Search/chainguard
Vendor

chainguard

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
malcontent
Connections
28 relationships
Exclusive: Linux Foundation's Akrites to Go Live in September
A major industry coalition set up to defend critical open-source software against AI-enabled cyber threats is expected to operationalize its vulnerability disclosure and remediation platform in September, Infosecurity has learned. The initiative, called Akrites, was launched at the end of June 2026 by the Linux Foundation, the Open Source Security Foundation (OpenSSF) and over 20 founding members. These include AI frontier labs Anthropic and OpenAI; cloud and tech giants like Amazon Web Services, Cisco, Google, Microsoft and its subsidiary GitHub, IBM and its subsidiary Red Hat and NVIDIA; cybersecurity firms like Chainguard, Endor Labs and Zscaler; and large enterprises, such as Citi, JPMorganChase, Ericsson and Vodafone. Each member of the coalition must donate between one and 10 engineers to the project and pay membership fees based on which of the three membership tiers they chose – Associate, General and Premier –, each corresponding to a level of benefits. At launch, the Linux Foundation announced two major missions for the initiative: Establish a shared security incident response team (SIRT) for mitigating and remediating vulnerabilities in open-source packages and libraries Develop a standardized coordinated vulnerability disclosure (CVD) process, built on confidentiality-first principles and industry-standard tooling Infosecurity spoke to Christopher ‘CRob’ Robinson, OpenSSF’s CTO and chief security architect, who was appointed as CTO of Akrites in June. He described Akrites’ sole mission as “coordinating AI-enabled vulnerability reports to upstream open-source maintainers so that the fixes are available to the whole ecosystem.” He said the team responsible for the initiative’s tooling, including the vulnerability management and SIRT platform, had now produced “the first draft of the tool chain.” He revealed that the initiative’s main platform will be based on Carnegie Mellon University's Vulnerability Information and Coordination Environment (VINCE), a vulnerability management platform developed in 2020 by the Computer Emergency and Response Team Coordination Center (CERT/CC), a unit of the university’s Software Engineering Institute (SEI). “We have a substantial amount of additional capabilities leveraging large language models (LLMs) to do deduplication, patch creation and more,” added the Akrites CTO, who confessed he’s already received thousands of vulnerability reports after two months of launching the project, an estimated 30% of these are duplicates. “Today, we’re bringing in some additional experts from the Akrites members to go through and do a penetration test and a security audit and then we’ll be augmenting the tools to allow the input of a combination of real and synthetic data through the system to make sure it functions as we design,” Robinson explained. When ready, the finished platform will be open-sourced and available for anyone to use for their own purposes. Additionally, Robinson said the Akrites-run platform is expected to “go live” and “start taking automated vulnerability reports” some time in September. “I have been trying to do something like Akrites my whole career,” he said. “I feel right now we have the tools, the willpower and access to the technical experts, so I’m very optimistic on our chances that we’re going to be able to provide a very valuable service to the global open-source ecosystem.” Stay tuned to Infosecurity for further updates on Akrites and similar initiatives to tackle the explosion of AI-enabled vulnerability reports in open-source projects. Image credits: Linux Foundation / IB Photography / Shutterstock.com
infosecurity-magazine.comAug 19, 2026extracted
Security Hub Extended adds Supply Chain Security as its tenth category
Since February, we’ve grown AWS Security Hub Extended from 14 curated partners across 9 categories to 23 partners across 10. At Black Hat this month, 14 of those partners were at the Amazon Web Services (AWS) booth demoing live. Four of those partners delivered theater talks and ten were featured on SecurityLive streaming. We hosted a partner reception that brought our leadership together with partner executives to plan what comes next. These are companies investing real engineering and real go-to-market (GTM) alongside us, and increasingly with each other, because the model resonates with the customers they’re talking to every day. The most common question we heard at the booth was when Supply Chain Security was coming. It’s here. And that’s the thing I want to spend the most time on today, because it’s the category customers keep asking us about. Supply Chain Security: The category customers have been asking for Software supply chain risk has moved from a security-team concern to a board-level conversation. SolarWinds showed what happens when a build system is compromised. Log4j showed what a single transitive dependency vulnerability can do at global scale. The xz utils backdoor showed the patience of a maintainer-compromise attack executed over years. Each demonstrated a different dimension of the same problem, and the pace is accelerating. Attackers know that a fast way into an enterprise is through the open source packages that enterprise unknowingly trust. Every customer I talked to at Black Hat had this on their risk register. Most still hadn’t operationalized a solution, because doing so meant a standalone deployment, a new contract, a new console, and integration work their security team couldn’t prioritize. That’s the friction we aim to remove. Security Hub Extended now offers Supply Chain Security with Chainguard and Socket as the curated partners. Supply Chain Security uses the same model as everything else in Extended. Every offering has pay-as-you-go pricing, one bill, no required long-term commitment. For enterprises that prefer to continue using the procurement process they always have, Security Hub Extended Private Offers are also available. These are committed term agreements with deeper discounts, the ability to aggregate spend across partners on a single AWS bill, and both monthly and annual payment options throughout the term. You pick the path that fits how you buy. What Chainguard does Chainguard gives you open source dependencies rebuilt from source in a hardened, verified build process, so what enters your environment is malware-resistant and provenance-backed. Their research shows that rebuilding from source would have stopped 98% of known malicious packages from ever reaching production. If you can’t verify the source, it never appears in the Chainguard repository. That’s the filter between the public registry and your developers. What Socket does Socket analyzes the actual behavior of open source packages to block malicious dependencies at the time of install. Not after a Common Vulnerability and Exposures (CVE) is published days or weeks later. At the moment the package tries to land in your environment, Socket flags it based on what it does, not what a database says about it. Its reachability analysis then tells you which vulnerabilities are exploitable from your code instead of drowning your team in noise. You pay for the distinct packages you check, not for how often your builds run. Why they work together Together, Chainguard and Socket cover the two questions that matter: Can I trust what I’m pulling in? Can I stop malicious components before they get built into my applications? Chainguard helps secure the foundation your code is built on. Socket secures the packages you pull into it. Both help protect your software supply chain regardless of where you deploy—across clouds or on-premises. Activate both through Security Hub Extended and their findings flow into Security Hub in OCSF (Open Cybersecurity Schema Framework) alongside everything else, so a supply chain risk is correlated and prioritized next to your endpoint, identity, and cloud signals. From there, it routes out to the downstream tools you’ve already integrated, so it fits the pipeline your builders run today. 