CI/CD

Miasma: A Worming npm Supply Chain Attack on Red Hat Cloud Services

Miasma: A Worming npm Supply Chain Attack on Red Hat Cloud Services

Executive Summary On June 1, 2026, unauthorized commits were pushed to repositories in the RedHatInsights GitHub organization and used to publish malicious versions of 32 packages under the @redhat-cloud-services npm scope.The campaign, tracked as Miasma, executes a 4.2 MB obfuscated payload through an npm preinstall hook the moment any of these packages is installed, directly…
Illustration of purple icons on platforms representing continuous integration/continuous delivery (CI/CD) tools against a blue sky. Text reads Streamline Discovery of CI/CD Events with a logo on one platform.

Streamline Automatic Discovery of CI/CD Events from Within the Upwind Platform

We are excited to announce the addition of a significant new capability to the Upwind cloud security platform, automatically streamlining CI/CD events context from your continuous integration or delivery platforms. Upwind Cloud Security Platform offers unprecedented end-to-end visibility of your cloud infrastructure and applications, marrying intelligence from both build time and runtime to quickly prioritize…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS