ByteBrief
We're a portrait publication through and through. Turn your phone back and your briefing picks up right where you left it.
(We tried widescreen once. It wasn't us.)

Three malicious RubyGems packages named SleeperGem target developer machines by impersonating Microsoft's Git Credential Manager. The attack downloads payloads from a Forgejo host, checks for CI environments to avoid detection, and installs persistence via cron and systemd. Two packages remained dormant for years before receiving malicious updates.
Tap to vote and see what everyone thinks.
Summary by ByteBrief