Follow the latest coverage, related explainers and connected technology stories.
SecurityWeek reviews a range of security developments, including malware that uses a poem on GitHub to identify its command-and-control server, the GhostAction campaign that targeted the secrets of 772 repositories, and a vulnerability in an Nvidia tool that exposed data from more than 12,000 GPUs. The roundup also covers a South Korean investigation into the use of AI against banks and the compromise of the Tensorlake software package.
The GitHub Advisory Database now imports malicious package data from the OpenSSF repository, enabling Dependabot to issue alerts across eight package ecosystems instead of being limited to npm. The new system relies on automated validation, source tracking, import limits, and rollback capabilities to protect the database from incorrect or compromised data.
Starting August 17, 2026, NuGet.org will limit the duration of new API keys to 30 days, while all keys created before that date will expire on November 1. Microsoft recommends that package publishers move to OIDC-based Trusted Publishing.