DEV Community

# supplychainsecurity

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Miasma Worm: How Opening a Repo in Claude Code Became a Credential Theft Vector

Miasma Worm: How Opening a Repo in Claude Code Became a Credential Theft Vector

Comments
9 min read
The Gemini CLI CVSS 10 Attack: How a GitHub Issue Became a Supply Chain Weapon

The Gemini CLI CVSS 10 Attack: How a GitHub Issue Became a Supply Chain Weapon

Comments
6 min read
Supply Chain Attacks: Schutz vor bösartigen Abhängigkeiten im IT-Betrieb

Supply Chain Attacks: Schutz vor bösartigen Abhängigkeiten im IT-Betrieb

Comments
5 min read
Signing Container Images with Cosign

Signing Container Images with Cosign

Comments
15 min read
The CRA's 24-hour clock is a cross-repo question. Your SBOM answers a different one.

The CRA's 24-hour clock is a cross-repo question. Your SBOM answers a different one.

Comments
12 min read
Socket: Secure Your JavaScript Supply Chain Against AI Threats

Socket: Secure Your JavaScript Supply Chain Against AI Threats

Comments
6 min read
What LucidShark Would Have Caught Before the TanStack Attack Landed

What LucidShark Would Have Caught Before the TanStack Attack Landed

Comments
7 min read
Clinejection: When Your AI Coding Tool Became the Weapon

Clinejection: When Your AI Coding Tool Became the Weapon

1
Comments
9 min read
Slopsquatting: The Attacker Playbook for AI-Hallucinated Package Names

Slopsquatting: The Attacker Playbook for AI-Hallucinated Package Names

1
Comments
10 min read
Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers

Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers

Comments
9 min read
AI Hallucinated Dependencies Are the New Supply Chain Attack: How to Stop Them

AI Hallucinated Dependencies Are the New Supply Chain Attack: How to Stop Them

Comments
8 min read
Supply Chain Security Proxy: Move Beyond Vulnerability Scanning

Supply Chain Security Proxy: Move Beyond Vulnerability Scanning

Comments
8 min read
GitHub Actions Security: How to Stop Secret Leaks in CI/CD

GitHub Actions Security: How to Stop Secret Leaks in CI/CD

Comments
7 min read
How Attackers Turned Trivy Into a Weapon Against Cisco

How Attackers Turned Trivy Into a Weapon Against Cisco

Comments
4 min read
Cisco's Source Code Breach Was Structural, Not Accidental

Cisco's Source Code Breach Was Structural, Not Accidental

Comments
3 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.