23 partners, 10 categories. Built on what customers asked for Every partner in Security Hub Extended is here because customers told us they needed that capability and that specific solution was already working for them. We add categories because the threat landscape evolves, and we add partners because customers point us to who’s solving those problems well. The goal is straightforward: Simplify adopting the security solutions your peers are already succeeding with, through the AWS relationship you already have. The full set today spans endpoint, identity, email, network, data, browser, cloud, AI, security operations, and now supply chain. The 23 curated partners are 7AI, Britive, Chainguard, CrowdStrike, Cyera, Island, LayerX, Native Security, Noma, Okta, Oligo, Opti, Palo Alto Networks, Proofpoint, SailPoint, SentinelOne, Socket, Splunk, Sublime, Upwind, Varonis, Zenity, and Zscaler. Our focus now is deepening integrations and reducing activation friction so these solutions work together, not in isolation. That’s where the real value compounds. What we’re building next Everything I’ve described so far is the commercial model working: Customers buying best-of-breed security through one AWS relationship with the flexibility they expect. But the bigger vision is the integration layer that makes these tools genuinely better together, not just easier to buy together. The integration we’re most focused on is cross-partner correlation, turning signals from an endpoint solution, an identity solution, and a cloud solution into one exposure and one attack path instead of three disconnected alerts. Right alongside that, we’re dramatically reducing the activation, deployment, and integration friction so customers go from subscribing to seeing value in hours rather than weeks. Both efforts enable the curated solutions you already trust to deliver stronger outcomes together than they do apart. That’s the build we’re accelerating with our partners now, and you’ll hear more leading into re:Invent. Explore what’s available If you’re running open source in production and don’t yet have supply chain visibility, start there. Activate Chainguard and Socket through the Security Hub console today. If you’re managing multiple security vendor relationships and want to understand what consolidation looks like with Security Hub Extended, talk to your AWS account team. Pricing for every partner is published on our pricing page , no sales call required. And if you’re already using Security Hub for posture management and threat detection, the Extended plan is available in the same console you already use. We’re just getting started. If you have feedback about this post, submit comments in the Comments section below. Michael Fuller Michael has been with AWS for 16 years and led product for AWS Security Services for 11 years. Michael has 29 years in the industry and held several roles in product management, business development, and software development for IBM, Cisco, and Amazon. Michael has a Bachelor’s of Science in Computer Engineering from the University of Arizona and an MBA from the University of Washington.
aws.amazon.comAug 18, 2026extracted
Week in review: 74k Fortinet firewall credentials stolen, Splunk Enterprise RCE under active attack
Week in review: 74k Fortinet firewall credentials stolen, Splunk Enterprise RCE under active attack Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: A hardware neural network backdoor that hides in plain sight Deep learning systems on edge devices often rely on third-party-designed FPGAs and ASICs for performance and efficiency, creating supply chain risks. Researchers from the University of Tennessee and the University of Florida developed HAMLOCK, a backdoor attack that splits malicious functionality between hardware and software, making detection more difficult. Onspring CISO on where automated GRC systems fall short In this interview with Help Net Security, Nichole Windholz, CISO at Onspring, talks about the limits of automated GRC systems and continuous control monitoring. She explains why color-coded dashboards can hide nuance, how teams can check the data feeding their tools, and which risks resist measurement, such as insider behavior and vendor concentration. AI vulnerability discovery is pushing 2026 CVEs toward 66,000 Vulnerability disclosures are piling up faster in 2026 than anyone expected at the start of the year. The running count for the first few months sits well above the original projection, and the Forum of Incident Response and Security Teams (FIRST) now expects the year to land near 66,000 CVEs. Reachability makes AI threat modeling worth the trust In this interview with Help Net Security, Oscar Andersson, CTO at Oplane, explains why most scanning tools fail. They cry wolf, flagging threats that cannot run in real code. The argument centers on reachability. A finding counts only when someone walks the path to impact on a working build. The SOC’s visibility gap comes down to staffing AI has settled into security operations centers faster than any earlier wave of technology. Around four in five practitioners report reaching for AI or machine learning tools in their daily work. The catch shows up one layer down. Roughly a third of those same teams have built these tools into a defined workflow with structure, governance, and consistent validation. The rest pick up AI on their own, case by case, with no shared playbook for how it gets used or checked. The Chainguard Athena coalition already shipped 2,000 patches across 500 open source projects Chainguard launched Athena, an industry coalition that pools open source vulnerability findings and remediates them under embargo before public disclosure. The group went live with more than two dozen member organizations. Founding members include BNY, Chainguard, Cisco, Cloudflare, Corridor, DepthFirst, Docker, JPMorganChase, Kyndryl, LTIMindtree, and PwC. What happens to oversight when AI agents write a lab’s own code Inside the labs building frontier AI, a growing share of the coding gets done by the AI itself. These agents write, edit, and run software with light human oversight between steps, and they reach into production infrastructure, research pipelines, and potentially the systems that train and evaluate future models. Securing digital keys when your phone unlocks the car In this interview with Help Net Security, Alysia Johnson, President of the Car Connectivity Consortium (CCC), explains how the CCC Digital Key has grown from a single-brand feature into a standard meant to work across phones, automakers, and suppliers. Your browser tab could become encrypted storage for someone else’s files Decentralized storage networks already hand pieces of people’s data to strangers’ machines. The lasting question across these networks is whether the machine holding the data can read it. A research paper by Gregory Magarshak, a professor at IENYC, describes a system called Safecloud built on one design rule: the nodes that store data see only ciphertext, and the nodes that route data hold no keys. PhishLumos: Exposing phishing campaigns that evade detection by hiding content Phishing remains one of the most stubbornly persistent threats in cybersecurity: humans are tired, distracted, trusting, and susceptible to urgency and authority in ways that no amount of awareness training can completely overcome. The security community has largely accepted this reality and shifted focus toward automated detection systems that can intercept and block phishing threats before users see them. China-linked spies backdoored authentication stack to stay hidden for years A China-linked cyber espionage group known as Velvet Ant spent nearly a decade inside the internal network of an unnamed organization without being detected, according to the results of a forensic investigation published by cybersecurity firm Sygnia. Cisco discloses second exploited SD-WAN vulnerability in two weeks (CVE-2026-20262) Cisco has revealed another Catalyst SD-WAN Manager vulnerability (CVE-2026-20262) that its Product Security Incident Response Team observed being exploited by attackers. But the associated security advisory also states that “the vulnerability was found during internal security testing”, raising the question of how attackers came to exploit it before Cisco had disclosed it publicly. SimpleHelp RMM flaw could give attackers full access to managed endpoints (CVE-2026-48558) A critical vulnerability (CVE-2026-48558) in SimpleHelp, a popular remote monitoring and management (RMM) tool, can be exploited remotely by unauthenticated attackers to create a new “Technician” account and use it to remote into managed endpoints, execute scripts, and more. Attackers are exploiting FortiSandbox vulnerabilities Attackers have been spotted exploiting three vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) in FortiSandbox, a platform that other Fortinet security products depend on for threat verdicts to enforce blocking