Skip to content
Navigation menu
Search
Powered by Algolia
Search
Log in
Create account
DEV Community
Close
#
supplychain
Follow
Hide
Posts
Left menu
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
Right menu
GitHub got pwned through one VSCode extension. 3,800 repos.
Ritabrata Maiti
Ritabrata Maiti
Ritabrata Maiti
Follow
Sep 24
GitHub got pwned through one VSCode extension. 3,800 repos.
#
github
#
vscode
#
security
#
supplychain
Comments
Add Comment
5 min read
The JFrog Artifactory authentication bypass: when an empty signing key becomes an admin token
StarkMan
StarkMan
StarkMan
Follow
Sep 24
The JFrog Artifactory authentication bypass: when an empty signing key becomes an admin token
#
supplychain
#
artifactrepository
#
authenticationbypass
#
jfrog
Comments
Add Comment
3 min read
The Credential Relay Economy: How Supply Chain Attacks Chain Through SaaS Vendors
jeffrey
jeffrey
jeffrey
Follow
Sep 23
The Credential Relay Economy: How Supply Chain Attacks Chain Through SaaS Vendors
#
supplychain
#
credentials
#
saassecurity
Comments
Add Comment
2 min read
Software Supply Chains Have an Address: Mapping Exposed Artifact Repositories with ZoomEye
jeffrey
jeffrey
jeffrey
Follow
Sep 23
Software Supply Chains Have an Address: Mapping Exposed Artifact Repositories with ZoomEye
#
supplychain
#
attacksurface
#
zoomeye
#
exposuremanagement
Comments
Add Comment
3 min read
The Ghost in the Machine: Unraveling Persistent Git Compromises Beyond Your Control
Oleg
Oleg
Oleg
Follow
Sep 22
The Ghost in the Machine: Unraveling Persistent Git Compromises Beyond Your Control
#
security
#
github
#
devops
#
supplychain
Comments
Add Comment
5 min read
The Artifactory Token Chain: Why Build Repositories Are a Credential Store
kozhevniko
kozhevniko
kozhevniko
Follow
Sep 21
The Artifactory Token Chain: Why Build Repositories Are a Credential Store
#
supplychain
#
artifactrepository
#
authenticationbypass
#
devsecops
Comments
Add Comment
4 min read
700 Agents, 25 Actions Each, and Nothing Fired
Jason Miller
Jason Miller
Jason Miller
Follow
Sep 21
700 Agents, 25 Actions Each, and Nothing Fired
#
supplychain
#
secrets
#
aiagents
Comments
Add Comment
3 min read
The Artifact Repository Is a Trust Root: Reading the JFrog Artifactory Authentication Bypass
jeffrey
jeffrey
jeffrey
Follow
Sep 20
The Artifact Repository Is a Trust Root: Reading the JFrog Artifactory Authentication Bypass
#
supplychain
#
devops
#
authentication
#
artifactrepository
Comments
Add Comment
4 min read
The Shai-Hulud npm worm showed that opening a folder is enough to run code
yutianle
yutianle
yutianle
Follow
Sep 20
The Shai-Hulud npm worm showed that opening a folder is enough to run code
#
supplychain
#
npm
#
developertooling
#
credentialtheft
Comments
Add Comment
3 min read
Print Servers and Artifact Repositories: Measuring Two Overlooked Attack Surfaces
kozhevniko
kozhevniko
kozhevniko
Follow
Sep 20
Print Servers and Artifact Repositories: Measuring Two Overlooked Attack Surfaces
#
security
#
zoomeye
#
exposure
#
supplychain
Comments
Add Comment
3 min read
One Console, Every Customer: What the N-able N-central Pre-Authentication RCE Says About RMM Concentration Risk
jeffrey
jeffrey
jeffrey
Follow
Sep 20
One Console, Every Customer: What the N-able N-central Pre-Authentication RCE Says About RMM Concentration Risk
#
vulnerabilitymanagement
#
msp
#
rmm
#
supplychain
Comments
Add Comment
3 min read
The Default Join Key That Let Attackers Mint Admin Tokens on JFrog Artifactory
yutianle
yutianle
yutianle
Follow
Sep 20
The Default Join Key That Let Attackers Mint Admin Tokens on JFrog Artifactory
#
supplychain
#
authenticationbypass
#
artifactory
#
cve202682329
Comments
Add Comment
4 min read
From Warehouses to Algorithms: How JD Logistics Builds a Technology-Driven Supply Chain
lyee blair
lyee blair
lyee blair
Follow
Sep 20
From Warehouses to Algorithms: How JD Logistics Builds a Technology-Driven Supply Chain
#
jdlogistics
#
jingdong
#
supplychain
#
ai
Comments
Add Comment
7 min read
Your coding agent installed 23 packages in a minute. Your SBOM saw zero.
Jason Miller
Jason Miller
Jason Miller
Follow
Sep 19
Your coding agent installed 23 packages in a minute. Your SBOM saw zero.
#
supplychain
#
aiagents
Comments
Add Comment
3 min read
Your Coding Agent Reads the Repository Before You Do: Configuration Injection in AI Developer Tooling
jeffrey
jeffrey
jeffrey
Follow
Sep 17
Your Coding Agent Reads the Repository Before You Do: Configuration Injection in AI Developer Tooling
#
aisecurity
#
supplychain
#
developertooling
#
appsec
Comments
Add Comment
3 min read
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
We're a place where coders share, stay up-to-date and grow their careers.
Log in
Create account