skip to content
astropod
sign in
news
Product news and updates from the Gastropod team.
tagged
software-supply-chain-security ×
ApostropheCMS's Critical Auth Bypass
2026-08-01 15:02:47 · Chris
vulnerability-intelligence
software-supply-chain-security
npm
+3
node-js
prototype-pollution
transitive-dependencies
No Login Required: TeamCity's Critical RCE and Your Build
2026-08-01 14:21:36 · Chris
vulnerability-intelligence
software-supply-chain-security
ci-cd-security
+3
remote-code-execution
teamcity
jetbrains
PyPI and GitHub Are Racing Against Time for Package Poisoning
2026-07-29 03:15:57 · Chris
software-supply-chain-security
vulnerability-intelligence
pypi
+3
python
package-poisoning
provenance
fastjson 1.x CVE-2026-16723 - yikes!
2026-07-25 17:22:44 · last edited 2026-07-25 17:27:19 · Chris
vulnerability-intelligence
software-supply-chain-security
maven
+3
java
remote-code-execution
deserialization
Langflow's Fifth CIS-KEV CVE in a year
2026-07-25 02:48:46 · Chris
vulnerability-intelligence
software-supply-chain-security
ci-cd-security
Borrowed Compute: How Ten Packagist Libraries Turned GitHub Actions Into an Attack Botnet
2026-07-24 02:49:49 · Chris
vulnerability-intelligence
software-supply-chain-security
composer
+3
github-actions
ci-cd-security
sbom
What the OpenAI/Hugging Face Breach Says About SBOM Blind Spots
2026-07-23 03:58:10 · Chris
vulnerability-intelligence
software-supply-chain-security
sbom
+2
ai-security
provenance
FakeGit: 7,600 Repos, 14 Million Downloads, and an AI Agent Reading the Attacker's README
2026-07-23 03:31:22 · Chris
agentbaiting
software-supply-chain-security
vulnerability-intelligence
+3
github
ai-agents
mcp
ViteVenom: expansion of the ChainVeil campaign
2026-07-21 19:01:22 · last edited 2026-07-21 19:02:29 · Chris
vulnerability-intelligence
sbom
software-supply-chain-security
+3
npm
crypto
credential-theft
Eleven Bytes, No CVE: The OpenSSL HollowByte Flaw That Scanners Miss
2026-07-21 01:02:58 · Chris
vulnerability-intelligence
software-supply-chain-security
openssl
+3
denial-of-service
tls
sbom
Inside the Injective SDK Wallet-Key Theft
2026-07-17 12:49:28 · Chris
vulnerability-intelligence
software-supply-chain-security
npm
+2
credential-theft
crypto
Asyncapi NPM Supply Chain Attack
2026-07-16 22:24:44 · Chris
vulnerability-intelligence
software-supply-chain-security
npm
+2
github-actions
provenance
The npm Package That Only Turned Evil When You Used It
2026-07-16 02:10:15 · Chris
vulnerability-intelligence
software-supply-chain-security
npm
+2
credential-theft
crypto
Braintree.net nuget Typosquat
2026-07-16 01:26:03 · Chris
vulnerability-intelligence
software-supply-chain-security
nuget
+3
net
typosquatting
payment-fraud
Laravel lang tag rewrite supply chain attack
2026-07-16 01:12:30 · Chris
vulnerability-intelligence
software-supply-chain-security
composer
+3
packagist
php
credential-theft
Paysafe/Skrill/Neteller fake SDK/Typosquat Campaign
2026-07-16 01:00:10 · last edited 2026-07-16 01:33:25 · Chris
vulnerability-intelligence
software-supply-chain-security
npm
+3
pypi
typosquatting
credential-theft
The jscrambler npm Compromise
2026-07-16 00:48:52 · Chris
vulnerability-intelligence
software-supply-chain-security
npm
+2
credential-theft
dependency-management
Inside the AsyncAPI "Miasma" Attack: When the Pipeline Itself Becomes the Attacker
2026-07-16 00:34:52 · Chris
vulnerability-intelligence
software-supply-chain-security
supply-chain-attack
+3
npm
ci-cd-security
github-actions