Skip to content
Topic

#Supply Chain Security

31 articles on Supply Chain Security — news, releases, guides and analysis from the SourceFeed engine.

The AI Didn't Go Rogue. The Test Bed Did.
Article 4d ago 4

The AI Didn't Go Rogue. The Test Bed Did.

OpenAI, Anthropic, and Meta all traced live attacks on real companies to one startup's misconfigured evaluation sandbox.

Emeka Okafor
Why a "Verified" GitHub Commit Hash Is Not Unique

Why a "Verified" GitHub Commit Hash Is Not Unique

Article · 1mo ago0
Alibaba’s Claude Code Ban Exposes the Agentic Security Paradox

Alibaba’s Claude Code Ban Exposes the Agentic Security Paradox

Article · 1mo ago2
Inside PinpinRAT: How APTs Hijack Developer Build Pipelines

Inside PinpinRAT: How APTs Hijack Developer Build Pipelines

Article · 1mo ago5
AI Coding Assistants Turn Local Git Repos Into Cloud Exploits

AI Coding Assistants Turn Local Git Repos Into Cloud Exploits

Article · 1mo ago2
The Cordyceps Exploits: Why Your CI/CD Pipelines Are Wide Open

The Cordyceps Exploits: Why Your CI/CD Pipelines Are Wide Open

Article · 1mo ago0
Apple Absorbs Swift Package Index. Watch the Signing Plan.

Apple Absorbs Swift Package Index. Watch the Signing Plan.

News · 1mo ago2
GitHub Hardens actions/checkout to Block Pwn Request Attacks

GitHub Hardens actions/checkout to Block Pwn Request Attacks

Article · 1mo ago0
The GitHub Clone Farm That Beat VirusTotal

The GitHub Clone Farm That Beat VirusTotal

Article · 1mo ago2
Arch's AUR Malware Sprawl Hits 1,579 Packages

Arch's AUR Malware Sprawl Hits 1,579 Packages

News · 1mo ago6
Homebrew 6.0.0 Makes You Trust Your Taps

Homebrew 6.0.0 Makes You Trust Your Taps

Release · 2mos ago7
npm v12 Is About to Stop Running Your Install Scripts — Here's What to Audit

npm v12 Is About to Stop Running Your Install Scripts — Here's What to Audit

News · 2mos ago5
Miasma Worm Hits Microsoft Packages Twice in Weeks — and Your SLSA Provenance Won't Save You

Miasma Worm Hits Microsoft Packages Twice in Weeks — and Your SLSA Provenance Won't Save You

Article · 2mos ago1
uv Gets Built-In Vulnerability and Malware Scanning

uv Gets Built-In Vulnerability and Malware Scanning

News · 2mos ago1
Config Files That Run Code: The Supply Chain Blind Spot Nobody Is Auditing

Config Files That Run Code: The Supply Chain Blind Spot Nobody Is Auditing

Article · 2mos ago0
Config Files That Run Code: The Supply Chain Blindspot You're Probably Not Auditing

Config Files That Run Code: The Supply Chain Blindspot You're Probably Not Auditing

Article · 2mos ago0