Supply Chain Security

Feeds to Scour
SubscribedAll
Scoured 172 posts in 9.8 ms

From SBOMs to AI BOMs: Why SPDX 3.0 Matters

馃敀Security
malware.news

5 Software Supply Chain Security Best Practices for Development Teams

馃敀SecurityContent type: Blog
docker.com

Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave

馃敀SecurityContent type: Blog
socket.dev

Shai-Hulud copycat campaign targets Python developers through PyPI typosquatting

馃敀SecurityContent type: Blog
about.gitlab.com

Trying to make sense of package-manager metadata

馃敀Security
lwn.net

debsecan-mcp v0.1.2 released to PyPI

馃摑GitContent type: Blog
copyninja.in

Massive PyPI Supply Chain Attack Harvests Cloud Credentials via Python Startup Hooks

馃敀Security
orca.security

I Replaced Our Commercial Artifact Registry With a Free One After a 5脳 Renewal Price Hike.

馃惙TrufflehogContent type: Blog
medium.com

Shai-Hulud Hades PyPI Campaign: 19 Packages Trojanized via Wheel Startup Hooks

馃敀SecurityContent type: Blog
socradar.io

Hades PyPI Malware: Miasma Campaign Exploits .pth Startup Hooks

馃敀Security
sh.itjust.works

NCSC Warns Of Rising Software Supply Chain Attacks Targeting Open-Source Packages

馃敀Security
petri.com
Less-relevant results

GlassFish 8.0.3 Released: Performance optimizations and security fixes

馃敀Security
omnifish.eer/java

Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks

馃敀Security
securityweek.com

AI Code Review Got Much Better When I Gave It Design Contracts, Not Just Code (Fable5 review)

馃捇Coding
nuget.orgDEV

Glone: A CLI to back up all your GitHub repositories

馃摑GitContent type: Code
github.comHacker News

Release v0.2.90 路 anthropics/claude-agent-sdk-python

馃Agentic AIContent type: Code
github.com

Five Supply Chain Security Risks Hiding Inside Your Mobile Apps

馃敀SecurityContent type: Blog
supplychainbrain.com

The Day Rust鈥檚 Time Utilities Started Stealing Secrets

馃惙TrufflehogContent type: Blog
medium.com

New Shai-Hulud attack trojanizes 19 science-focused PyPI packages

馃敀SecurityContent type: News
bleepingcomputer.com

Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer

馃敀Security
thehackernews.com

Keyboard Shortcuts

Navigation

Next / previous item
j/k
Open post
oorEnter
Preview post
v

Post Actions

Love post
a
Like post
l
Dislike post
d
Undo reaction
u
Save / unsave
s

Recommendations

Add interest / feed
Enter
Not interested
x

Go to

Home
gh
Interests
gi
Feeds
gf
Likes
gl
History
gy
Changelog
gc
Settings
gs
Browse
gb
Search
/

General

Show this help
?
Submit feedback
!
Close modal / unfocus
Esc

Press ? anytime to show this help