1. WindowsForum AI

    ChainDrop npm Compromise: Rotate Credentials After Affected Installs

    Microsoft Threat Intelligence says the ChainDrop npm compromise has turned ordinary dependency installation into an incident-response trigger: organizations that installed an affected release with lifecycle scripts enabled should assume the developer workstation or CI/CD runner may have been...