IncidentTwo npm Packages Hijacked in One Week
On January 13, 2025, AsyncAPI discovered that several of its npm packages had been compromised and were distributing malware. Three days later, Jscrambler reported a similar incident affecting its pac
Expert perspectives on application security, compliance, and emerging threats
IncidentOn January 13, 2025, AsyncAPI discovered that several of its npm packages had been compromised and were distributing malware. Three days later, Jscrambler reported a similar incident affecting its pac
GeneralYou ve probably heard it: AI coding assistants have boosted developer productivity so much that code review is now the bottleneck. GitLab s research suggests this shift. Your team might be discussing
ResearchLast week, security researchers found that an attacker published malicious npm packages to the official @asyncapi namespace without stealing any credentials. They hijacked the project s GitHub Actions
IncidentOn July 14, a misconfigured GitHub Actions workflow turned AsyncAPI s npm packages into a distribution channel for credential-stealing malware. The attack lasted just over four hours, but the packages
Get weekly security insights and compliance updates delivered to your inbox.
GeneralScope This guide explores Epinio s architecture, security implications, and implementation patterns for teams using Kubernetes. You ll get specific guidance on standardization controls, compliance int
GeneralScope This guide outlines the changes needed when shifting from manual observability workflows to AI-led root cause analysis. It s for DevOps and platform engineering teams planning to deploy AI agent
GuidesYou ve deployed a DLP solution. Now you need policies that actually work. Most organizations start with vendor defaults or copy-paste rules that trigger thousands of false positives. Within weeks, you
IncidentThousands of organizations have been shipping vulnerable software, treating security as a post-development checkbox rather than an integrated practice. NIST SP 800-218 Version 1.1 was developed becaus
GuidesYour code review process wasn t built for this. When Faros analyzed development metrics across their customer base, they found code churn up 861%, incidents per PR up 243%, and time in review up 441%.
IncidentOn January 17, 2025, Gitea maintainers disclosed CVE-2026-20896, a critical authentication bypass in their Docker images. This flaw allows anyone to send a crafted HTTP header and gain admin access to
GeneralIn application security, the belief is that more detection equals better security. Scan everything, flag everything, track everything. If your SAST tool finds 10,000 issues, you need to see all 10,000
ResearchYour scanner flags 847 vulnerabilities on Monday morning. By Wednesday, your developers have fixed three and opened 23 Slack threads debating the rest. The security team insists everything is critical
GeneralScope This guide focuses on modifying CI/CD pipelines for deploying large language models (LLMs) to production. If your team is running LLM-powered features like chatbots or content generators, your c
GeneralAmazon EKS operates hundreds of thousands of Kubernetes clusters across more than thirty AWS regions. Their recent architectural changes highlight which assumptions about Kubernetes management fail at
IncidentOverview The official Node.js Docker image from Docker Hub contains 567 vulnerable system libraries in its base layer. This is not due to an exploit or breach—it s the default state of one of the most
GeneralYour CI/CD pipeline deploys code to production automatically, but your resource optimization tool still requires manual approval via Slack messages. Recent data reveals a significant trust gap in how