Skip to main content
← All Articles

Tag

#DevSecOps

13 articles

Advertisement

Cordyceps: Defending Against Malicious Pull Requests in CI/CD
HIGH
Supply Chain

Cordyceps: Defending Against Malicious Pull Requests in CI/CD

The Cordyceps campaign highlights critical CI/CD vulnerabilities in GitHub Actions, targeting high-profile projects like Apache Doris and Cloudflare Workers SDK.

Runtime Rebel Intel
4 min read · Jun 24, 2026
Novo Nordisk Breach: Securing Secrets in GitHub Development Pipelines
MEDIUM
Supply Chain

Novo Nordisk Breach: Securing Secrets in GitHub Development Pipelines

Analysis of the Novo Nordisk GitHub token leak and why secrets management must transition from static tools to identity-based security frameworks.

Runtime Rebel Intel
4 min read · Jun 19, 2026
HIGH
Supply Chain

GitHub Supply Chain Disruption: Microsoft Repos Abused to Host Malware

GitHub recently disabled 73 official Microsoft repositories after they were targeted in a massive campaign pushing password-stealing malware to developers.

Runtime Rebel Intel
4 min read · Jun 9, 2026
INFO
Supply Chain

Boost Security Expands SDLC Defense via Strategic Acquisitions

Boost Security secures $4 million and acquires SecureIQx and Korbit.ai to streamline automated governance and security within the development lifecycle.

Runtime Rebel Intel
3 min read · May 7, 2026
MEDIUM
Supply Chain

SAP NPM Supply Chain Attack: Analyzing the Mini Shai-Hulud Campaign

Security researchers identified a malicious supply chain attack targeting SAP via NPM packages using the Bun runtime to evade traditional EDR detection.

Runtime Rebel Intel
4 min read · Apr 30, 2026
Checkmarx GitHub Repository Data Leaked Following Supply Chain Attack
HIGH
Supply Chain

Checkmarx GitHub Repository Data Leaked Following Supply Chain Attack

Checkmarx confirms internal GitHub repository data was published on the dark web following a March 2026 supply chain incident. Learn the impact and TTPs.

Runtime Rebel Intel
4 min read · Apr 27, 2026

Advertisement

MEDIUM
Supply Chain

Anthropic Claude Code Source Code Leaked via NPM Registry

Anthropic accidentally exposed proprietary source code for its Claude Code CLI tool on the public npm registry. Analyze the technical impact and risks.

Runtime Rebel Intel
3 min read · Apr 1, 2026
GitGuardian 2026 Report: Analyzing the 34% Surge in Secrets Sprawl
MEDIUM
Identity & Access

GitGuardian 2026 Report: Analyzing the 34% Surge in Secrets Sprawl

GitGuardian's 2026 report reveals 29 million leaked secrets on GitHub in 2025. Learn how AI and hardcoded credentials impact enterprise security posture.

Runtime Rebel Intel
4 min read · Mar 30, 2026
INFO
Identity & Access

Betterleaks: A New Open-Source Tool for Detecting Secrets in Git

Betterleaks is a new open-source secrets scanner designed to identify hardcoded credentials and sensitive data across directories and Git repositories.

Runtime Rebel Intel
4 min read · Mar 15, 2026
Secure-by-Design: Mitigating Enterprise Risk & Human Error
INFO
Threat Intel

Secure-by-Design: Mitigating Enterprise Risk & Human Error

Leverage secure-by-design principles from software development to address non-technical enterprise risks, including governance gaps and human error, enhancing…

Runtime Rebel Intel
4 min read · Mar 5, 2026
AI-Driven Development and the Crisis of Firewall Rule Backlogs
INFO
Cloud Security

AI-Driven Development and the Crisis of Firewall Rule Backlogs

Examine how AI-accelerated coding creates network security bottlenecks and why manual firewall management fails in modern DevSecOps environments.

Runtime Rebel Intel
3 min read · Mar 3, 2026
Claude Code Security Analysis: Assessing AI CLI Assistant Risks
INFO
Threat Intel

Claude Code Security Analysis: Assessing AI CLI Assistant Risks

Technical analysis of Anthropic's Claude Code CLI tool, evaluating its impact on application security and potential for introducing code vulnerabilities.

Runtime Rebel Intel
4 min read · Feb 27, 2026
INFO
Vulnerabilities

Anthropic Claude Code Security: Automated Static Analysis and Remediation Preview

Anthropic has introduced Claude Code Security, a research-preview tool designed to perform static analysis for vulnerability detection and automated patch generation…

Runtime Rebel Intel
2 min read · Feb 23, 2026