JFrog Artifactory CVEs: Your Artifact Repository Is a Build Boundary
CISA KEV activity and a fresh critical Artifactory authentication bypass show why package repositories need incident-grade monitoring, not just routine patching.
12 articles
CISA KEV activity and a fresh critical Artifactory authentication bypass show why package repositories need incident-grade monitoring, not just routine patching.
Australian and U.S. authorities have charged alleged TeamPCP operators after a software supply chain campaign that authorities say hit more than 1,000 organizations. The defensive lesson is about tokens, publishing rights, and update speed.
NGINX 1.30.4 and 1.31.3 fixed three new memory-safety flaws, but exposure depends on map, slice, SSI, proxy, and buffering configuration. Here is how to audit the real path.
Cato AI Labs found two 9.8 CVSS flaws in Cursor's terminal sandbox — CVE-2026-50548 and CVE-2026-50549 — that let a poisoned MCP response or search result silently escape to full remote code execution. Neither requires a click.
STRIDE has been Microsoft's threat modeling framework since 1999 and still works. Here's how to run a real session with a whiteboard, a data flow diagram, and 30 minutes — no expensive tooling required.
Publish a package with the same name as a company's private one, give it a higher version number, and package managers will happily install the attacker's code instead. Here's how it still works in 2026.
Fast takedowns do not protect systems that auto-install malicious packages or extensions in the first minutes after release. Minimum package age turns time into a practical supply chain defense.
Trend Micro documented QLNX, a Linux RAT that combines credential harvesting, LD_PRELOAD persistence, PAM backdoors, and rootkit behavior. The real risk is not one infected host - it is the supply chain access behind it.
npm packages no longer publish instantly. GitHub's staged publishing forces a 2FA-gated human approval before any version hits the registry — here's what it means and how to enable it.
GitHub says an employee device was compromised through a poisoned third-party VS Code extension and internal repositories were exfiltrated. Here is the fact-checked breakdown for defenders.
How attackers turn GitHub Actions' shared build cache into a supply chain weapon — real cases, attack mechanics, detection logic, and mitigations.
65% of Forbes AI 50 companies leaked secrets on GitHub with 94-day median remediation time. Blue team guide to detect, prevent, and respond to repository leaks.