Developer Workstations Are Now Part of the Software Supply Chain
Source: The Hacker News · Category: Supply Chain
Supply chain attackers targeting developer environments and CI/CD pipelines to steal secrets (API keys, cloud credentials, SSH, tokens) across npm, PyPI, and Docker Hub. Law firms with custom development are exposed; implement secret scanning and CI/CD hardening immediately.