Incident3,000 Components, Zero Visibility
What Happened A mid-market SaaS company discovered unauthorized data access in their production environment. The entry point wasn t their code. An attacker exploited a known vulnerability in a third-p
Expert perspectives on application security, compliance, and emerging threats
IncidentWhat Happened A mid-market SaaS company discovered unauthorized data access in their production environment. The entry point wasn t their code. An attacker exploited a known vulnerability in a third-p
IncidentWhat Happened A software supply chain compromise occurred when your team integrated what appeared to be a clean open-source dependency. The package showed zero CVEs in your security scanning tools. Th
IncidentA research team at the University of Missouri-Kansas City has published proof-of-concept code for an attack that bypasses AI code review tools by hiding malicious instructions inside PNG files attache
IncidentWhat Happened On July 8, 2026, a threat actor published version 1.20.21 of @injectivelabs/sdk-ts to npm. The package contained code to steal cryptocurrency wallet private keys. Within 24 hours, the at
Get weekly security insights and compliance updates delivered to your inbox.
IncidentOn January 14, 2025, security researcher Michael Clark confirmed what Sysdig had already detected: attackers were exploiting CVE-2026-20896 to bypass authentication in Gitea Docker deployments. This v
IncidentUbiquiti recently released security updates for UniFi OS, addressing seven critical vulnerabilities. One of these, CVE-2026-50746, has a maximum CVSS severity score. Censys data shows over 100,000 Uni
IncidentWhat Happened By the end of Q2 2026, Sonatype Research logged 1.8 million malicious packages across public registries. This wasn t a single sophisticated attack. It was industrial-scale pollution of t
IncidentOn December 20, 2024, attackers compromised the GitHub repository for Injective Labs SDK and published a malicious npm package designed to steal cryptocurrency wallet private keys. The malicious versi
IncidentYour AI coding assistant just suggested a package that doesn t exist. You accept the suggestion. Moments later, malware is running on your machine. This isn t theoretical. Researchers at Tel Aviv Univ
IncidentWhat Happened Attackers are actively exploiting CVE-2026-55255 , an Insecure Direct Object Reference (IDOR) vulnerability in Langflow s /api/v1/responses endpoint. This flaw allows anyone to execute w
IncidentYour security tooling just became an attack vector. Researchers have demonstrated a proof-of-concept attack called Friendly Fire that turns AI coding agents into unwitting accomplices. Tools like Anth
IncidentWhat Happened Noma Security discovered GitLost, a prompt injection attack exploiting GitHub s preview Agentic Workflows to leak private repository data. The attack is simple: an attacker submits a cra
IncidentWhat Happened On June 30, 2026, Adobe released emergency patches for CVE-2026-48282, a path traversal vulnerability in ColdFusion s Remote Development Services (RDS) component. This vulnerability has
IncidentYour GitHub Actions workflows are green across the board. CodeQL found nothing. Your SAST tool gave you a clean bill of health. You re compliant, right? Not according to Novee Security, which just fla
IncidentA public GitHub issue with a cleverly-worded sentence can trick an AI agent into revealing the contents of your private repository. This isn t just theoretical. Researchers at Noma Security demonstrat
IncidentWhat Happened Your team integrated an AI coding assistant into the CI/CD pipeline to speed up feature delivery. Over three months, the assistant generated about 40% of the production code, including a