#poisoned


GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption

Jul 27, 2026 // 13:24

GitHub has announced a new cooldown mechanism in Dependabot, allowing the tool to wait at least three days after a release is published before opening […]

AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code

Jul 21, 2026 // 19:10

Hidden text on a web page was enough to make Kiro, AWS’s agentic coding IDE, rewrite its own configuration file and run an attacker’s code […]

Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data

Jul 2, 2026 // 02:07

New Microsoft research shows how attackers can hijack AI agents that act on a user’s behalf, using nothing more than a poisoned tool description to make the […]

Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer

Jun 9, 2026 // 14:07

The Miasma supply chain campaign has sparked a fresh attack wave called Hades, this time involving 37 malicious wheel artifacts across 19 packages in the […]

Poisoned Ruby Gems and Go Modules Exploit CI Pipelines for Credential Theft

May 1, 2026 // 12:52

A new software supply chain attack campaign has been observed using sleeper packages as a conduit to subsequently push malicious payloads that enabled credential theft, […]