» Tag
supply-chain
19 postsLicense Laundering Exposed Across AI Dataset-to-App Supply Chains
Study of 232,270 AI supply chains reveals systematic license laundering, with obligation-bearing licenses vanishing while permissive ones persist.
Python Bytecode: The Security Blind Spot Beyond Source Review
Study of over 1M PyPI packages shows Python .pyc bytecode bypasses source-level security review, exposing CPython to crashes and memory-corruption bugs.
Show HN: A Real-Data Simulator for a Strait of Hormuz Closure Scenario
An open interactive simulator models a Strait of Hormuz closure using real oil trade data and a network-based economic model.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comAI Coding CLI Uploads Entire Git History, Bypassing Privacy Opt-Out
An AI coding CLI was found silently uploading full Git history and secrets to vendor storage, bypassing the privacy opt-out users trusted.
Cybersecurity Startup Published Infostealers to NPM
Seven NPM packages typosquatting Anthropic, OpenAI, LangChain and Vercel used postinstall scripts to exfiltrate git, SSH and cloud identity data. The publisher traces back to an Israeli security startup founder.
Shadow AI: You Can't Secure the AI Systems You Can't See
Enterprise AI adoption is outpacing visibility. A look at shadow AI risks and how an AI Bill of Materials helps discover, own, and govern hidden AI systems.
Hackers poison arrayref Rust crate to push infostealer malware
Hackers compromised the arrayref Rust crate to introduce infostealer malware. Learn more about the attack.
Malicious Jscrambler NPM Package Versions Deploy Infostealer
A supply chain attack on the jscrambler npm package highlights risks to developer credentials.
Supply Chain Attack Discovered in BdThemes WordPress Plugins
Supply chain attack in BdThemes WordPress plugins: hidden admin accounts created.