News

Open-source projects which are self-hosting their code repositories may be at increased risk of this type of supply-chain attack and must have robust processes in place to detect and reject ...
Code hosting website GitHub announced today plans to add support for a Dependency Graph for Composer-based PHP projects.
Attackers were able to place malicious code in the PHP central code repository by impersonating key developers, forcing changes to the PHP Group's infrastructure.
In the latest software supply chain attack, the official PHP Git repository was hacked and the code base tampered with. Yesterday, two malicious commits were pushed to the php-src Git repository ...
Hackers backdoor PHP source code after breaching internal git server Code gave code-execution powers to anyone who knew the secret password: "zerodium." ...