Explore real-world engineering experiences from top tech companies.
Receive daily AI-curated summaries of engineering articles from top tech companies worldwide.
Drift's $285M hack on April 1, 2026 was a six-month DPRK social engineering operation by group UNC4736.
This post covers Google Cloud release notes from April 5, 2026, highlighting updates across security operations, cloud services, and AI integrations.
This article covers the discovery of 36 malicious npm packages disguised as Strapi CMS plugins that deployed persistent implants and harvested credentials.
Fortinet has released emergency patches for CVE-2026-35616, a critical pre-authentication API access bypass vulnerability in FortiClient EMS actively exploited in the wild.
This release note covers updates to Google SecOps and Google SecOps SOAR as of April 4, 2026.
This article covers TA416, a China-aligned threat actor, resuming targeted campaigns against European government and diplomatic entities since mid-2025 using PlugX malware and OAuth-based phishing techniques.
Microsoft Defender Security Research Team details PHP-based web shells on Linux servers that use HTTP cookies as a stealthy command-and-control channel.
North Korean threat actors (UNC1069) compromised the Axios npm package via a targeted social engineering attack against its maintainer, Jason Saayman.
This article argues that third-party risk management (TPRM) has become a critical security challenge and a growth opportunity for MSPs and MSSPs.
A new variant of the SparkCat malware has been discovered on both the Apple App Store and Google Play Store, targeting cryptocurrency wallet recovery phrases via OCR.
Drift, a Solana-based decentralized exchange, lost $285 million in a sophisticated attack using durable nonces and social engineering, with evidence linking it to North Korean threat actors.
This post covers Google Cloud release notes from early April 2026, highlighting updates across SecOps, SOAR, and various cloud services.