ByteBrief
We're a portrait publication through and through. Turn your phone back and your briefing picks up right where you left it.
(We tried widescreen once. It wasn't us.)

A worm named Shai-Hulud altered over 500 npm package versions between September 14th and 18th, 2025, publishing new versions without maintainer action. The worm uploaded stolen credentials to a public GitHub repo named Shai-Hulud, demonstrating that controlling a package registry controls the software supply chain.
Tap to vote and see what everyone thinks.
Summary by ByteBrief