decisions and trigger automated responses. The warning came on Monday from threat intelligence company Defused, which said that the exploit for one of the flaws is vibecoded, and likely faulty. Microsoft working on patch for RoguePlanet Defender zero-day (CVE-2026-50656) Microsoft has acknowledged the local elevation of privilege issue in Microsoft Defender that can be triggered via the “RoguePlanet” exploit, and is “working to provide a high quality security update that addresses this vulnerability.” The vulnerability, which has been assigned the CVE-2026-50656 identifier, stems from improper link resolution before file access, and can be exploited in low complexity attacks by authenticated attackers, with no user interaction required. Low-skilled attacker used Claude, Codex to breach 14 companies Researchers have long warned that AI agents could lower the skill floor for offensive cyber operations, and a recent report by OALABS (Open Analysis) researchers bears that out. After recovering and analyzing over 1,000 agent sessions from a compromised server on which an attacker deployed Anthropic’s Claude Code and OpenAI’s Codex agents, the researchers discovered how easily the attacker was able to bypass most of the agents’ guardrails, and how little he actually needed to know and do himself. 74,000 Fortinet firewall credentials exposed in FortiBleed data leak A Russian-speaking cybercriminal group has stolen credentials contained in the configuration files of nearly 74,000 Fortinet firewalls and VPN gateways around the world. The data was accidentally exposed by the group on a server, along with other artifacts and tools, and the exposure was noticed by security researcher Volodymyr “Bob” Diachenko. Law enforcement hits SocGholish: 106 servers down, 15,000 sites cleaned SocGholish, an operation that’s been delivering malware to users via fake software updates, has suffered a major blow: the international law enforcement coalition behind Operation Endgame has taken down 106 of its servers and domains, and cleaned up nearly 15,000 websites compromised to serve their malicious payloads. The result of this most recent multinational law enforcement action was announced today by the Dutch National Police and on the operation’s website. Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253) CISA has added CVE-2026-20253, a critical, remotely exploitable vulnerability in Splunk Enterprise, to its Known Exploited Vulnerabilities catalog, and ordered US federal civilian agencies to apply mitigations by June 21, 2026. EU Cybersecurity Act 2.0: When good regulation goes bad Over recent years we’ve witnessed the EU becoming increasingly serious about cybersecurity. After years of watching high profile breaches, many resulting from supply chain attacks targeting our critical infrastructure, that seriousness is welcome. But good intentions and good policy are not the same thing, and the proposed EU Cybersecurity Act 2.0 is starting to look a lot more like the former than the latter. Navigating SEC, NIS2, and DORA incident disclosure timelines under pressure In this Help Net Security video, Rick Goud, Global Field CTO at Kiteworks, discusses how to handle SEC, NIS2, and DORA disclosure timelines during a security incident. Proving what a military AI model will do is the real problem Defense contractors build AI systems that task drones automatically and propose kill-chains to support soldiers. Several of these contractors have partnered with frontier AI companies to put advanced models into military tools. The systems coming out of these partnerships carry a security problem that sits outside the methods of arms control diplomacy: confirming what an AI model will do. Open-source CI/CD abuse detector guards against stolen credential attacks CI/CD Abuse Detector is an open-source project that uses a large language model to flag suspicious changes to continuous integration and continuous deployment pipelines, workflows, and automation configurations. The repository contains drop-in templates for GitHub Actions, GitLab CI, and Azure DevOps. Ukrainian national pleads guilty in connection with Conti ransomware A Ukrainian national pleaded guilty to conspiracy to commit wire fraud in connection with the deployment of Conti ransomware, which targeted more than 1,000 victims worldwide. Chinese hackers breached North American research institutions via REDCap servers A China-linked cyber espionage operation targeted North American medical research institutions through compromised REDCap servers, using custom malware to gain persistent access and collect sensitive information, Google’s Threat Intelligence Group (GTIG) researchers found. Planning a trip? Fake travel sites are multiplying this summer Cyberattacks against hospitality, travel, and recreation organizations rose 24% year over year, reaching an average of 2,291 incidents per organization each week in May 2026, according to Check Point. Crypto scammers are sending couriers to victims’ homes to collect cash Scammers behind cryptocurrency investment schemes are dispatching couriers to pick up cash from victims in person, the FBI warns. According to the agency, scammers usually approach victims through social media, text messages, or fake investment personas, luring them into cryptocurrency schemes that use fraudulent trading platforms and fabricated returns to encourage additional deposits. Cybercriminals mask malicious communications through Microsoft Teams relays The DragonForce ransomware group used a custom malware called Backdoor.Turn to hide command-and-control traffic inside Microsoft Teams relay infrastructure during an intrusion at a U.S. services company, according to Symantec. Apple is bringing Hide My Email and Sign in with Apple under one domain Apple will unify the email domains used by Sign in with Apple and iCloud+ Hide My Email under a shared domain, private.icloud.com, later this summer. Hide My Email is a service included with iCloud+, Apple’s subscription service. It allows users to generate one-time-use or reusable email addresses that forward messages to their personal inbox without revealing their actual email address. Rokarolla Android trojan targets banking and crypto users, enables device takeover A newly discovered Android banking trojan, dubbed Rokarolla, targets 217 banking and cryptocurrency applications and can execute 137 commands on infected devices, according to researchers at Zimperium. Named after its command-and-control (C2) infrastructure, Rokarolla is primarily distributed through malicious websites that impersonate popular applications such as TikTok and Google Chrome, fooling users into downloading what appears to be a legitimate app. Another healthcare firm attacked days after Novo Nordisk breach Medical technology company iRhythm Holdings disclosed a cyberattack involving certain third-party-hosted business applications that resulted in the theft of patient protected health information, proprietary data, and other personal data. The company discovered unauthorized activity on June 8, 2026, and launched an investigation with the assistance of external cybersecurity experts. AWS Continuum brings AI models to code vulnerability management AWS Continuum for code vulnerabilities, a system built to handle a vulnerability across its lifecycle, from discovery through to a fix, is now available in gated preview. It reasons over a customer’s environment, confirms which findings are real, and works toward resolution. It is model agnostic and draws on multiple frontier models, assigning each to the work where it performs best. AWS designed it to take in newer models as they become available. Malware attacks strip Roblox developers of entire games Hackers who once focused on stealing valuable Roblox items are now taking over entire games. Although Roblox operates the service, users can create and publish their own games on it. Successful games can generate substantial revenue through in-game purchases. Some developers have earned millions of dollars and built dedicated studios around their creations. Klue breach lead to Salesforce data theft, Huntress affected Cybersecurity vendor Huntress was among multiple companies hit by a breach originating at Klue, a market intelligence platform used to integrate CRM and sales data across various business tools. Senior engineers are spending their week cleaning up AI-generated code At most U.S. technology companies, machines now write the bulk of the code that ships each week. The engineer’s job has shifted toward reviewing what the AI produces, and that review gives the