GhostAction Returns: Malicious "Security Audit" Workflows Now Mine Credentials from Entire Git Histories #Security #DevSecOps #GitHubActions
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382800Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382800Copy
Don't have an account? Find a server at joinmastodon.org
Oct 9, 2026 StepSecurity Now Inventories AI Agent Skills in Your GitHub Repositories and on Developer Machines #AISecurity #DevOps #GitHub
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382811Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382811Copy
Don't have an account? Find a server at joinmastodon.org
Oct 8, 2026 Tensorlake npm Package Compromised: A Worm With a Hostage Token That Wipes Your Machine If You Revoke It #Security #SupplyChain #Malware
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382819Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382819Copy
Don't have an account? Find a server at joinmastodon.org
Oct 8, 2026 SubQuery Ecosystem Compromise: Hidden Credential Theft and Backdoors #CyberSecurity #DevSecOps #SoftwareSupplyChain
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382832Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382832Copy
Don't have an account? Find a server at joinmastodon.org
Oct 5, 2026 Sckit Supply Chain Worm Hits MemTensor npm & PyPi scopes #Security #SupplyChain #DevSecOps
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382837Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382837Copy
Don't have an account? Find a server at joinmastodon.org
Sep 30, 2026 Introducing deny list egress policies for Harden-Runner #Security #DevOps #OpenSource
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382856Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382856Copy
Don't have an account? Find a server at joinmastodon.org
Sep 2, 2026 Runtime Security for AWS CodeBuild-Hosted GitHub Actions Runners #DevSecOps #CloudSecurity #GitHubActions
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382851Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382851Copy
Don't have an account? Find a server at joinmastodon.org
Sep 2, 2026 @7nohe/openapi-react-query-codegen Compromised Through an Exposed npm Publishing Workflow #Security #SupplyChain #DevOps
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382865Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382865Copy
Don't have an account? Find a server at joinmastodon.org
Aug 28, 2026 Dev Machine Guard Now Inventories Browser Extensions on Developer Machines #Security #DevOps #SoftwareSupplyChain
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382889Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382889Copy
Don't have an account? Find a server at joinmastodon.org
Aug 28, 2026 Dev Machine Guard Now Inventories Where Developer Credentials Live #Security #DevOps #Credentials
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382879Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382879Copy
Don't have an account? Find a server at joinmastodon.org
Aug 28, 2026 The State of Open Source Supply Chain Attacks #OpenSource #Security #DevOps
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382899Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382899Copy
Don't have an account? Find a server at joinmastodon.org
Aug 23, 2026 Rust Supply-Chain Attack: arrayref, internment, and append-only-vec Poisoned by the proc-macro1 Build-Time Dropper #CyberSecurity #RustLang #OpenSource
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382910Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382910Copy
Don't have an account? Find a server at joinmastodon.org
Aug 22, 2026 ChainDrop npm Worm: Bun-loaded CI/CD credential harvester with Ethereum dead-drop C2 #CyberSecurity #SupplyChain #DevOps
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382919Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382919Copy
Don't have an account? Find a server at joinmastodon.org
Aug 16, 2026 Team PCP Stole 78,330 Secrets From 2,186 Organizations. CloudSEK Just Published the List. #CyberSecurity #SupplyChain #DevSecOps
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382927Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382927Copy
Don't have an account? Find a server at joinmastodon.org
Aug 15, 2026 Control Which Package Registries Your CI Jobs and Developer Machines Use #Security #DevOps #CICD
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382936Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382936Copy
Don't have an account? Find a server at joinmastodon.org
Aug 12, 2026 Anthropic Incident: An AI Agent Published a Malicious Package to PyPI and 15 Real Systems Ran It #Security #AI #SupplyChain
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382946Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382946Copy
Don't have an account? Find a server at joinmastodon.org
Aug 3, 2026 Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan #SupplyChain #Security #OpenSource
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382965Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382965Copy
Don't have an account? Find a server at joinmastodon.org
Jul 30, 2026 Dev Machine Guard Now Inventories AI Agent Skills on Developer Machines #Security #AI #DevOps
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382956Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382956Copy
Don't have an account? Find a server at joinmastodon.org
Jul 30, 2026 2026 Mid-Year Update: On Pace for Our Biggest Year Yet #Security #DevSecOps #SoftwareSupplyChain
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382974Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382974Copy
Don't have an account? Find a server at joinmastodon.org
Jul 28, 2026 Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud, and Kubernetes Credentials #Security #SupplyChain #OpenSource
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382984Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382984Copy
Don't have an account? Find a server at joinmastodon.org
Jul 25, 2026 Find Unused, Stale, and OIDC-Replaceable GitHub Actions Secrets Across Your GitHub Organization #Security #DevOps #GitHub
