» Tag
supplychain
5 posts0-click RCE flaw in AI coding agents poses major security risk
A zero-click vulnerability in AI coding agents could give attackers full access.
AsyncAPI Supply Chain Attack Delivers Miasma RAT via NPM
A supply chain attack on AsyncAPI has resulted in malicious npm packages delivering Miasma RAT. This incident reveals critical vulnerabilities.
Slopsquatting: Your Coding Agent Is a Supply-Chain Attack Vector
Slopsquatting is a supply-chain attack emerging from AI coding agents. Learn how LineageLens Trellis mitigates this risk.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comDisrupting Supply Chain Attacks on NPM and GitHub Actions
Recent updates on npm and GitHub Actions aim to disrupt supply chain attacks.
DepsGuard – A Native Cross-Platform Security Tool
DepsGuard scans npm and other managers for security vulnerabilities, enhancing protection against supply chain attacks.