

Discover how AI exploits are fueling vulnerable code proliferation in supply chains and learn steps to protect your organization - read the expert insights now.

OSINTSights

Agentic AI Turbo Boosts Mobile App Attacks

The alarming rise of mobile app attacks is no longer looming on the horizon - it's here, with a staggering 87% of monitored apps facing threats in 2026, a drastic jump from 55% in 2022, fueled by the rapid adoption of AI models. This explosive growth in attacks is a wake-up call for businesses to bolster their mobile app security.

https://osintsights.com/agentic-ai-turbo-boosts-mobile-app-attacks?utm_source=mastodon&utm_medium=social

#AgenticAi #MobileAppAttacks #EmergingThreats #ApplicationSecurity #ArtificialIntelligence

Agentic AI Turbo Boosts Mobile App Attacks

Learn how agentic AI turbo boosts mobile app attacks, compromising 87% of apps. Discover the latest threat trends and protect your business now effectively.

OSINTSights
Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised | Wiz Blog

Detect and mitigate malicious npm packages linked to the latest Mini Shai-Hulud supply chain campaign targeting high-value developer tooling.

wiz.io

Socket Expands Supply-Chain Visibility with Secure Annex Acquisition

Socket is supercharging its supply-chain visibility with the acquisition of Secure Annex, a cutting-edge extension security startup, to give developers unprecedented control across the entire software development life cycle. This strategic move combines Socket's expertise in application dependencies with Secure Annex's…

https://osintsights.com/socket-expands-supply-chain-visibility-with-secure-annex-acquisition?utm_source=mastodon&utm_medium=social

#SupplyChain #ApplicationSecurity #SoftwareDevelopment #Acquisition #SecureAnnex

Socket Expands Supply-Chain Visibility with Secure Annex Acquisition

Learn how Socket expands supply-chain visibility with Secure Annex acquisition, enhancing software development life cycle control - read the details now.

OSINTSights

GlassWorm Malware Resurfaces Through 73 OpenVSX Extensions

Researchers at Socket have uncovered a sneaky new wave of GlassWorm malware, this time hiding in 73 OpenVSX extensions that behave like sleepers - seemingly harmless at first, but turning malicious after a stealthy update. Six of these extensions have already been activated, unleashing malware on unsuspecting developers.

https://osintsights.com/glassworm-malware-resurfaces-through-73-openvsx-extensions?utm_source=mastodon&utm_medium=social

#GlasswormMalware #Openvsx #MalwareOperations #EmergingThreats #ApplicationSecurity

GlassWorm Malware Resurfaces Through 73 OpenVSX Extensions

Discover how 73 OpenVSX extensions spread GlassWorm malware and learn how to protect yourself - read the latest threat analysis now.

OSINTSights

Anthropic's Claude Desktop sparks EU consent concerns

Can a single app really reach into your other software without asking for permission? The surprising behavior of Anthropic's Claude Desktop for macOS is raising eyebrows and sparking concerns about consent under EU law.

https://osintsights.com/anthropics-claude-desktop-sparks-eu-consent-concerns?utm_source=mastodon&utm_medium=social

#EuConsent #Macos #ApplicationSecurity #EmergingThreats #Gdpr

Anthropic's Claude Desktop sparks EU consent concerns

Anthropic's Claude Desktop raises EU consent concerns by interacting with other software without permission, learn more about the implications now.

OSINTSights

Together, these measures enhance your security posture by protecting against unauthorized access and potential vulnerabilities.

Read more 👉 https://lttr.ai/AqIiJ

#Security #Infosec #ApplicationSecurity

Leveraging Multiple Environments: Enhancing Application Security through Dev, Test, and Production Segregation

Tweet   Application security has never been more critical, as cyber threats loom large over every piece of software. To safeguard applications, segregation of development, testing, and production environments has emerged as a crucial strategy. This practice not only improves … Continue reading →

MSI :: State of Security