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382994Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22382994Copy
Don't have an account? Find a server at joinmastodon.org
Jul 23, 2026 SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor #CyberSecurity #OpenSource #DevSecOps
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383004Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383004Copy
Don't have an account? Find a server at joinmastodon.org
Jul 19, 2026 Introducing Secret Exfiltration Protection for GitHub Actions #Security #GitHubActions #DevSecOps
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383053Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383053Copy
Don't have an account? Find a server at joinmastodon.org
Jul 16, 2026 Coordinated AsyncAPI Supply Chain Attack: Miasma RAT Delivered via Compromised CI/CD Pipelines in Two Repositories #CyberSecurity #SupplyChain #DevOps
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383044Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383044Copy
Don't have an account? Find a server at joinmastodon.org
Jul 16, 2026 Introducing Device Policy: Enforce Approved VS Code Extensions Across Your Fleet #Security #DevOps #VSCode
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383032Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383032Copy
Don't have an account? Find a server at joinmastodon.org
Jul 16, 2026 Harden-Runner Block Mode Now Available for macOS and Windows GitHub-Hosted Runners #Security #DevOps #GitHub
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383025Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383025Copy
Don't have an account? Find a server at joinmastodon.org
Jul 16, 2026 Runtime Security for Third-Party GitHub Actions Runners: Bitrise, Blacksmith, Depot, Namespace, and Warp #Security #DevOps #GitHub
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383015Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383015Copy
Don't have an account? Find a server at joinmastodon.org
Jul 16, 2026 GitHub Secret Scanning Public Monitoring for Enterprises: Coverage and Gaps #Security #GitHub #DevOps
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383083Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383083Copy
Don't have an account? Find a server at joinmastodon.org
Jul 12, 2026 Injective npm Supply Chain Attack: 18 Packages Backdoored to Steal Crypto Wallet Keys #CyberSecurity #SupplyChain #OpenSource
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383073Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383073Copy
Don't have an account? Find a server at joinmastodon.org
Jul 12, 2026 jscrambler npm package publishes malicious preinstall binary #Security #SupplyChain #Malware
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383063Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383063Copy
Don't have an account? Find a server at joinmastodon.org
Jul 12, 2026 10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Supply Chain Attack on GitHub Actions #Security #SupplyChain #GitHubActions
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383106Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383106Copy
Don't have an account? Find a server at joinmastodon.org
Jul 2, 2026 StepSecurity Maintained Actions Are Now Free for Public Repos #OpenSource #DevSecOps #GitHubActions
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383093Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383093Copy
Don't have an account? Find a server at joinmastodon.org
Jul 2, 2026 15 Malicious JetBrains Plugins Stole AI API Keys from 70,000 Developers #CyberSecurity #AI #DevTools
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383173Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383173Copy
Don't have an account? Find a server at joinmastodon.org
Jul 1, 2026 codfish/semantic-release-action GitHub Action has been compromised #Security #SupplyChain #GitHubActions
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383162Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383162Copy
Don't have an account? Find a server at joinmastodon.org
Jul 1, 2026 simonecorsi/mawesome GitHub Action has been compromised #Security #OpenSource #GitHub
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383152Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383152Copy
Don't have an account? Find a server at joinmastodon.org
Jul 1, 2026 Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised #CyberSecurity #SupplyChain #NPM
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383143Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383143Copy
Don't have an account? Find a server at joinmastodon.org
Jul 1, 2026 Maven Support Comes to GitHub Checks and OSS Package Search #DevSecOps #GitHub #Maven
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383133Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383133Copy
Don't have an account? Find a server at joinmastodon.org
Jul 1, 2026 Multiple @immobiliarelabs Backstage Plugins Compromised on npm #Security #SupplyChain #OpenSource
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383124Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383124Copy
Don't have an account? Find a server at joinmastodon.org
Jul 1, 2026 Secure Registry now tells you which machine pulled a compromised package #Security #DevSecOps #SupplyChain
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383115Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383115Copy
Don't have an account? Find a server at joinmastodon.org
Jul 1, 2026 Miasma and Hades Are Spreading Now: Detect Them on Developer Machines with Suspicious Files #CyberSecurity #Malware #DevSecOps
0Boost from your server Enter the server your account is on. The post opens there so you can boost it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383212Copy
Don't have an account? Find a server at joinmastodon.org
0Favorite from your server Enter the server your account is on. The post opens there so you can favorite it.
or
Or paste this post's address into your app's search: https://robot.villas/users/stepsecurity/posts/22383212Copy
Don't have an account? Find a server at joinmastodon.org
Jun 18, 2026