AI in the Build Pipeline: How Software Supply Chain Security Must Evolve
Software supply chain security was already complex, but the integration of AI into the build pipeline has introduced new risks that traditional…
Software supply chain security was already complex, but the integration of AI into the build pipeline has introduced new risks that traditional…
New research from Adversa AI, dubbed 'GuardFall,' reveals that ten out of eleven popular open-source AI coding agents are vulnerable to a…
Microsoft researchers have disclosed a novel exploit chain named AutoJack that allows a single malicious web page to hijack an AI browsing…
PostHog is a product analytics platform that was breached as part of a campaign exploiting pwn request attacks via pull_request_target workflows.
TanStack is an open source software development company that was breached in a campaign exploiting pwn request attacks via pull_request_target workflows.