GITHUB, PYPI DEPLOY TIME-BASED DEFENSES AGAINST SUPPLY CHAIN ATTACKS
■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE
GitHub and PyPI have integrated time-based security mechanisms into Dependabot to protect against supply chain attacks. The new defense limits the window of exposure when malicious packages are introduced.
■ MORE FROM THE SECURITY DESK
Over 120,000 Flock automatic license plate reader (ALPR) cameras operate across the US, but dozens of communities are now canceling contracts or shutting down the surveillance infrastructure amid privacy concerns.
Apple now sends push notifications directly to iPhone lock screens when it detects government-sponsored spyware targeting a user's device. The alerts mark a significant shift in how the company communicates security threats to its users.
Immigration and Customs Enforcement announced plans to acquire electrified gloves capable of delivering painful electric shocks to detainees. The Department of Homeland Security published a procurement notice Monday for the devices, with delivery expected by March 2027.
The Jewelbug hacker group is simultaneously breaching government and military webmail systems while operating a parallel cryptocurrency fraud scheme.