Skip to content
Book a call

Home / Blog / Supply Chain

Category

Supply Chain

Dependency and pipeline attacks – poisoned packages, malicious editor extensions and AI tool plugins, and CI/CD as an attack surface.

Supply Chain

One Click, and Every Private Repo You Can Reach Is Theirs

A link, inside the tool you use every day. Simulated keystrokes install an extension, which lifts the GitHub OAuth token - and that token is not scoped to…

Read it

Supply Chain

The Docker Instruction That Runs on Your Machine, Not Theirs

ONBUILD does not run for whoever wrote it. It runs for you, the moment you FROM their image - silently, with no line in your own Dockerfile.

Read it

Supply Chain

Canary Credentials: The Smoke Detector Nobody Installs

Fake credentials in the pipeline that are wired to nothing. Nothing legitimate ever touches them, so the moment anything does, you know it was stolen. Costs nothing, takes…

Read it

Supply Chain

The AI Skill That Steals Your GitHub Token

A week-old GitHub account and a Markdown file is all it takes to publish a skill. One developer installing one plugin equals access to every repository the company…

Read it

Supply Chain

GitHub Was Breached Through an Editor Extension

Not a zero-day. Not a sophisticated state attack. An extension. 3,800 internal repositories pulled out of the company that holds half the world's code.

Read it

Supply Chain

Every npm install You Run Is a Bet

Attackers poisoned TanStack's build cache. Nobody stole credentials, nobody compromised a maintainer account. The system was simply designed in a way that allows it.

Read it

Supply Chain

500 AI-Written Attacks, 90% Stopped by a Default Setting

An AI tool analysed 500 repositories and wrote a custom payload for each. Then it waited for GitHub Actions to run them automatically - which GitHub does not…

Read it

Supply Chain

A Regex Without Anchors, and a Race to Register a GitHub Account

A webhook filter checked ACTOR_ID with a regex that had no ^ or $. Substring match was enough. This is not a regex mistake - it is a…

Read it

Supply Chain

The Coding Test That Was a Payload: Attacking Developers Through Trust

A real profile, a real company, a clean Bitbucket repo. Thirty seconds before running it, he asked an AI to check the code - and found an obfuscated…

Read it

Supply Chain

Secure Development Lifecycle for Open Source Usage

Secure Development Lifecycle for Open Source Usage  by Yaron HakonPrefaceHow do we adjust the SDL (Security Development Lifecycle) process for the growing use of open source in internal/external systems…

Read it

Tell us what the system does and what worries you.

If a penetration test is not what you need yet, we will say so.

Book a scoping call See the test catalogue