I wanted validation, Apple gave me a keynote.
A few weeks back, @_PrabhpreetSing and I started building an on-device memory layer for your work.
The idea was: your AI should know your work without your work leaving your laptop.
Turns out Apple thinks so too.
#sherlocked #wwdc26
Honestly, one of the easiest security upgrades you can make on macOS is installing @littlesnitch.
It shows you when apps are trying to connect out from your machine, and itβs honestly eye-opening how many apps quietly phone home in the background.
At the very least, do this on your main work device.
Update 5:05 PT: The attack has now expanded well beyond @TanStack and @Mistral.
373 malicious package-version entries across 169 npm package names, including @uipath, @squawk, @tallyui, @beproduct, and more.
The malware propagates by stealing your CI credentials and using them to publish new compromised versions.
Full IOCs, affected package list, and detection steps: https://t.co/jWG9DUCu3x
@anulagarwal Same, stuck on an Axis Bank βCustomer Profile Updateβ for 10 days now. Visiting the branch daily, and half the time the support staff donβt even know the resolution steps themselves. The invoicing startups claiming to fix cross-border payments are more or less the same.
π¨ BREAKING: Socket and @Docker uncovered what appears to be a broader Checkmarx supply chain compromise affecting official KICS Docker images and recent Checkmarx VS Code extension releases.
We found malicious images in the official checkmarx/kics Docker Hub repo, including overwritten tags and a new tag outside the normal release flow.
Our analysis also found signs that recent Checkmarx extension releases introduced code capable of downloading and executing what appears to be a malicious remote addon.
Weβre in touch with the Checkmarx team and still investigating the incident.