Is Your Code SAFE? The NPM Attacks That Changed Everything - Expose 2,180 Github Accounts
Technically U12 Syys 2025

Is Your Code SAFE? The NPM Attacks That Changed Everything - Expose 2,180 Github Accounts

NPM Security Breaches 2025 – The Largest Supply Chain Attacks in History

The attack resulted in the exposure of 2,180 GitHub accounts and 7,200 repositories across three separate attack waves — and the damage is still unfolding.

NPM, the world’s largest software registry with over 17 million developers and 2 million packages, suffered two massive breaches in 2025.

From malware hidden in Nx builds to phishing attacks hijacking popular packages with billions of downloads, these incidents exposed sensitive data, cryptocurrency wallets, and developer credentials across the globe.

In this episode of Technically U, we break down:

✅ The August 2025 “s1ngularity” attack against Nx packages

✅ The September 2025 phishing incident targeting chalk, debug, ansi-styles & more

✅ How attackers targeted cryptocurrency wallets and hijacked transactions

✅ The role of AI tools in reconnaissance and exploitation

✅ The global impact on enterprises like Netflix, Amazon, Shopify, and Spotify

✅ Security measures businesses must take to prevent supply chain compromises

These attacks mark a new era of software supply chain threats—where open-source trust can be weaponized against millions.

🔔 Subscribe to Technically U for more tech dives into cybersecurity, AI, and the future of tech.

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(265)

The Confidence Gap: Why Executives Think AI Agents Are Secure (And Why They're Wrong)

The Confidence Gap: Why Executives Think AI Agents Are Secure (And Why They're Wrong)

The Confidence Gap: AI Agents and the Security Crisis Nobody Is Talking AboutEighty-two percent of executives feel confident that their existing AI agent policies are enough to keep their organization...

8 Elo 18min

Seeing Is No Longer Believing: How Deepfake Fraud Targets Businesses and Families

Seeing Is No Longer Believing: How Deepfake Fraud Targets Businesses and Families

What if the voice on the phone sounds exactly like your boss, your bank, or someone in your family — but it isn’t them?In this episode of Technically U, we break down Deepfake Fraud and why it has bec...

31 Heinä 23min

The AI Criminal Playbook: How Cybercrime Changed Forever in 2026

The AI Criminal Playbook: How Cybercrime Changed Forever in 2026

The next generation of cybercrime may not come from a hacker typing code in a dark room.It may come from someone using AI to generate phishing emails, clone voices, create fake identities, manipulate ...

24 Heinä 16min

RiskRecon Explained: The Cybersecurity Credit Score Companies Use to Judge You

RiskRecon Explained: The Cybersecurity Credit Score Companies Use to Judge You

What if a company you've never heard of is already influencing whether customers do business with you?In this episode of Technically U, we break down RiskRecon, the cybersecurity risk-rating platform ...

19 Heinä 9min

Vulnerability Management Explained: Find, Prioritize & Patch Before Hackers Strike

Vulnerability Management Explained: Find, Prioritize & Patch Before Hackers Strike

Right now, there may be vulnerabilities sitting inside your organization’s systems — and attackers may already be looking for them.In this episode of Technically U, we break down Vulnerability Managem...

12 Heinä 19min

HSTS: The Invisible Security Header Protecting Billions

HSTS: The Invisible Security Header Protecting Billions

Every time you visit your bank, check your email, log into a shopping site, or open a secure web app, there’s an invisible browser protection working behind the scenes: HSTS — HTTP Strict Transport Se...

3 Heinä 10min

The DNS Encryption War: Why Privacy Tools and Security Teams Are Fighting Over DoH

The DNS Encryption War: Why Privacy Tools and Security Teams Are Fighting Over DoH

DNS over HTTPS (DoH) encrypts the internet's phonebook—and it's breaking traditional network security. Here's what IT professionals need to know about DoH in 2026, why enterprises are concerned, and h...

20 Kesä 28min

Container Security Explained: Kubernetes, Docker & Cloud Native Threats

Container Security Explained: Kubernetes, Docker & Cloud Native Threats

🔐 Are your containers actually secure… or just assumed to be?In this episode of Technically U, we take a deep, structured dive into Container Security, breaking down how modern environments built on ...

14 Kesä 9min