<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>InfoQ - Application Security</title>
    <link>https://www.infoq.com</link>
    <description>InfoQ Application Security feed</description>
    <item>
      <title>TanStack Details Sophisticated npm Supply Chain Attack That Compromised 42 Packages</title>
      <link>https://www.infoq.com/news/2026/05/tanstack-supply-chain-attack/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Application+Security</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/05/tanstack-supply-chain-attack/en/headerimage/generatedHeaderImage-1778915238952.jpg"/&gt;&lt;p&gt;TanStack has released a detailed postmortem describing a sophisticated supply-chain attack that compromised 42 npm packages and published 84 malicious package versions in just six minutes, exposing developers and CI/CD systems to credential theft and malware propagation.&lt;/p&gt; &lt;i&gt;By Craig Risi&lt;/i&gt;</description>
      <category>Application Security</category>
      <category>NPM</category>
      <category>Software Supply Chain</category>
      <category>DevOps</category>
      <category>news</category>
      <pubDate>Tue, 19 May 2026 12:00:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/05/tanstack-supply-chain-attack/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Application+Security</guid>
      <dc:creator>Craig Risi</dc:creator>
      <dc:date>2026-05-19T12:00:00Z</dc:date>
      <dc:identifier>/news/2026/05/tanstack-supply-chain-attack/en</dc:identifier>
    </item>
    <item>
      <title>Article: Kernel-Level Ground Truth: Why eBPF is Replacing User-Space Agents for Security Observability</title>
      <link>https://www.infoq.com/articles/ebpf-for-security-observability/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Application+Security</link>
      <description>&lt;img src="https://res.infoq.com/articles/ebpf-for-security-observability/en/headerimage/ebpf-for-security-observability-header-1778674557176.jpg"/&gt;&lt;p&gt;eBPF is emerging as a preferred method for security observability over traditional user-space agents. By attaching probes directly to the Linux kernel's syscall interface, it provides consistent visibility even during container-level compromises. eBPF reduces security-related CPU consumption and limits data volume by performing filtering at the kernel level, enhancing operational efficiency.&lt;/p&gt; &lt;i&gt;By Niranjan Sharma&lt;/i&gt;</description>
      <category>Application Security</category>
      <category>eBPF</category>
      <category>Observability</category>
      <category>DevOps</category>
      <category>article</category>
      <pubDate>Tue, 19 May 2026 09:00:00 GMT</pubDate>
      <guid>https://www.infoq.com/articles/ebpf-for-security-observability/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Application+Security</guid>
      <dc:creator>Niranjan Sharma</dc:creator>
      <dc:date>2026-05-19T09:00:00Z</dc:date>
      <dc:identifier>/articles/ebpf-for-security-observability/en</dc:identifier>
    </item>
    <item>
      <title>Google Introduces Cloud Fraud Defense as Successor to reCAPTCHA</title>
      <link>https://www.infoq.com/news/2026/05/cloud-fraud-defense-recaptcha/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Application+Security</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/05/cloud-fraud-defense-recaptcha/en/headerimage/generatedHeaderImage-1777383901225.jpg"/&gt;&lt;p&gt;At the recent Next ‘26 conference, Google introduced Google Cloud Fraud Defense, the successor to reCAPTCHA. The platform goes beyond basic bot detection to address broader online fraud across login, account creation, and payment flows, helping organizations detect suspicious behavior and block abuse, including fake accounts, automated attacks, and transaction fraud.&lt;/p&gt; &lt;i&gt;By Renato Losio&lt;/i&gt;</description>
      <category>Fraud Detection</category>
      <category>Google Cloud</category>
      <category>Application Security</category>
      <category>Cloud Security</category>
      <category>AI, ML &amp; Data Engineering</category>
      <category>Development</category>
      <category>news</category>
      <pubDate>Sat, 16 May 2026 08:39:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/05/cloud-fraud-defense-recaptcha/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Application+Security</guid>
      <dc:creator>Renato Losio</dc:creator>
      <dc:date>2026-05-16T08:39:00Z</dc:date>
      <dc:identifier>/news/2026/05/cloud-fraud-defense-recaptcha/en</dc:identifier>
    </item>
    <item>
      <title>GitHub Expands Secret Scanning with General Availability of MCP Server Integration</title>
      <link>https://www.infoq.com/news/2026/05/github-mcp-secret-scanning/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Application+Security</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/05/github-mcp-secret-scanning/en/headerimage/generatedHeaderImage-1778422946373.jpg"/&gt;&lt;p&gt;GitHub has announced the general availability of secret scanning support through its MCP Server, extending automated credential detection and remediation capabilities into AI-assisted and agent-driven development workflows.&lt;/p&gt; &lt;i&gt;By Craig Risi&lt;/i&gt;</description>
      <category>github</category>
      <category>Application Security</category>
      <category>Model Context Protocol (MCP)</category>
      <category>DevOps</category>
      <category>news</category>
      <pubDate>Tue, 12 May 2026 12:00:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/05/github-mcp-secret-scanning/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Application+Security</guid>
      <dc:creator>Craig Risi</dc:creator>
      <dc:date>2026-05-12T12:00:00Z</dc:date>
      <dc:identifier>/news/2026/05/github-mcp-secret-scanning/en</dc:identifier>
    </item>
  </channel>
</rss>
