Incident300,000 Ollama Servers Leaking Memory
Three API calls. No authentication required. Full process memory exposed — including API keys, conversation history, and model weights. CVE-2026-7482, now known as Bleeding Llama, turned approximately
Expert perspectives on application security, compliance, and emerging threats
IncidentThree API calls. No authentication required. Full process memory exposed — including API keys, conversation history, and model weights. CVE-2026-7482, now known as Bleeding Llama, turned approximately
IncidentWhat Happened TeamPCP compromised the Checkmarx Jenkins AST plugin in a second supply chain attack, using credentials obtained from an earlier breach. The attackers gained write access to the plugin s
IncidentWhat Happened On May 9, 2026, TeamPCP published a compromised version of the Checkmarx Jenkins AST plugin to the official Jenkins Marketplace. This malicious plugin contained info-stealing malware, ex
GeneralThe belief that documenting AI components will control AI risk is widespread. CISA and the G7 have released guidance for AI software bills of materials (SBOMs), and the compliance world is treating it
Get weekly security insights and compliance updates delivered to your inbox.
IncidentWhat Happened SAP s May 2026 security updates addressed 15 vulnerabilities across its enterprise software portfolio. Two critical flaws stand out for their exploitability and potential impact: CVE-202
IncidentIncident Overview Between late 2024 and early 2025, attackers published over 150 malicious gems to the RubyGems repository. These gems were not meant to compromise developers who downloaded them. Inst
GuidesYour CI/CD pipeline is the most privileged account in your infrastructure. It deploys to production, accesses secrets, and runs on every commit. Yet, many security policies treat it like any other sys
GuidesYour coding agent just modified three microservices, updated a Helm chart, and pushed changes to staging. Did it work? In a traditional monolithic app, you d run the test suite and know within seconds
IncidentWhat Happened Between late 2024 and early 2025, attackers exploited CVE-2026-41940 , a vulnerability in cPanel s web hosting management interface, compromising hosting infrastructure on a large scale.
IncidentWhat Happened In early 2025, HackerOne paused its bug bounty program due to an overwhelming increase in vulnerability discoveries, driven by AI-assisted research. This wasn t a breach or technical fai
IncidentOn February 28, 2025, security researchers at Endor Labs discovered that attackers had published malicious versions of popular JavaScript packages—including TanStack Query and Mistral AI s SDK—using s
IncidentWhat Happened RubyGems temporarily stopped new account creation after detecting hundreds of malicious packages uploaded to its registry. The attack involved multiple newly created accounts uploading p
IncidentWhat Happened JetBrains disclosed CVE-2026-44413 , a high-severity vulnerability in TeamCity On-Premises versions 2025.11.4 and earlier. This flaw enables privilege escalation and may expose sensitive
IncidentWhat Happened Between late 2024 and early 2025, threat actor TeamPCP executed a supply chain attack that compromised over 170 npm and PyPI packages with more than 518 million downloads. The attack, as
GeneralA credential-stealing worm is spreading through hundreds of npm packages right now. The Mini Shai-Hulud worm, created by TeamPCP, targets the TanStack ecosystem specifically, but your exposure isn t l
IncidentIn 2024, the TeamPCP threat group executed a supply chain attack compromising 170 npm and PyPI packages, including key dependencies like the TanStack Router ecosystem and Mistral AI SDK. The attack ex