code high marks. Leaders rate AI-generated code as higher quality than the code their own people write, praising its clean structure, consistent style, and low count of obvious bugs at submission time. Microsoft’s workplace check-in via Wi-Fi tracks who’s in the office, and not everyone’s happy Microsoft is rolling out workplace check-in via Wi-Fi for Teams and Microsoft Places. Connect to your office network and your in-office presence updates automatically, no manual status change needed. A $2 trillion revenue shift hinges on AI data governance Across large enterprises, a single question keeps surfacing when teams want to put customer data to work. Can this record be used for a given purpose, and does the consent behind it still hold? The data sits in warehouses and customer databases, and the ability to answer that question often lags behind. That delay carries a cost. GitHub releases an open dataset for multilingual developer content Developers coordinate code across README files, issue threads, and pull request discussions. Much of that exchange happens in English, and a large share happens in other languages. GitHub has released a dataset built to help researchers and developers locate public repositories that carry non-English natural-language content. Software supply chains are heading for a transparency test Software supply chain visibility is becoming part of product security work as the EU Cyber Resilience Act (CRA) moves toward application in December 2027. ENISA’s SBOM Adoption State of Play 2026 shows organizations preparing for CRA obligations through SBOM tooling, automation, and changes to software development practices. The checklist problem behind critical infrastructure cyber safety An asset owner can meet major federal cyber compliance standards and still run equipment that lacks the engineering to withstand an attack or a failure. New research from George Mason University examines how United States cyber policy defines reasonable care for systems that control physical processes, and it finds that compliance has become a stand-in for safety. Product showcase: From phishing texts to risky Wi-Fi, Norton 360 Deluxe watches the gaps Norton 360 Deluxe combines device security, scam detection, web protection, and VPN privacy in a single subscription that covers up to five devices. It is available for Windows, macOS, Android, and iOS. Microsoft AntiSSRF open-source library helps block server-side request forgery AntiSSRF is an open-source code library from Microsoft that validates URLs and network connections to reduce server-side request forgery (SSRF) risks in web applications. It supports .NET and Node.js applications and is distributed under the MIT license. The library works as a drop-in component, giving developers a way to check untrusted input before their applications make outbound requests. Ukraine can now tap EU cyber support during major attacks Ukraine can now call on emergency cyber support from the European Union during large-scale cybersecurity incidents. The move follows a decision by the Council of the European Union to add the country to the EU Cybersecurity Reserve. What’s new in Android 17? Anti-theft tools, scam detection, and parental controls The Android 17 rollout has started for supported Pixel devices, delivering new security and privacy capabilities before expanding to other devices later this year. Most agentic AI projects in production have stalled over data problems Enterprises are connecting AI agents to live data feeds and putting them to work on tasks that once required human review, from IT operations to software development. The number doing this in production reached 32 percent in 2026, up from 29 percent the year before, according to Confluent’s annual Data Streaming Report, which surveyed 4,625 IT leaders across 14 countries. Homebrew tightens tap security, begins work on its interface Anyone who installs software through a third-party Homebrew tap runs Ruby code written by people outside the project, and that code runs without a sandbox. That risk sits at the center of Homebrew 6.0.0. It now requires a tap, along with any tap-qualified formula or cask, to be trusted before its code is evaluated or run. Google’s open standard for AI agents to discover and verify tools AI agents rely on tools, services, and other agents distributed across different teams, organizations, and platforms. Because these resources are often isolated in separate systems, agents have limited ability to discover and connect to capabilities outside their own environment. Google aims to solve this with Agentic Resource Discovery, an open specification for publishing, discovering, and verifying AI capabilities across the web, regardless of framework, protocol, or provider. GentleKiller targets more than 400 security processes across 48 products Most ransomware operations leave the work of disabling endpoint security software to their affiliates. The ransomware-as-a-service gang Gentlemen runs a different model. Its operators develop and maintain a set of tools for shutting down endpoint detection and response (EDR) products, then provide these tools directly to the affiliates who rent the gang’s encryptors. Asia-Pacific scam networks generate nearly $40 billion a year Cybercrime is taking a larger share of criminal activity in Asia and the Pacific. More than half of surveyed jurisdictions reported that cybercrime accounts for over 30% of all crimes recorded nationally, according to INTERPOL’s 2025/2026 Asia and South Pacific Cyberthreat Assessment Report. Companies are discarding the logs they need to catch a breach Many large enterprises discard most of the log data their systems generate, and they do it on purpose to keep costs down. A Dynatrace survey of 450 senior IT leaders at large enterprises found that half of organizations drop or never collect an average of 86 percent of their logs, even after filtering and aggregation. Many also limit how long they retain the logs they do keep. The rise of machine identities and agentic AI: Securing trust in the next era of digital autonomy For years, identity security has been centered on humans, ensuring that the right person has the right level of access to the right resources. But now, the same principle applies to non-human entities: machines, APIs, bots, and increasingly, AI agents. These new “digital actors” authenticate, access sensitive information, execute workflows, and even make decisions, often faster and at greater scale than any human ever could. How security teams are getting credential visibility into developer endpoints Attackers increasingly target developer machines to steal credentials. Recent supply chain attacks, including Megalodon, TrapDoor, and Miasma, focused on compromising developer environments where secrets often reside in shell histories, .env files, cloud CLI configs, local caches, and AI agent directories. To address this risk, GitGuardian has introduced Developer Endpoint Protection in ggshield, enabling organizations to discover credentials on developer workstations. Google sets timeline for Android developer verification enforcement Android’s developer verification protections will take effect on September 30, 2026, starting with users in Brazil, Indonesia, Singapore, and Thailand. Developers distributing apps through participating stores in those markets must complete the verification process by the deadline. Mastodon 4.6 adds profile Collections and two-factor controls People who run accounts on the open source social network Mastodon can now group profiles together and share those groups across the web. The 4.6 release centers on a feature called Collections, along with reworked profiles, email newsletters, server administration controls, and a set of accessibility changes. Forget traffic lights, Google’s reCAPTCHA may ask for hand gestures Google has introduced hand gesture verification for reCAPTCHA, a new method for verifying that a user is human. Google’s reCAPTCHA is part of Google Cloud Fraud Defense, a fraud and abuse prevention platform for bot, account, and transaction protection. It uses risk analysis and challenge-based verification to help organizations identify automated activity and suspicious behavior. Cybersecurity jobs available right now: June 16, 2026 We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now. New infosec products of the week: June 19, 2026 Here’s a look at the most interesting products from the past week, featuring releases from ArmorCode, Barracuda Networks, Blue Planet, Flip, Fortinet, Legit Security, Tigera, and WitnessAI.
