The brief

Friday, May 22, 2026

GitHub's 3,800 internal repos were breached via a malicious Nx Console VS Code extension—part of TeamPCP's broader campaign hitting 500+ software packages across 20 attack waves. Your supply chain and post-authentication visibility are critical gaps: MFA doesn't stop lateral movement, and employee monitoring platforms leak data to Meta/Google.

12 stories · 3 podcasts · get this by email each weekday

Today's stories

Worth a listen

  • How Superhuman Took Over Silicon Valley Email

  • React Native at Scale

  • Marc Andreessen on AI, California, and the Future of America | Joe Rogan

← All editions