JFrog's team caught the campaign early and keeps their post updated with the current package list and IOCs — the fastest way to check whether anything you depend on is affected.
A credential-stealing worm that started with keyv has torn through the npm ecosystem, with counts now past 800 packages and over two billion monthly installs.
As of early August, npm granular access tokens set to skip 2FA can no longer manage other tokens, maintainers, or account settings — and direct publishing is next to go, in early 2027.
The Steering Council has put the experimental JIT compiler on a six-month clock to produce a standards-track PEP — otherwise it gets cut from CPython main.
The Python core team shipped maintenance releases for both active branches on June 10, carrying a combined ~419 bugfixes, build improvements, and documentation corrections.
The Node.js project is restructuring its release cadence to one major version per year, dropping the odd/even split and making every release LTS-eligible.
The June 2026 security drop lands actual release builds across all three active lines, patching two HIGH-severity CVEs including a WebCrypto integer overflow and a TLS wildcard authentication bypass.
Spring Boot 3.5 reaches end of open-source support on June 30, leaving teams without a commercial agreement dependent on self-patching or a migration to 4.x.
Kotlin 2.4.0 graduates from preview to stable, shipping Wasm Component Model support, Swift packages as Native dependencies, and an 18-month stdlib security support policy.
JDK 27 review cycles opened for JEP 523 (G1 as universal default GC), JEP 534 (compact object headers default), JEP 537 (Vector API 12th incubator), and JEP 538 (new PEM encoding/decoding API).
Oracle's Inside Java Newscast #112 details post-quantum TLS support being added to the JDK, a major cryptographic hardening ahead of quantum computing threats.
GeeCon 2026 runs May 14-15 in Kraków with sessions on JDK 27 roadmap items including Structured Concurrency and what excites developers most about Java in 2026.
Salesforce's Summer '26 release lands new Apex user-mode defaults alongside Agent Script (Apache 2.0) and a programmatic Agent Builder API for configuring Agentforce agents in code.
A new GitHub API in public preview lets GitHub Apps directly query whether they are installed on a specific enterprise and retrieve the installation ID, eliminating the need to paginate all installations.