helpnetsecurity.comJun 21, 2026extracted
The Chainguard Athena coalition already shipped 2,000 patches across 500 open source projects
The Chainguard Athena coalition already shipped 2,000 patches across 500 open source projects Chainguard launched Athena, an industry coalition that pools open source vulnerability findings and remediates them under embargo before public disclosure. The group went live with more than two dozen member organizations. Founding members include BNY, Chainguard, Cisco, Cloudflare, Corridor, DepthFirst, Docker, JPMorganChase, Kyndryl, LTIMindtree, and PwC. Dan Lorenc, CEO of Chainguard, said no single company can get ahead of the threat alone and that orchestrated defense is the answer. In a comment on the launch, he said: “Athena is operational. More than 20,000 findings processed, 2,000 patches across 500 projects, first coordinated disclosures in about a month. Will it be perfect? No, and no one should pretend otherwise. But fragmentation is worse, standing still isn’t survivable, and the more of the industry that’s in, the less any attacker has left to find.” A faster vulnerability discovery cycle Athena targets a problem created by frontier AI models. These systems read code, reason across dependencies, and surface novel, chained zero-day vulnerabilities at machine speed, including flaws that survived decades of expert review. In one case, a critical bug sat in media-processing code used by many applications that automated fuzzers had run more than five million times without catching it. The gap between a vulnerability being discovered and being exploited has collapsed from years to hours, and a growing share of exploits are weaponized before the bug becomes public. The code underneath much of this software is often maintained by one or two volunteers already buried in low-quality scanner noise. Many of the coalition’s submitting members surface these vulnerabilities through frontier AI programs including Anthropic’s Project Glasswing and OpenAI’s Daybreak, and bring the resulting findings to Athena. The Athena pipeline Athena runs a shared platform that carries each vulnerability through its lifecycle from discovery to a durable upstream fix. Organizations submit pre-disclosure findings through an encrypted portal, and each submitter sets what is shared, with whom, and on what embargo timeline. Athena deduplicates and enriches each finding, traces when the flaw was introduced and whether it is already fixed at head, and publishes the metadata as an OSV feed. Members receive anonymized, aggregated intelligence across submitters and access to patched builds ahead of public disclosure. Before disclosure, private forks and rebuilt, hardened versions reach members through Chainguard Libraries. Findings get addressed in batches across an entire library, hardening it against whole classes of issues. Findings are reconciled against upstream activity throughout the embargo to keep fixes current. Athena stacks additional layers of protection. Partners that operate infrastructure, platform, network, and security layers push non-patch mitigations ahead of disclosure, including detection signatures, traffic-level rules, and platform-side blocks. Cybersecurity partners add their own detections, signatures, and virtual patching. The coalition drives coordinated disclosure upstream, and Athena acts as a maintainer of last resort for fixes that cannot reach the volunteer maintainers on their own. Chainguard hopes to work with the Linux Foundation on a coordinated Security Incident Response Team for open source. Protection for organizations that cannot patch quickly A large share of Athena’s work stays invisible by design. A patch only protects systems that can apply it, and much of the world’s critical infrastructure cannot patch on an attacker’s timeline. Athena’s platform-level mitigations aim to neutralize a vulnerability across the internet before public disclosure. The same open source libraries that run inside large technology companies also run inside municipal water systems and regional hospitals with little or no dedicated security staff. Those organizations gain protection without taking any action. Membership and availability Athena is open to vetted organizations through an application process. Members keep control of their findings, which they can hold private, share with a trusted subset of the coalition, or open to everyone. Organizations that join before the first coordinated disclosure wave next month are covered under embargo ahead of it. Must read: 25 open-source cybersecurity tools that don’t care about your budget GitHub CISO on security strategy and collaborating with the open-source community
helpnetsecurity.comJun 17, 2026extracted
Chainguard, JPMorgan, BNY Team Up to Secure Open Source from AI Threats
Open-source security firm Chainguard has brought together dozens of partners in a new industry coalition to protect open-source software from AI attacks. The initiative, called Athena, was announced by Chainguard on June 16. Its founding members include BNY, Chainguard, Cisco, Cloudflare, Corridor, DepthFirst, Docker, JPMorganChase, Kyndryl, LTIMindtree and PwC. Based on preliminary work at Chainguard, Athena provides a vulnerability intelligence sharing platform and tools to fix the vulnerabilities frontier AI models, like Anthropic’s Mythos and OpenAI’s GPT-5.5.-Cyber, find before attackers can exploit them. Here’s how Athena works, according to Chainguard’s CEO Dan Lorenc: Coalition members pool vulnerabilities affecting open-source projects they have discovered and packages into the Athena platform using frontier AI programs they have access to, including Anthropic's Project Glasswing and OpenAI's Daybreak Chainguard patches them privately and affected projects are rebuilt as private, hardened versions, available to members through Chainguard Libraries before disclosure Coalition members that operate infrastructure, platform, network and security layers push non-patch mitigations ahead of disclosure so that coverage exists even where a clean patch does not yet Cybersecurity partners add their own detections, signatures and virtual patching The Athena coalition drives coordinated upstream disclosure Additionally, Chainguard hopes to work with the Linux Foundation on a coordinated Security Incident Response Team (SIRT) for open source and a maintainer of last resort program. Announcing the project on LinkedIn, Lorenc said Athena allows for every vulnerability one member discovers to get remediated and pushed upstream, “becoming a fix the entire ecosystem inherits, often before disclosure.” “And for the parts of the world that can't patch on an attacker's timeline, partners who sit in front of much of the internet push mitigations out ahead of disclosure, blocking the issue for people who never knew there was anything to block,” he added. Chainguard also highlighted that the Athena model acts as “an AI cybersecurity clearinghouse” like the one the US government has been asked to build following the Trump Administration's latest Executive Order, Promoting Advanced Artifical Intelligence Innovation and Security, published on June 2. “It’s even more relevant since the US government declared Mythos too dangerous for public access on Friday,” the open-source security company added. Athena is operational and has already processed over 20,000 findings and shipped more than 2000 patches across 500 open-source projects. The initiative will begin publishing its first wave of disclosures in July and continues to welcome new partners. “Will it be perfect? No, and no one should pretend otherwise,” said Lorenc. “But fragmentation is worse, standing still isn't survivable, and the more of the industry that's in, the less any attacker has left to find. Join us.”
