Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope

An attacker republished the entire @mastra npm scope on June 17, 2026, slipping a single malicious dependency into 143 packages and counting, including @mastra/core, which pulls roughly 4 million downloads a month and has hundreds of dependent projects. The injected dependency, easy-day-js, is a dayjs lookalike whose install hook disables TLS verification, downloads a second-stage payload from a raw IP address, and runs a cross-platform cryptocurrency stealer in the background.

Build a Custom Security Training Course in Seconds | KnowBe4 AIDA Content Creation Agent

What if you could build a complete, personalized security awareness course from a single prompt — in seconds? KnowBe4's AIDA Content Creation Agent does exactly that. Powered by our decade of AI innovation, it generates e-learning modules instantly — and goes far beyond basic content generation: Deepfake Face Injection — Insert real members of your team into training visuals using safe, consensual deepfake synthesis. Your people, your culture, your training.

Salt Code: Stop Reviewing Al Code Start Governing It

AI coding assistants are generating APIs, MCP integrations, agent tools, and application logic faster than your security team can review them. And none of them are trained on your internal security standards, industry frameworks, or regulatory requirements. Salt Code changes that. Join us for this product launch and see how Salt governs AI-generated code from the first prompt through runtime, without slowing your developers down.

Stop building security dashboards nobody reads

On this episode of Masters of Data, we dig into one of data's most contested formats: the dashboard. We explore why so many dashboards get built and never opened, tracing the shift from in-person SOC culture (big screens, shared visibility, immediate feedback) to the remote-work era of folders full of charts no one reviews. The conversation covers North Star metrics, the tension between practitioner and leadership dashboards, and the uniquely tricky problem of security metrics that can look green while a threat actor has quiet dwell time in your environment.

Cybersecurity Connection Happy Hour | Reach Security, Cloudflare & JetStream

The Cybersecurity Connection! Cocktails, tacos, and a pool table, beachfront in Huntington Beach. Reach Security, Cloudflare, and JetStream are hosting a happy hour at The Bungalow on Wednesday, June 24. Security and IT leaders, two hours, no agenda. Come unwind, meet the team, and lose a game of pool to someone you just met. Wednesday, June 24, 5 to 7 PM. The Study at The Bungalow.

Stablecoin Settlement: Why PSPs Can't Afford to Wait

Stablecoin settlement has moved from experiment to execution. Payments leaders from Fireblocks, Nuvei, and EY break down how PSPs go from pilot to launch. In 2025, stablecoin transaction volume hit $33 trillion, surpassing Visa in annual throughput, and 86% of firms now say their infrastructure is ready. For payment service providers and B2B payments firms, the question is no longer whether to build a stablecoin strategy. It's how to ship one that differentiates.

Stablecoins vs the Payments Toll Booth

Payments firms have run on a toll booth model for decades: clip a fee off every transaction. Neil Chopra (Head of Strategy & Business Development, Americas, Fireblocks) on why that model is running out of road, and how stablecoins let firms keep funds on platform, get direct to users, and build new services. From the Finextra panel on stablecoin settlement, with Nuvei and EY. Chapters Key Takeaways.