Skip to main content
← All Articles

Tag

#devsecops

6 articles

Advertisement

Cordyceps: Defending Against Malicious Pull Requests in CI/CD
HIGH
Supply Chain

Cordyceps: Defending Against Malicious Pull Requests in CI/CD

The Cordyceps campaign highlights critical CI/CD vulnerabilities in GitHub Actions, targeting high-profile projects like Apache Doris and Cloudflare Workers SDK.

Runtime Rebel Intel
4 min read·Jun 24, 2026
SU
HIGH
Supply Chain

GitHub Supply Chain Disruption: Microsoft Repos Abused to Host Malware

GitHub recently disabled 73 official Microsoft repositories after they were targeted in a massive campaign pushing password-stealing malware to developers.

Runtime Rebel Intel
4 min read·Jun 9, 2026
SU
HIGH
Supply Chain

SAP NPM Supply Chain Attack: Analyzing the Mini Shai-Hulud Campaign

Security researchers identified a malicious supply chain attack targeting SAP via NPM packages using the Bun runtime to evade traditional EDR detection.

Runtime Rebel Intel
4 min read·Apr 30, 2026
SU
MEDIUM
Supply Chain

Anthropic Claude Code Source Code Leaked via NPM Registry

Anthropic accidentally exposed proprietary source code for its Claude Code CLI tool on the public npm registry. Analyze the technical impact and risks.

Runtime Rebel Intel
3 min read·Apr 1, 2026
AI-Driven Development and the Crisis of Firewall Rule Backlogs
INFO
Cloud Security

AI-Driven Development and the Crisis of Firewall Rule Backlogs

Examine how AI-accelerated coding creates network security bottlenecks and why manual firewall management fails in modern DevSecOps environments.

Runtime Rebel Intel
3 min read·Mar 3, 2026
Claude Code Security Analysis: Assessing AI CLI Assistant Risks
INFO
Threat Intel

Claude Code Security Analysis: Assessing AI CLI Assistant Risks

Technical analysis of Anthropic's Claude Code CLI tool, evaluating its impact on application security and potential for introducing code vulnerabilities.

Runtime Rebel Intel
4 min read·Feb 27, 2026