infosecurity-magazine.comJun 16, 2026extracted
175: Bayrob
It started with a fake car listing on eBay. What looked like a simple online scam quietly grew, over more than a decade, into one of the most sophisticated cybercrime operations the FBI had ever traced. Custom malware. Opsec off the charts. Fleets of infected computers mining cryptocurrency for someone else. Millions of dollars siphoned from victims who had no idea. This is the story of Bayrob and the three men from Romanian who were behind it. And the long, strange road that led American investigators to their door. Sponsors Support for this show comes from ThreatLocker® . ThreatLocker® is a Zero Trust Endpoint Protection Platform that strengthens your infrastructure from the ground up. With ThreatLocker® Allowlisting and Ringfencing™, you gain a more secure approach to blocking exploits of known and unknown vulnerabilities. ThreatLocker® provides Zero Trust control at the kernel level that enables you to allow everything you need and block everything else, including ransomware! Learn more at www.threatlocker.com . This show is sponsored by Meter , the company building networks from the ground up. Meter delivers a complete networking stack - wired, wireless, and cellular - in one solution that’s built for performance and scale. Alongside their partners, Meter designs the hardware, writes the firmware, builds the software, manages deployments, and runs support. Learn more at meter.com . This show is sponsored by Maze . Maze uses AI agents to triage and remediate cloud vulnerabilities by figuring out what’s actually exploitable, not just what’s theoretically risky. They remove the noise, prioritize vulns that matter, and manage remediation, so your team stops wasting time on meaningless vulns. Visit MazeHQ.com/darknet for more information. Support for this episode comes from NetSuite . NetSuite gives you visibility and control of your financials, planning, budgeting, and of course - inventory - so you can manage risk, get reliable forecasts, and improve margins. NetSuite helps you identify rising costs, automate your manual business processes, and see where to save money. KNOW your numbers. KNOW your business. And get to KNOW how NetSuite can be the source of truth for your entire company. Visit www.netsuite.com/darknet to learn more. This episode is sponsored by Chainguard . Chainguard builds container images the right way — minimal, hardened, and built from source every single day. We’re talking images with zero known CVEs, designed from the ground up for production. No bloat. No mystery packages. No 2 a.m. patching marathons because some transitive dependency lit up your dashboard. Stop patching images that are insecure. Start shipping clean. Head to chainguard.dev to see how secure your software supply chain can really be.
darknetdiaries.comJun 2, 2026extracted
⚡ Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and More
Some weeks are loud. This one was quieter but not in a good way. Long-running operations are finally hitting courtrooms, old attack methods are showing up in new places, and research that stopped being theoretical right around the time defenders stopped paying attention. There's a bit of everything this week. Persistence plays, legal wins, influence ops, and at least one thing that looks boring until you see what it connects to. All of it below. Let's go. ⚡ Threat of the Week Citrix Flaw Comes Under Active Exploitation — A critical security flaw in Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-3055, CVSS score: 9.3) has come under active exploitation as of March 27, 2026. The vulnerability refers to a case of insufficient input validation leading to memory overread, which an attacker could exploit to leak potentially sensitive information. Per Citrix, successful exploitation of the flaw hinges on the appliance being configured as a SAML Identity Provider (SAML IDP). Your Engineers Are Drowning in Tools — Here's the Data Chainguard surveyed 1,200 engineers and tech leaders for their 2026 Engineering Reality Report. AI is buying back time but also introducing new security concerns, while technical debt, tool sprawl, and burnout keep dragging teams down. 72% say time pressure blocks new feature work; 88% report productivity loss from too many tools. Get the Full Report ➝ 🔔 Top News FBI Confirms Hack of Director Kash Patel's Personal Email Account — The U.S. Federal Bureau of Investigation (FBI) confirmed that threat actors gained access to an email account belonging to FBI Director Kash Patel, but said no government information has been compromised. The Iran-linked hacker group Handala claimed responsibility for the hack, releasing files allegedly representing photos, emails, and classified documents taken from the FBI director's inbox. "The so-called 'impenetrable' systems of the FBI were brought to their knees within hours by our team," the hackers wrote. It's unclear when the account was hacked. The U.S. government, which recently took down multiple sites operated by Iranian state actors, said it's offering up to $10 million for information on threat groups like Parsian Afzar Rayan Borna and Handala. Parsian Afzar Rayan Borna is an IT company that's been implicated in Iran's disinformation and surveillance campaigns. The company is assessed to be linked to Banished Kitten, an Iran-nexus adversary active since at least 2008 and operates the Homeland Justice and Handala Hack personas. Red Menshen Uses Stealthy BPFDoor to Spy on Telecom Networks — A China-linked state-sponsored threat actor known as Red Menshen has deployed kernel implants and passive backdoors deep within telecommunication backbone infrastructure worldwide for long-term persistence. The implants have been fittingly described as sleeper cells that lie dormant and blend into target environments, but spring into action upon receiving a magic packet by quietly monitoring network traffic instead of opening a visible connection. Initial access is usually gained by exploiting known vulnerabilities in edge networking devices and VPN products or by leveraging compromised accounts. Once inside, the threat actor maintains long-term access by deploying tools like BPFdoor. Some BPFdoor samples mimic bare-metal infrastructure, posing as legitimate enterprise platforms to blend into operational noise. Others spoof core containerization components. By embedding the implant deep below traditional visibility layers, the goal is to significantly complicate detection efforts. Rapid7 has released a scanning script designed to detect known BPFDoor variants across Linux environments. GlassWorm Evolves to Drop Extension-Based Stealer — A new evolution of the GlassWorm campaign is delivering a multi-stage framework capable of comprehensive data theft and installing a remote access trojan (RAT), which deploys an information-stealing Google Chrome extension masquerading as an offline version of Google Docs. "It logs keystrokes, dumps cookies and session tokens, captures screenshots, and takes commands from a C2 server hidden in a Solana blockchain memo," Aikido said. GlassWorm is the moniker assigned to a persistent campaign that obtains an initial foothold through rogue packages published across npm, PyPI, GitHub, and the Open VSX marketplace. In addition, the operators are known to compromise the accounts of project maintainers to push poisoned updates. Russian Hacker Sentenced to 2 Years for TA551-Linked Ransomware Attacks — Ilya Angelov, a 40-year-old Russian national, was sentenced to two years in prison for managing a botnet that was used to launch ransomware attacks against U.S. companies. Angelov, who went by the online aliases "milan" and "okart," is said to have co-managed a Russia-based cybercriminal group known as TA551 (aka ATK236, G0127, Gold Cabin, Hive0106, Mario Kart, Monster Libra, Shathak, and