Advertisement
Cordyceps: Defending Against Malicious Pull Requests in CI/CD
The Cordyceps campaign highlights critical CI/CD vulnerabilities in GitHub Actions, targeting high-profile projects like Apache Doris and Cloudflare Workers SDK.
Novo Nordisk Breach: Securing Secrets in GitHub Development Pipelines
Analysis of the Novo Nordisk GitHub token leak and why secrets management must transition from static tools to identity-based security frameworks.
GitHub Supply Chain Disruption: Microsoft Repos Abused to Host Malware
GitHub recently disabled 73 official Microsoft repositories after they were targeted in a massive campaign pushing password-stealing malware to developers.
Boost Security Expands SDLC Defense via Strategic Acquisitions
Boost Security secures $4 million and acquires SecureIQx and Korbit.ai to streamline automated governance and security within the development lifecycle.
SAP NPM Supply Chain Attack: Analyzing the Mini Shai-Hulud Campaign
Security researchers identified a malicious supply chain attack targeting SAP via NPM packages using the Bun runtime to evade traditional EDR detection.
Checkmarx GitHub Repository Data Leaked Following Supply Chain Attack
Checkmarx confirms internal GitHub repository data was published on the dark web following a March 2026 supply chain incident. Learn the impact and TTPs.
Advertisement
Anthropic Claude Code Source Code Leaked via NPM Registry
Anthropic accidentally exposed proprietary source code for its Claude Code CLI tool on the public npm registry. Analyze the technical impact and risks.
GitGuardian 2026 Report: Analyzing the 34% Surge in Secrets Sprawl
GitGuardian's 2026 report reveals 29 million leaked secrets on GitHub in 2025. Learn how AI and hardcoded credentials impact enterprise security posture.
Betterleaks: A New Open-Source Tool for Detecting Secrets in Git
Betterleaks is a new open-source secrets scanner designed to identify hardcoded credentials and sensitive data across directories and Git repositories.
Secure-by-Design: Mitigating Enterprise Risk & Human Error
Leverage secure-by-design principles from software development to address non-technical enterprise risks, including governance gaps and human error, enhancing…
AI-Driven Development and the Crisis of Firewall Rule Backlogs
Examine how AI-accelerated coding creates network security bottlenecks and why manual firewall management fails in modern DevSecOps environments.
Claude Code Security Analysis: Assessing AI CLI Assistant Risks
Technical analysis of Anthropic's Claude Code CLI tool, evaluating its impact on application security and potential for introducing code vulnerabilities.
Anthropic Claude Code Security: Automated Static Analysis and Remediation Preview
Anthropic has introduced Claude Code Security, a research-preview tool designed to perform static analysis for vulnerability detection and automated patch generation…