Supply Chain
One Click, and Every Private Repo You Can Reach Is Theirs
A link, inside the tool you use every day. Simulated keystrokes install an extension, which lifts the GitHub OAuth token - and that token is not scoped to…
Read itSupply Chain
The Docker Instruction That Runs on Your Machine, Not Theirs
ONBUILD does not run for whoever wrote it. It runs for you, the moment you FROM their image - silently, with no line in your own Dockerfile.
Read itSupply Chain
Canary Credentials: The Smoke Detector Nobody Installs
Fake credentials in the pipeline that are wired to nothing. Nothing legitimate ever touches them, so the moment anything does, you know it was stolen. Costs nothing, takes…
Read itSupply Chain
The AI Skill That Steals Your GitHub Token
A week-old GitHub account and a Markdown file is all it takes to publish a skill. One developer installing one plugin equals access to every repository the company…
Read itSupply Chain
GitHub Was Breached Through an Editor Extension
Not a zero-day. Not a sophisticated state attack. An extension. 3,800 internal repositories pulled out of the company that holds half the world's code.
Read itSupply Chain
Every npm install You Run Is a Bet
Attackers poisoned TanStack's build cache. Nobody stole credentials, nobody compromised a maintainer account. The system was simply designed in a way that allows it.
Read itSupply Chain
500 AI-Written Attacks, 90% Stopped by a Default Setting
An AI tool analysed 500 repositories and wrote a custom payload for each. Then it waited for GitHub Actions to run them automatically - which GitHub does not…
Read itSupply Chain
A Regex Without Anchors, and a Race to Register a GitHub Account
A webhook filter checked ACTOR_ID with a regex that had no ^ or $. Substring match was enough. This is not a regex mistake - it is a…
Read itSupply Chain
The Coding Test That Was a Payload: Attacking Developers Through Trust
A real profile, a real company, a clean Bitbucket repo. Thirty seconds before running it, he asked an AI to check the code - and found an obfuscated…
Read itSupply Chain
Secure Development Lifecycle for Open Source Usage
Secure Development Lifecycle for Open Source Usage by Yaron HakonPrefaceHow do we adjust the SDL (Security Development Lifecycle) process for the growing use of open source in internal/external systems…
Read itTell us what the system does and what worries you.
If a penetration test is not what you need yet, we will say so.