en
JetBrains Marketplace AI Key Theft — 15 Malicious Plugins, 70K Installs, TLS Bypass
Security breakdown of 15 malicious JetBrains IDE plugins stealing OpenAI, Anthropic, and AWS API keys from 70,000 developers.
en
Security breakdown of 15 malicious JetBrains IDE plugins stealing OpenAI, Anthropic, and AWS API keys from 70,000 developers.
en
Weekly briefing: Oracle PeopleSoft zero-day exploited by ShinyHunters, Chrome V8 in-browser RCE, and TanStack Mini Shai-Hulud worm.
en
How threat actor TeamPCP deployed the Mini Shai-Hulud worm to poison TanStack packages and compromise developer build environments.
en
Full forensic analysis of the TeamPCP campaign: tag poisoning and entrypoint backdoors injected into Trivy, KICS, and Bitwarden CLI.
en
Weekly briefing: Megalodon backdoors 5,500 GitHub repos, Ghost CMS SQLi hijacks 700 sites for ClickFix, and MiniPlasma Windows 0-day.
en
How campaign Megalodon weaponized infostealer-harvested developer secrets to backdoor 5,561 GitHub repositories in automated CI runs.
en
Weekly briefing: Microsoft Exchange OWA zero-day XSS, TeamPCP GitHub breach (3.8K repos), Cisco SD-WAN UAT-8616, and Defender zero-days.
en
Investigation into how TeamPCP used a poisoned VS Code Marketplace extension to pivot into developer workstations and exfiltrate 3,800 GitHub repositories.
en
How the Mini Shai-Hulud attack poisoned TanStack npm packages and bypassed SLSA Level 3 build provenance guarantees.
Security Roundup
Weekly briefing: PAN-OS auth portal buffer overflow (root RCE), RubyGems 500+ malicious packages, and SHADOW-EARTH-053 espionage.
Supply Chain
How campaign BufferZoneCorp flooded RubyGems with over 500 malicious packages using typosquatting and GemStuffer payload obfuscation.
guides
A complete architecture and deployment guide for OWASP Dependency-Track using Docker Compose, FluxCD, and ArgoCD.