skip to content
astropod
sign in
news
Product news and updates from the Gastropod team.
tagged
sbom ×
Borrowed Compute: How Ten Packagist Libraries Turned GitHub Actions Into an Attack Botnet
2026-07-24 02:49:49 · Chris
vulnerability-intelligence
software-supply-chain-security
composer
+3
github-actions
ci-cd-security
sbom
What the OpenAI/Hugging Face Breach Says About SBOM Blind Spots
2026-07-23 03:58:10 · Chris
vulnerability-intelligence
software-supply-chain-security
sbom
+2
ai-security
provenance
ViteVenom: expansion of the ChainVeil campaign
2026-07-21 19:01:22 · last edited 2026-07-21 19:02:29 · Chris
vulnerability-intelligence
sbom
software-supply-chain-security
+3
npm
crypto
credential-theft
Eleven Bytes, No CVE: The OpenSSL HollowByte Flaw That Scanners Miss
2026-07-21 01:02:58 · Chris
vulnerability-intelligence
software-supply-chain-security
openssl
+3
denial-of-service
tls
sbom