supply-chain 39
- Visual Studio Extensions Revisited
- Out of the Crypt: The Evolving Cyber Extortion Economy
- Intelligence Insights: May 2026
- AWS Security Digest #262 - Not private
- We hardened zizmor's GitHub Actions static analyzer
- Shai-Hulud Is Back, and This Time It Ate the Whole Ecosystem
- SVD-2026-0515: Third-Party Package Updates in Splunk User Behavior Analytics - May 2026
- SVD-2026-0512: Third-Party Package Updates in Splunk AppDynamics Private Synthetic Agent (PSA) - May 2026
- Reduce CVE noise with OpenVEX assessments in Datadog
- durabletask: TeamPCP's Latest PyPi Compromise
- AWS Security Digest #261 - Pretending
- Living Off the Pipeline: Defending Against CI/CD Subversion
- Backdoored node-ipc npm releases steal developer credentials through DNS queries
- Backdoored Cemu release linked to TanStack and Mistral supply chain campaign
- Shai-Hulud Goes Open Source
- Composer vulnerability leaks GitHub tokens, threatens PHP supply chain
- Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised
- Malicious Coding Agent Skills and the Risk of Dynamic Context
- Personal Software and BaremetalVMM
- The Good, the Bad and the Ugly in Cybersecurity – Week 18
- You’re Not Watching MCPs. Anthropic’s Vulnerability Shows Why You Should Be.
- IR Trends Q1 2026: Phishing reemerges as top initial access vector, as attacks targeting public administration persist
- From Code to Pipeline: Wiz Code Now Secures Your Build Environment
- Context.ai OAuth Token Compromise
- Fracturing Software Security With Frontier AI Models
- Spotting CI/CD misconfigurations before the bots do: Securing GitHub Actions with Datadog IaC Security
- The case for dependency cooldowns in a post-axios world
- Performing Supply-Chain Attack in the NodeJS Ecosystem [hands-on exercise]
- Primer on GitHub Actions Security - Threat Model, Attacks and Defenses (Part 1/2)
- Securing the Software Supply Chain: How SentinelOne’s AI EDR Autonomously Blocked the CPU-Z Watering Hole Cyber Attack
- CI/CD security: How to secure your GitHub ecosystem
- CI/CD security: threat modeling using a MITRE-style threat matrix
- AI in cybersecurity: The good, the bad, and the FUD
- Scroll trīgintā sextus
- What enables malicious models?
- Using KServe to deploy malicious models
- Model Confusion - Weaponizing ML models for red teams and bounty hunters
- Introducing the Offsec ML Playbook v0.1
- Six Accounts, One Actor: Inside the prt-scan Supply Chain Campaign