ResearchResearch Won't Save Your Supply Chain
You re overwhelmed by dependency vulnerabilities. Your SBOM lists 847 transitive dependencies. A new paper claims 94% accuracy in detecting malicious packages, but you can t use it. The gap between ac
Expert perspectives on application security, compliance, and emerging threats
ResearchYou re overwhelmed by dependency vulnerabilities. Your SBOM lists 847 transitive dependencies. A new paper claims 94% accuracy in detecting malicious packages, but you can t use it. The gap between ac
IncidentWhat Happened In November 2023, Spring Boot 2.7 reached end-of-life. If your organization is still using this version, you re dealing with 143 known CVEs across 79 projects in your dependency tree. Th
GeneralThe assumption that you can secure AI in your applications just like open-source libraries—by scanning for vulnerabilities, checking licenses, and updating as needed—is dangerously incomplete. Why Tra
GeneralScope This guide addresses browser extension security controls for enterprise environments. It covers permission analysis, remote code execution risks, and organizational policy frameworks for extensi
Get weekly security insights and compliance updates delivered to your inbox.
IncidentWhat Happened On April 15, 2026, NIST announced that the National Vulnerability Database (NVD) would stop providing comprehensive enrichment for most Common Vulnerabilities and Exposures (CVEs). Inste
IncidentOverview of the Issue In August 2019, W3Techs scanned websites and found jQuery running on 73% of them. Snyk s security research revealed that 83.4% of those jQuery installations used the 1.x release
IncidentIn early 2026, the timeline between discovering a vulnerability and its exploitation shrank dramatically—from days or weeks to mere hours. Security teams accustomed to a predictable patching schedule
GeneralYour CI/CD pipeline deploys code to production automatically, but your resource optimization tool still requires manual approval via Slack messages. Recent data reveals a significant trust gap in how
IncidentWhat Happened AIR , a security research organization, deployed a fake AI agent skill marketed as a landing page builder tool. The skill passed security validation from Cisco, Nvidia, and skills.sh sca
What Happened JFrog researchers discovered CVE-2026-8461 , a heap out-of-bounds write vulnerability in FFmpeg s MagicYUV decoder. They demonstrated remote code execution on Jellyfin and Nextcloud by u
IncidentWhat Happened LastPass disclosed that attackers accessed customer data in its Salesforce environment using compromised OAuth tokens from Klue, a market intelligence platform. The breach exposed standa
IncidentWhat Happened OpenAI and Trail of Bits launched Patch the Planet, an AI-assisted vulnerability research program targeting critical open-source projects. The program used AI models and Codex Security t
IncidentWhat Happened A user named abdrizak published three malicious npm packages disguised as legitimate PostCSS tools: aes-decode-runner-pro , postcss-minify-selector , and postcss-minify-selector-parser .
IncidentWhat Happened Between late 2025 and early 2026, attackers discovered they could chain two vulnerabilities in LiteLLM—an open-source AI gateway used to route requests across multiple LLM providers—to a
GeneralThe conventional wisdom suggests that AI-generated code should undergo the same review process as human-written code. This involves running it through your existing CI/CD pipeline, having a senior dev
IncidentWhat Happened ShapedPlugin, a vendor of premium WordPress plugins, experienced a supply chain attack that injected backdoor code into official releases of multiple Pro plugins. This affected Product S