UNC2420) between 2017 and 2021. The attacks leveraged spam emails to compromise systems and rope them into a botnet that other cybercriminals used to break into corporate systems and deploy ransomware. This included threat actors affiliated with BitPaymer and IcedID. FCC Bans New Foreign-Made Routers Over Security Risks — The U.S. Federal Communications Commission (FCC) said it was banning the import of new, foreign-made consumer routers, citing "unacceptable" risks to cyber and national security. To that end, all consumer-grade routers manufactured in foreign countries have been added to the Covered List, unless they have been granted a Conditional Approval by the Department of War (DoW) or the Department of Homeland Security (DHS) after determining that they do not pose any risks. The development comes as the Indian government appears to be preparing to bar Chinese CCTV product makers, such as Hikvision, Dahua, and TP-Link, from selling their cameras from April 1, 2026, to tighten oversight under the Standardisation Testing and Quality Certification (STQC) rules, the Economic Times reported. ️🔥 Trending CVEs New vulnerabilities show up every week, and the window between disclosure and exploitation keeps getting shorter. The flaws below are this week's most critical — high-severity, widely used software, or already drawing attention from the security community. Check these first, patch what applies, and don't wait on the ones marked urgent — CVE-2026-3055 (Citrix NetScaler ADC and NetScaler Gateway), CVE-2025-62843, CVE-2025-62844, CVE-2025-62845, CVE-2025-62846 (QNAP), CVE-2026-22898 (QNAP QVR Pro), CVE-2026-4673, CVE-2026-4677, CVE-2026-4674 (Google Chrome), CVE-2026-4404 (GoHarbor Harbor), CVE-2026-1995 (IDrive for Windows), CVE-2026-4681 (Windchill and FlexPLM), CVE-2025-15517, CVE-2025-15518, CVE-2025-15519, CVE-2025-15605, CVE-2025-62673 (TP-Link),CVE-2025-66176 (HikVision), CVE-2026-32647 (NGINX Open Source and NGINX Plus), CVE-2026-22765, CVE-2026-22766 (Dell Wyse Management Suite), CVE-2026-21637, CVE-2026-21710 (Node.js), CVE-2026-25185 aka LnkMeMaybe (Microsoft), CVE-2026-1519, CVE-2026-3104, CVE-2026-3119, CVE-2026-3591 (BIND 9), CVE-2026-2931 (Amelia Booking plugin), CVE-2026-33656 (EspoCRM), CVE-2026-3608 (Kea), CVE-2026-20817 (Microsoft Windows Error Reporting), CVE-2025-33244 (NVIDIA Apex), CVE-2026-32746 (Synology DiskStation Manager), and CVE-2026-3098 (Smart Slider 3 plugin). 🎥 Cybersecurity Webinars Your Identity Program Is Mature. So Why Are You Still Getting Breached? → Your identity program is mature. Yet hundreds of apps still operate outside it. New 2026 Ponemon research from 600+ security leaders shows exactly how big that gap is and what it costs. Now, AI agents are making it worse. This webinar breaks down the findings and shows you what to fix first. Everyone Agrees AI Agents Need Identity. Almost Nobody Knows How to Do It → Everyone agrees AI agents need identity. Few know how to actually do it. This session skips the theory and shows you what a real production deployment looks like, including how to give agents strong identities, see exactly what they're doing, and control how they behave. 📰 Around the Cyber World Fortinet FortiClient EMS Flaw Comes Under Attack — A recently patched security flaw affecting Fortinet FortiClient EMS has come under active exploitation in the wild as of March 24, 2026. The vulnerability in question is CVE-2026-21643 (CVSS score: 9.1), a critical SQL injection that could allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests. The issue was addressed by Fortinet last month in FortiClient EMS version 7.4.5. "Attackers can smuggle SQL statements through the 'Site'-header inside an HTTP request," Defused Cyber said. Nearly 1,000 FortiClient EMS are publicly exposed. Meta Disrupts Influence Operation Linked to Iran — Meta said it disrupted an influence operation linked to Iran that employed "sophisticated fake personas" on Instagram to build relationships with U.S. users before sending political messaging. The network used accounts posing as journalists, commentators, and ordinary people to engage users and gradually introduce political narratives. A second layer of accounts amplified posts to help spread the messaging. Armenian National Extradited to U.S. in Connection with RedLine Stealer Operations — An Armenian national has been extradited to the United States over his alleged role in the administration of the RedLine infostealer malware. Hambardzum Minasyan, per court documents, allegedly developed and managed the stealer, while unnamed conspirators maintained digital infrastructure, including the command-and-control (C2) servers and administrative panels to enable the deployment of the malware by affiliates, and collected payments from the affiliates. "They allegedly responded to questions and requests from actual and potential RedLine affiliates, conspired with each other and affiliates to steal and possess the financial information, including access devices, of victims, and laundered the proceeds of cybercrime through cryptocurrency exchanges and other means," the U.S. Justice Department said. Minasyan has also been accused of registering two virtual private servers to host portions of RedLine's infrastructure, as well as two internet domains in support of the scheme, repositories on an online file sharing site to distribute the stealer to affiliates, and registering a cryptocurrency account in November 2021 to receive payments. RedLine Stealer was disrupted in an international law enforcement operation in October 2024. Minasyan has been charged with conspiracy to commit access device fraud, conspiracy to violate the Computer Fraud and Abuse Act, and conspiracy to commit money laundering. If convicted, he faces up to 10 years in prison for access device fraud and up to 20 years in prison for the other two counts. In June 2025, the U.S. Department of State announced a $10 million reward for information on Maxim Alexandrovich Rudometov, who is believed to be the main developer and administrator of RedLine. New Android Malware "Android God Mode" Abuses Accessibility Permissions — The Indian Cybercrime Coordination Centre (I4C) has issued an advisory, alerting users of a new Android malware called Android God Mode that abuses its permissions to accessibility services to seize control of infected devices. The malware is propagated via dropper apps that masquerade as banking, public, and utility services such as SBI YONO, Jivan Parman Patra, and RTO Challan, indicating that the campaign's focus is on targeting Indian users. "By coercing users into granting elevated Android permissions, these threats achieve near-total control over the device, enabling stealthy overlay attacks and the real-time theft of sensitive financial and personal information," the I4C said. The malware is distributed in the form of links or APK files shared through WhatsApp. Once installed, it abuses Android's accessibility services to grant itself additional permissions to harvest incoming SMS messages, send messages on the victim's behalf, access contact lists, initiate fraudulent call forwarding, and take pictures using the device's camera. Android 17 Beta Gains New Security Features — To improve security against code injection attacks, Android now enforces that dynamically loaded native libraries must be read-only. If your app targets Android 17 or higher, all native files loaded using System.load() must be marked as read-only beforehand. Another new addition is the support for Post-Quantum Cryptography (PQC) through the new v3.2 APK Signature Scheme. This scheme utilizes a hybrid approach, combining a classical signature with an ML-DSA signature. China-Linked Actors Deliver Mofu Loader and KIVARS — In recent months, Chinese-affiliated espionage clusters like DRBControl have employed DLL side-loading techniques to deliver Mofu Loader – a malware previously attributed to GroundPeony – which then drops a C++ backdoor capable of executing commands issued by an attacker-controlled server. Last year, companies and organizations in Japan and Taiwan have also been targeted by variants of a backdoor called KIVARS, which is tied to a Chinese hacking group called BlackTech. Automated Traffic Outpaces Human Traffic — HUMAN Security found that automated traffic grew eight times faster than human traffic year-over-year. "In 2025, automated traffic across the internet grew 23.51% year over year, while human traffic increased 3.10% over the same period," the company said. The cybersecurity company noted that its customers experienced more than 400,000 attempted post-login account compromise attacks, more than quadruple that of 2024. U.S. Accuses China of Backing Scam Compounds — A senior U.S. official accused Beijing of implicitly backing Chinese criminal syndicates running cyber scam compounds across Southeast Asia. Speaking during a Joint Economic Committee congressional hearing about U.S. efforts to combat digital scams, Reva Price, commissioner with the U.S.