Please turn JavaScript on

Mend Leadership Update: Building on Our Momentum for the Next Phase of Growth

Is this your feed? Claim it!

Publisher:  Unclaimed!
Message frequency:  0.26 / day

Message History

On 2026-05-22, an attacker rewrote every repository tag across four Composer packages in the Laravel-Lang ecosystem to point at malicious commits. The affected packages are laravel-lang/lang, laravel-lang/attributes, laravel-lang/http-statuses, and laravel-lang/actions. The rewrite took place on 2026-05-22 into the early hours of 2026-05-23. Every malicious commit makes the s...


Read full story
Key takeaways The Cyber Resilience Act (CRA) entered into force on December 10, 2024 and applies to nearly every "product with digital elements" sold in the EU. Vulnerability and incident reporting obligations begin on September 11, 2026. Manufacturers will have 24 hours to file an early warning and 7...

Read full story

An active supply chain attack has compromised 323 npm packages published under the atool npm maintainer account. The wave sweeps the entire @antv data-visualization organization alongside standalone libraries with wide independent adoption: echarts-for-react, timeago.js, size-sensor, and canvas-nest.js. With echarts-for-react pulling roughly 1.1 million weekly downloads, any ...


Read full story

On May 11, 2026, Mend Defender flagged more than 120 malicious packages newly published to RubyGems — the standard package manager for the Ruby ecosystem. Within 24 hours, that initial cluster expanded into something far larger: tens of thousands of packages pushed by...


Read full story

The Mini Shai-Hulud supply chain campaign has resurfaced with its largest wave yet. Over a 48-hour window on May 11-12, 2026, attackers compromised 172 unique packages across 403 malicious versions on npm and PyPI, including high-profile scopes like @tanstack, @uipath, @mistralai, and


Read full story