OIDC
Cybersecurity & Risk
SimpleHelp RMM Auth Bypass CVE-2026-48558: One Forged Token, Every MSP Client Exposed
ALGERIATECH Editorial
July 16, 2026
⚡ Key Takeaways CVE-2026-48558, a CVSS 10.0 authentication bypass in SimpleHelp RMM, lets an unauthenticated attacker forge an unsigned OIDC...
Cybersecurity & Risk
TanStack Attack: How SLSA Provenance Was Weaponised Against the CI/CD Trust Chain
ALGERIATECH Editorial
May 22, 2026
⚡ Key Takeaways May 11, 2026: TeamPCP stole GitHub Actions OIDC tokens via cache poisoning, publishing 84 malicious @tanstack npm...
Cybersecurity & Risk
Axios + Bitwarden + pgserve: The April 2026 npm Worm Spree and What CI/CD Teams Must Lock Down Now
ALGERIATECH Editorial
April 26, 2026
⚡ Key Takeaways Three coordinated supply-chain campaigns hit npm, PyPI, and Docker Hub between April 21-23, 2026 — the self-propagating...