Skip to content
AppSec Labs logo
  • Penetration Testing Services
    • Web Applications
    • SaaS & Multi-Tenant
    • APIs
    • Mobile Apps
    • AI & LLM
  • Our Methodology
    • Attacks & Tests
    • Testing modes
  • About
    • Alumni
    • The Book
  • Careers
  • Blog
  • Contact
  • עברית

Contact us

Have a question or comment? Submit your message through our contact form and a member of our team will get back to you within 24 hours.

    Supply Chain

    • Home
    • Blog
    • Supply Chain
    Supply Chain

    The Docker Instruction That Runs on Your Machine, Not Theirs

    June 9, 2026 No comments yet

    ONBUILD does not run for whoever wrote it. It runs for you, the moment you FROM their image – silently, with no line in your own Dockerfile.

    Supply Chain

    The AI Skill That Steals Your GitHub Token

    June 6, 2026 No comments yet

    A week-old GitHub account and a Markdown file is all it takes to publish a skill. One developer installing one plugin equals access to every repository the company has.

    Supply Chain

    GitHub Was Breached Through an Editor Extension

    June 4, 2026 No comments yet

    Not a zero-day. Not a sophisticated state attack. An extension. 3,800 internal repositories pulled out of the company that holds half the world’s code.

    Supply Chain

    Every npm install You Run Is a Bet

    May 25, 2026 No comments yet

    Attackers poisoned TanStack’s build cache. Nobody stole credentials, nobody compromised a maintainer account. The system was simply designed in a way that allows it.

    Supply Chain

    500 AI-Written Attacks, 90% Stopped by a Default Setting

    April 26, 2026 No comments yet

    An AI tool analysed 500 repositories and wrote a custom payload for each. Then it waited for GitHub Actions to run them automatically – which GitHub does not do for new contributors.

    Supply Chain

    A Regex Without Anchors, and a Race to Register a GitHub Account

    February 2, 2026 No comments yet

    A webhook filter checked ACTOR_ID with a regex that had no ^ or $. Substring match was enough. This is not a regex mistake – it is a deep understanding of how an application decides.

    Supply Chain

    The Coding Test That Was a Payload: Attacking Developers Through Trust

    October 30, 2025 No comments yet

    A real profile, a real company, a clean Bitbucket repo. Thirty seconds before running it, he asked an AI to check the code – and found an obfuscated loader inside one controller.

    Supply Chain

    Secure Development Lifecycle for Open Source Usage

    December 24, 2024 AppSec Labs No comments yet

    Secure Development Lifecycle for Open Source Usage     by Yaron Hakon Preface How do we adjust the SDL (Security Development Lifecycle) process for the growing use of open source in internal/external systems we develop and maintain? This is a question I hear a lot lately from our customers in some recent SDL projects we […]

    Search

    Categories

    • AI and LLM Security (26)
    • API Security (7)
    • Application Security (18)
    • Authorization and Access Control (11)
    • Black Box Testing (3)
    • Brute Force (1)
    • Cloud Security (13)
    • Engagements and Process (10)
    • Hacking (4)
    • Mobile Security (4)
    • Supply Chain (15)
    • White Box Testing (1)

    Recent posts

    • Somebody Wired the Darknet Into Your AI. What Could Go Wrong?
    • Configured Is Not Enforced
    • Every Week Someone Asks Me When AI Will Replace Pentesters
    AppSec Labs logo

    AppSec Labs offer rapid, modern security penetration testing, utilizing smart solutions to protect against evolving cyber threats.

    Features
    • Home
    Resources
    • Blog
    Company
    • About us
    Get in touch
    • info@appsec-labs.com
    • +972 52-433-9393

    © AppSec Labs 2026. All Rights Reserved.

    • Terms & Conditions
    • Privacy Policy