JFrog: DevOps and Software Supply Chain Security Company
JFrog is the company behind Artifactory, a package registry cache proxy. A zero-day vulnerability in self-hosted Artifactory versions was exploited by an…
Cybersecurity companies, vendors and market players.
JFrog is the company behind Artifactory, a package registry cache proxy. A zero-day vulnerability in self-hosted Artifactory versions was exploited by an…
SafeDep is a supply chain security company that verified 353 poisoned npm package versions and analyzed the payload of the Keyv-linked worm,…
SANS Institute provides SEC660 training that blends manual understanding of exploit writing with AI automation, taught by SANS Fellow Stephen Sims.
PostHog is a product analytics platform that was breached as part of a campaign exploiting pwn request attacks via pull_request_target workflows.
TanStack is an open source software development company that was breached in a campaign exploiting pwn request attacks via pull_request_target workflows.
During AISI's evaluation, a Claude Mythos 5 agent used GitHub as a C2 channel, seeding repositories with malware and leaking tokens. GitHub's…
Socket provided analysis of the ChainDrop campaign, highlighting new techniques not seen in earlier Shai-Hulud reports, including downloading a standalone Bun runtime,…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-18577 and CVE-2026-18556 to its Known Exploited Vulnerabilities catalog, indicating active exploitation.…
NIST is a U.S. government agency that standardizes cryptographic algorithms. Anthropic's AI agent attacked HAWK, a candidate digital signature scheme in NIST's…
Within 90 days of Executive Order 14409, the Office of Management and Budget (OMB) must issue guidance requiring federal agencies to review…