
.avif)
News

Good riddance, TeamPCP. Now for the hard part.
The AFP, FBI, and WA Police charged two men allegedly behind TeamPCP. Charlie Eriksen on why the arrest doesn't close the gap TeamPCP exposed.
Good riddance, TeamPCP. Now for the hard part.
The AFP, FBI, and WA Police charged two men allegedly behind TeamPCP. Charlie Eriksen on why the arrest doesn't close the gap TeamPCP exposed.
Software supply chain security requires decisions rather than defaults
Most software runs on decisions nobody made. We talk about why gating, pinning, backporting, and SBOM upkeep only work if someone actually owns them.
Shai-Hulud was the best thing to happen to supply chain security
npm Trusted Publishing sat near-idle after it was released. Then Shai-Hulud and 14 more supply chain attacks pushed adoption 3.4x. Charlie looks at the data behind it.
From Hugging Face to Fable: this summer shows AI control matters more than trust
An autonomous AI breach at Hugging Face and Anthropic's Fable suspension show the same thing: trusting a vendor isn't the same as being in control
What is AI harness engineering?
Harness engineering is the code around an AI model that turns it into an agent. What a harness does, why it beats picking a model, and how to build one.
Who was behind the attack? Possibly nobody
Three summer disclosures documented AI agents attacking real organizations with no human intent in the chain. Incident response has no box for this yet.
Four incident-response decisions from the Hugging Face breach
Recon, stolen credentials, hidden C2, and rebuild-or-patch. Four Hugging Face breach decisions that show whether you can catch an attack in progress.
Better generic secrets detection starts with finding non-secrets
Some API keys are meant to be public. Betterleaks now removes them from generic secret findings, dropping thousands of false positives per scan.
SQL injection isn't dead
The fix for SQL injection is decades old and still works. So why did WordPress core just need an emergency patch for one? The data, and how to defend against it.
The upgrade trap: when upgrading is the wrong answer to a CVE
Upgrading to fix a CVE sounds straightforward. But the patched version often breaks your app, hasn't shipped yet, or doesn't exist. Here's why, and what actually works.
Get secure now
Secure your code, cloud, and runtime in one central system.
Find and fix vulnerabilities fast automatically.


.png)
.png)