Microsoft's Defender Experts say Storm-3068 reset one user's password and ran an Azure DevOps pipeline authorized to reach more than 50 resources. It pulled the kubeconfig files that authenticate to a Kubernetes cluster.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+30
- Incentives
- Insufficient
- Confidence62
Storm-3068 hijacked one account via self-service password reset and ran an Azure DevOps pipeline authorized for 50-plus resources, Microsoft says. No exploit was involved, so the fix sits in the reset flow and in what one account's pipelines can reach.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives65
- Confidence45
A dev.to team replaced its coding agent's LLM with mocks built to sabotage the repo. The first run let 21 adversarial commits through, and the fix was path and AST checks that run after the model call and before git commit.
Reality
- Evidence38
- Adoption
- Insufficient
- Hype gap+35
- Incentives60
- Confidence45
GitHub's workflow execution protections went generally available on September 17, and the evaluate mode that shows what a rule would block before enforcement is documented as an Enterprise Cloud capability.
Reality
- Evidence58
- Adoption25
- Hype gap+12
- Incentives58
- Confidence54
Tetragon ran inside a CodeBuild GitHub Actions runner and killed /usr/bin/curl when a dependency's postinstall script tried to reach a non-loopback address. The control needs a pinned host kernel and privileged mode.
Reality
- Evidence58
- Adoption12
- Hype gap+5
- Incentives22
- Confidence55
Checkmarx found that indexed-btree declares no lifecycle hooks and starts its loader when application code calls set() with key 100. The loader reads its C2 address from a smart contract on Ethereum Sepolia.
Reality
- Evidence58
- Adoption38
- Hype gap+18
- Incentives62
- Confidence57
TanStack's postmortem says 84 malicious versions went out across 42 packages on 2026-05-11 with no npm token stolen, because a release job restored a cache that an untrusted pull_request_target build had written.
Publishers:tanstack.com
Reality
- Evidence68
- Adoption45
- Hype gap+6
- Incentives65
- Confidence58
Four core SAP build packages shipped an identical 11.6MB credential stealer. Because npm trusted the whole cap-js repository rather than one branch, a commit pushed to an unused branch was enough to publish them.
Publishers:stepsecurity.io
Reality
- Evidence60
- Adoption38
- Hype gap+15
- Incentives78
- Confidence55
The provenance on @7nohe/openapi-react-query-codegen was accurate about every question it was built to answer, which is why the Docker Security Dispatch reaches instead for a five-day resolution cooldown that npm ci does not apply.
Reality
- Evidence47
- Adoption
- Insufficient
- Hype gap+12
- Incentives72
- Confidence55
Ed25519 tells you which key signed which bytes. A slice log from the Ranex project shows how a policy path read from the working tree let the gated side pick the rules, and what pinning the trust root to the evaluated commit cost.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+12
- Incentives45
- Confidence45
The count of places this worm looks for secrets more than doubled between builds, and the additions sit in CI/CD and developer tooling, which is where the standing tokens that make a supply chain attack portable actually live.
Reality
- Evidence44
- Adoption
- Insufficient
- Hype gap+26
- Incentives78
- Confidence52
Google places the spree with a single operator in South Africa, which makes one arrest plausible, while Palo Alto Networks counts three core members. Either way, the packages moved because almost nobody checks what they ingest.
Reality
- Evidence58
- Adoption74
- Hype gap+10
- Incentives68
- Confidence55
One team's audit found a single pool labelled linux-docker scheduling outside contributors' builds onto the same agents that held internal deploy credentials, an arrangement that sat outside anything a controller permission model was built to check.
Reality
- Evidence32
- Adoption21
- Hype gap+12
- Incentives33
- Confidence41
Unit 42 says the group backdoored Trivy, KICS, LiteLLM and Telnyx's Python SDK, tools that run inside CI with the privileges needed to reach production secrets, which is also why the headline counts deserve a slow read.
Reality
- Evidence55
- Adoption58
- Hype gap+32
- Incentives78
- Confidence48
CISA says a trojanized extension version, 18.95.0, reached a GitHub employee's machine without anyone installing it, and internal repositories left from there. CVE-2026-48027 is now in the KEV catalog.
Reality
- Evidence76
- Adoption58
- Hype gap−8
- Incentives24
- Confidence74
StepSecurity's first annual report logs 56 confirmed supply chain compromises and says plainly that these are its own alerts. The February change is the finding; explaining it is the hard part.
Reality
- Evidence46
- Adoption42
- Hype gap+16
- Incentives79
- Confidence51
Unit 42 says a worm hidden in more than 400 npm packages read GitHub Actions runner memory for temporary OIDC tokens. An SBOM generated at the end of the build would not have seen any of it.
Reality
- Evidence55
- Adoption62
- Hype gap+18
- Incentives80
- Confidence52
Codecov in 2021 and tj-actions/changed-files in March 2025 failed the same way: trusted third-party code running with pipeline privileges on a push nobody on your team made.
Reality
- Evidence52
- Adoption24
- Hype gap+18
- Incentives34
- Confidence55
Adversa.ai says Claude Code's folder-trust dialog stopped naming MCP servers in v2.1, while a repo-supplied config can still launch an unsandboxed process on one keypress.
Publishers:adversa.ai
Reality
- Evidence38
- Adoption42
- Hype gap+22
- Incentives68
- Confidence34