
New ChainDrop worm poisons over 1,300 npm packages, Keyv and Cacheable among those hit
THE SO WHAT
A ChainDrop worm compromising 1,300+ npm packages—including widely used ones like Keyv and Cacheable—shows how fragile modern software supply chains remain. If you ship Node-based products, lock down dependency updates, add automated malware scanning, and be ready to rotate credentials and patch quickly.
READ THE SOURCE
MORE FROM THE WIRE
Deep & Emerging TechStray Piece of SpaceX Falcon 9 Rocket Slams Into the Moon
Untracked upper stages hitting the Moon is a reminder that orbital debris is now a systems problem, not a PR issue. If your roadmap touches launch or cislunar infrastructure, assume tighter debris regulation and higher compliance overhead over the next cycle.
Deep & Emerging Tech'The largest in history:' Russia blocks over 20 popular VPNs in major internet crackdown
A mass block of 20+ VPNs in Russia is a stress test for how resilient consumer privacy tools really are under state pressure. If your product assumes open internet access — from SaaS to gaming — you need a contingency plan for markets where basic connectivity and privacy tools can disappear overnight.
Deep & Emerging TechMicrosoft 365 users hit by phishing scheme posing as RingCentral emails
Phishing-as-a-service targeting Microsoft 365 via RingCentral spoofs shows that attackers are optimizing against the exact SaaS bundles enterprises standardize on. If you’re a Microsoft shop, tighten conditional access and train users on SaaS-to-SaaS impersonation — not just generic “don’t click links” guidance.
Deep & Emerging Tech3 reasons AMD’s stock is falling in the face of its latest earnings report
AMD’s selloff on muted upside and margin worries shows how unforgiving the market is for chip names priced on AI euphoria — anything less than explosive growth gets punished. If you’re planning around their roadmap, model more volatility into pricing and availability rather than assuming a smooth up-and-to-the-right trajectory.