Skip to main content
← All Articles

Tag

#Open Source Security

9 articles

Advertisement

SU
HIGH
Supply Chain

Bash Tricks Exploit AI Agents: Supply Chain Attack Risk Analysis

Analysis of how decades-old Bash shell vulnerabilities can bypass safeguards in AI coding agents, enabling supply chain attacks via malicious repositories.

Runtime Rebel Intel
5 min read·Jun 30, 2026
SU
INFO
Supply Chain

Linux Foundation's Project Akrites: Bolstering Open Source Security

Project Akrites aims to streamline vulnerability management across open source projects, enhancing reporting, patching, and disclosure processes for critical software.

Runtime Rebel Intel
4 min read·Jun 26, 2026
Miasma Compromises 73 Microsoft GitHub Repos: Incident Analysis
CRITICAL
Supply Chain

Miasma Compromises 73 Microsoft GitHub Repos: Incident Analysis

Microsoft restores some GitHub repositories after 73 projects were hit by Miasma's supply chain attack to inject information stealers. Learn detection steps.

Runtime Rebel Intel
4 min read·Jun 9, 2026
SU
HIGH
Supply Chain

Shai-Hulud Attack: Trojanized PyPI Packages Steal Developer Secrets

New Shai-Hulud supply chain attack compromises 19 science-focused PyPI packages, distributing malware to steal developer credentials and secrets.

Runtime Rebel Intel
4 min read·Jun 8, 2026
Shai-Hulud Campaign: TeamPCP Targets Open-Source Supply Chain
HIGH
Supply Chain

Shai-Hulud Campaign: TeamPCP Targets Open-Source Supply Chain

Analysis of the Shai-Hulud campaign by TeamPCP, detailing their open-source supply chain attacks, TTPs, and critical mitigation strategies.

Runtime Rebel Intel
5 min read·May 26, 2026
SU
MEDIUM
Supply Chain

RubyGems Suspends Registrations Due to Malicious Package Influx

RubyGems maintainers suspended new user registrations after detecting an automated attack involving over 500 malicious packages targeting platform resources.

Runtime Rebel Intel
4 min read·May 13, 2026
Axios Attack: Industrialized Social Engineering on NPM Maintainers
HIGH
Supply Chain

Axios Attack: Industrialized Social Engineering on NPM Maintainers

An analysis of the Axios NPM package attack reveals advanced, scaled social engineering campaigns targeting open-source maintainers, elevating supply chain risk.

Runtime Rebel Intel
4 min read·Apr 7, 2026
Open Source Security: Key Findings from 2025 Trust Report
INFO
Supply Chain

Open Source Security: Key Findings from 2025 Trust Report

Analysis of the 2025 State of Trusted Open Source Report, detailing prevalent vulnerabilities and consumption patterns in container images and language libraries.

Runtime Rebel Intel
4 min read·Apr 2, 2026
SU
INFO
Supply Chain

Tech Giants Pledge $12.5M to Bolster Open Source Software Security

Anthropic, AWS, Google, Microsoft, and OpenAI invest $12.5 million into the OpenSSF to mitigate systemic supply chain risks in open source ecosystems.

Runtime Rebel Intel
4 min read·Mar 17, 2026