ResearchResearch Won't Save Your Supply Chain
You re overwhelmed by dependency vulnerabilities. Your SBOM lists 847 transitive dependencies. A new paper claims 94% accuracy in detecting malicious packages, but you can t use it. The gap between ac
Expert perspectives on application security, compliance, and emerging threats
ResearchYou re overwhelmed by dependency vulnerabilities. Your SBOM lists 847 transitive dependencies. A new paper claims 94% accuracy in detecting malicious packages, but you can t use it. The gap between ac
ResearchAfter Zafran Security published their DifyTap research, compliance teams began questioning tenant isolation in multi-tenant AI platforms. This issue is not limited to Dify, which boasts over 146,000 G
ResearchYour team wants to integrate AI agents into your development workflow. You find a plugin registry with hundreds of options. Some have official-looking scope names. Some claim to be maintained by the r
ResearchWhen mobile teams discovered that a seemingly legitimate advertising SDK was doing more than displaying ads, they faced serious security challenges. Snyk found that the Mintegral SDK included method s
Get weekly security insights and compliance updates delivered to your inbox.
ResearchYour mobile app just integrated an advertising SDK promising better fill rates and higher eCPMs. Three months later, you discover it s using method swizzling to intercept user data and potentially sip
ResearchWhen Microsoft disclosed the AutoJack vulnerability in AutoGen Studio, the attack vector was clear: three layered weaknesses in the Model Context Protocol (MCP) WebSocket implementation allowed malici
ResearchYou ve sat through the vendor demo. The slide deck claims 99% accuracy in bold letters. The sales engineer points to benchmark results showing their tool catches more vulnerabilities than competitors.
ResearchYour team s JetBrains environment is now an attack vector. Since October 2025, malicious plugins posing as AI coding assistants have been stealing API keys from developer workstations. Two such plugin
ResearchThe Challenge Your development team has boosted sprint velocity by 40%. Code moves from developer workstations to production faster than ever. Pull requests that once took days now close in hours. The
ResearchOnly 11% of AI agents deployed in production meet high security standards. This statistic should alarm you, but what s more concerning is why the other 89% fail — and how similar the mistakes are acro
ResearchYour security team approved an OAuth app six months ago. The publisher s domain is now parked. The app still has read access to your company s Google Drive. This isn t a hypothetical. An OhAuth audit
ResearchReliaQuest has identified a threat cluster named OP-512 deploying custom web shell frameworks against Microsoft IIS servers, with moderate to high confidence attribution to China-based actors. The fra
ResearchYour package.json scripts are clean. Your lockfile passes integrity checks. You run npm audit before every deployment. Yet, you re still vulnerable to the attack vector that compromised 281 npm packag
ResearchYour build just failed. Someone on the team installed a package that looked legitimate but turned out to be malware. Now you re fielding questions in three different Slack channels while trying to fig
ResearchSocket s research into the TrapDoor campaign reveals a critical issue your security team may have overlooked: developer workstations are now high-value targets. These workstations often run unmonitore
ResearchYou found a Google API key in a public GitHub repo. You deleted it immediately. Your work is done, right? Not for the next 23 minutes. Aikido Security s research confirms that deleted Google API keys