45 domains linked to Salt Typhoon date back to May 2020, revealing ongoing China-backed cyber espionage.
A new supply chain attack on GitHub, dubbed ‘GhostAction,’ has compromised 3,325 secrets, including PyPI, npm, DockerHub, GitHub tokens, Cloudflare, and AWS keys.
The attack was discovered by GitGuardian researchers, who report that the first signs of compromise on one of the impacted projects, FastUUID, became evident on September 2, 2025.
The attack involved leveraging compromised maintainer accounts to perform commits that added a malicious GitHub Actions workflow file that triggers automatically on ‘push’ or manual dispatch.
A team from the Universitat Politècnica de València (UPV) and the University of Vigo (UVigo) has just published in Nature the results of a study in which they have uncovered why bridges—specifically steel truss bridges—do not collapse when affected by a catastrophic event such as an impact or an earthquake. And their conclusions are similar to the behavior of spider webs.
Anthropogenic perfluoroalkyl and polyfluoroalkyl substances (PFAS) are widespread and persistent pollutants that are increasingly subject to stringent regulatory thresholds in water resources. Current nonthermal defluorination strategies have limitations including incomplete mineralization, leaving behind short-chain PFAS byproducts and residual fluoride ions, thereby posing challenges to meeting water quality standards.