Skip to content
HiveSecurity
  • Home
  • Blog
  • Tags
  • Vulnerabilities
    • Tools
    • Cheat Sheet
    • Security Guides
  • Contact
  • About
Esc
Type to search...
  • Home
  • Blog
  • Tags
  • Vulnerabilities
  • Resources
  • Tools
  • Cheat Sheet
  • Security Guides
  • Contact
  • About
← All tags Tag

DevSecOps

8 articles

STRIDE Threat Modeling: A Practical Guide Nobody Needs a Tool to Start

STRIDE has been Microsoft's threat modeling framework since 1999 and still works. Here's how to run a real session with a whiteboard, a data flow diagram, and 30 minutes — no expensive tooling required.

24 July 2026
AppSec DevSecOps Blue Team

Dependency Confusion: Your Internal Package Name Is a Public Attack Surface

Publish a package with the same name as a company's private one, give it a higher version number, and package managers will happily install the attacker's code instead. Here's how it still works in 2026.

20 July 2026
Supply Chain DevSecOps Blue Team

Minimum Package Age: The Supply Chain Control That Buys Defenders Time

Fast takedowns do not protect systems that auto-install malicious packages or extensions in the first minutes after release. Minimum package age turns time into a practical supply chain defense.

5 July 2026
Supply Chain Blue Team DevSecOps

Quasar Linux QLNX: A Developer Workstation RAT Built for Supply Chain Access

Trend Micro documented QLNX, a Linux RAT that combines credential harvesting, LD_PRELOAD persistence, PAM backdoors, and rootkit behavior. The real risk is not one infected host - it is the supply chain access behind it.

26 May 2026
Linux Supply Chain Malware

GitHub Finally Puts a Human in the Loop: npm Staged Publishing Explained

npm packages no longer publish instantly. GitHub's staged publishing forces a 2FA-gated human approval before any version hits the registry — here's what it means and how to enable it.

25 May 2026
Supply Chain Blue Team DevSecOps

GitHub's VS Code Extension Breach: What We Know, What We Don't, and How to Defend

GitHub says an employee device was compromised through a poisoned third-party VS Code extension and internal repositories were exfiltrated. Here is the fact-checked breakdown for defenders.

Updated 21 May 2026
Cybersecurity Supply Chain Developer Security

The Cache That Bites Back: GitHub Actions Cache Poisoning Attacks

How attackers turn GitHub Actions' shared build cache into a supply chain weapon — real cases, attack mechanics, detection logic, and mitigations.

12 May 2026
Supply Chain GitHub Actions Red Team

GitHub Secrets Management Crisis: 65% of AI Companies Leaked Credentials

65% of Forbes AI 50 companies leaked secrets on GitHub with 94-day median remediation time. Blue team guide to detect, prevent, and respond to repository leaks.

7 May 2026
Cybersecurity DevSecOps Supply Chain
HiveSecurity

Offensive thinking. Defensive expertise.

Content
  • Home
  • Blog
  • Tags
  • Vulnerabilities
Resources
  • Tools
  • Cheat Sheet
  • Security Guides
Company
  • Contact
  • About
  • RSS
  • Privacy
  • Security Policy

© 2026 Hive Security. All rights reserved.

Built with zero trust & least privilege