Supply Chain Security

Feeds to Scour
SubscribedAll
Scoured 62 posts in 6.4 ms

NCSC Warns Of Rising Software Supply Chain Attacks Targeting Open-Source Packages

 🌐Open Source
petri.com·

sinewaveai/agent-security-scanner-mcp: Security scanner MCP server for AI coding agents. Prompt injection firewall, package hallucination detection (4.3M+ packages), 1000+ vulnerability rules with AST & taint analysis, auto-fix.

 ⌨️CLI Tools  Content type: Code
github.com··Hacker News

Shai-Hulud copycat campaign targets Python developers through PyPI typosquatting

 🛠️Developer Tools  Content type: Blog
about.gitlab.com·

someone actually leaked the Miasma supply chain attack toolkit source code on github

 ☸️Kubernetes

SAST vs SCA: Key Differences for AppSec Teams

 🔍Static Analysis
orca.security·

You can fork a package, but can you own it?

 🔬eBPF
event-driven.io·

Securing CI/CD for an open source project: Controlling who runs what

 🔬eBPF  Content type: Blog
cncf.io·

Miasma Worm Compromises 73 Microsoft GitHub Repositories

 🛠️Developer Tools
securityaffairs.com·

SOC 2 Controls for Non-Human Identities: CC6, CC7, and CC8

 ☸️Kubernetes  Content type: Blog
goteleport.com·

IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks

 🔬eBPF
thehackernews.com·

Five Supply Chain Security Risks Hiding Inside Your Mobile Apps

 🛡️AI Safety  Content type: Blog

OWASP Dependency-Track 5.0 Is Now Generally Available

 🔌APIs  Content type: Blog
owasp.org·

Miasma Malware Hits 32 Red Hat Packages via Compromised GitHub Account

 🌐Open Source
hackread.com·

(Video) Connecting vscode to FreeBSD through remote SSH

 🛠️Developer Tools
discoverbsd.com·

Two-Thirds of Open Source Community Unaware of Cyber Resilience Act

 Dev Best Practices  Content type: News

For the 2nd time in weeks, Microsoft packages laced with credential stealer

 🕸️Distributed Systems  Content type: News

Microsoft identifies seven new ways AI agents can be hacked

 ✍️Prompt Engineering  Content type: News
infoworld.com·

Show HN: CI/locksupply-chain attestation CLI, from the Witness creators

 🔬eBPF  Content type: Blog
cilock.dev··Hacker News

Meet Hades: The malware that lies to AI security agents

 ✍️Prompt Engineering  Content type: News
csoonline.com·

Spring is 23 years old. AI just made it a security emergency.

 🤖AI Engineering
thenewstack.io·

Keyboard Shortcuts

Navigation

Next / previous item
j/k
Open post
oorEnter
Preview post
v

Post Actions

Love post
a
Like post
l
Dislike post
d
Undo reaction
u
Save / unsave
s

Recommendations

Add interest / feed
Enter
Not interested
x

Go to

Home
gh
Interests
gi
Feeds
gf
Likes
gl
History
gy
Changelog
gc
Settings
gs
Browse
gb
Search
/

General

Show this help
?
Submit feedback
!
Close modal / unfocus
Esc

Press ? anytime to show this help