-China Economic and Security Review Commission, said links have been unearthed between scam centers and the Chinese government's Belt and Road Initiative. Chinese criminal syndicates have "invested in projects linked to China's Belt and Road Initiative alongside China's state-owned enterprises," she said, adding that they "have also seen criminal leaders who appear to have gotten a pass by promoting messaging and other activities aligned with Chinese Communist Party priorities." Scam centers in Southeast Asia are often operated by Chinese crime syndicates that lure people into the region with enticing job opportunities and coerce them into participating in pig butchering or romance baiting scams by confiscating their passports and subjecting them to torture. Exploitation Against Oracle WebLogic Servers — A recently disclosed security flaw in Oracle WebLogic (CVE-2026-21962, CVSS score: 10.0) witnessed automated exploitation attempts almost immediately after public exploit code was released, demonstrating how software flaws are being rapidly weaponized by bad actors. The activity, detected by CloudSEK against its honeypots, also leveraged other WebLogic flaws (CVE-2020-14882, CVE-2020-14883, CVE-2020-2551, and CVE-2017-10271), as well as flaws impacting Hikvision and PHPUnit, indicating a spray and pray approach. "Attackers predominantly utilized rented Virtual Private Servers (VPS) from common hosting providers like DigitalOcean and HOSTGLOBAL.PLUS," the company said. "The overall activity was characterized by high-volume, automated scanning, with tools like libredtail-http and the Nmap Scripting Engine dominating the malicious traffic." Security Flaws in Cisco Catalyst 9300 Series Switches — Details have emerged about now-patched vulnerabilities in Cisco Catalyst 9300 Series switches (CVE-2026-20110, CVE-2026-20112, CVE-2026-20113, and CVE-2026-20114) that could result in privilege escalation, operational denial-of-service, stored cross-site scripting (XSS), and CRLF injection. "Collectively, these vulnerabilities introduce risks to administrative trust boundaries, service availability, session integrity, and system log reliability – affecting both operational continuity and security monitoring capabilities," OPSWAT said. "CVE-2026-20114 and CVE-2026-20110 are the most operationally impactful when chained. A low-privilege Web UI user can escalate access and invoke a maintenance-mode operation, resulting in full denial of service that may require physical intervention to restore." The issues were patched by Cisco last week. Financial Institution Targeted by BRUSHWORM and BRUSHLOGGER — A modular backdoor with USB-based spreading capabilities was used in an attack targeting an unnamed South Asian financial institution, according to findings from Elastic Security Labs. The malware, dubbed BRUSHWORM, is one of the two malware components identified in the victim's infrastructure, the other being a DLL keylogger referred to as BRUSHLOGGER. "BRUSHWORM features anti-analysis checks, AES-CBC encrypted configuration, scheduled task persistence, modular DLL payload downloading, USB worm propagation, and broad file theft targeting documents, spreadsheets, email archives, and source code," security researcher Salim Bitam said. BRUSHWORM is also responsible for running basic anti-analysis checks, maintaining persistence, command-and-control (C2) communication, and downloading additional modular payloads. BRUSHLOGGER augments the backdoor by capturing system-wide keystrokes via a simple Windows keyboard hook and logging the active window context for each keystroke session. "Neither binary employs meaningful code obfuscation, packing, or advanced anti-analysis techniques," Elastic said. "Given the absence of a kill switch, the use of free dynamic DNS servers in testing versions, and some coding mistakes, we assess with moderate confidence that the author is relatively inexperienced and may have leveraged AI code-generation tools during development without fully reviewing the output." U.K. Sanctions Xinbi — The U.K.'s Foreign, Commonwealth and Development Office (FCDO) has sanctioned Xinbi, a Chinese-language guarantee marketplace accused of enabling large-scale online fraud and human exploitation by supporting #8 Park (aka Legend Park), an industrial-scale scam compound in Cambodia notorious for large-scale pig butchering scams and forced labor of trafficked workers. The U.K. is the first country to sanction Xinbi. The move is designed to isolate Xinbi from the legitimate crypto ecosystem and disrupt its operations. Xinbi is estimated to have processed over $19.9 billion between 2021 and 2025. "The platform facilitates everything from 'Black U' money laundering and unlicensed OTC trades to the sale of compromised personal databases and scam infrastructure," Chainalysis said. "In the face of previous takedowns, Xinbi demonstrated significant resilience by rapidly migrating to the SafeW messaging app and launching its own proprietary payment app, XinbiPay. This evolution highlights the challenges around pursuing illicit services as they build custom financial rails to insulate themselves from platform-level disruptions." According to a report published by Elliptic last month, #8 Park is linked to a company named Legend Innovation, which, in turn, has ties to Prince Group, whose chairman, Chen Zhi, was arrested and extradited to China in connection with a crackdown on a large-scale fraud operation. #8 Park is also tied to HuiOne Group, with its payment business, HuiOne Pay (later rebranded as H-PAY), which operates a physical store within the compound. There has since been a sharp decline in incoming payments to merchants operating inside the compound beginning around February 9, 2026, with transactions almost entirely ceasing by February 13. What is Tsundere? — Tsundere is a botnet that enables system fingerprinting and arbitrary command execution on victim machines. It's notable for the use of a technique called EtherHiding to retrieve command-and-control (C2) servers stored in smart contracts on the Ethereum blockchain. The malware is suspected to be a Malware-as-a-Service (MaaS) offering of Russian origin, owing to logic that checks whether the infected host is located in a CIS country, including Ukraine, and terminates execution if so. Most recently, the use of the botnet has been linked to the Iranian state-sponsored actor MuddyWater. Jailbreaking, a Continued Risk to LLMs — New research from Palo Alto Networks Unit 42 has uncovered that prompt jailbreaking remains a practical risk to large language models (LLMs) and that a genetic algorithm-based fuzzing approach can be used to generate meaning-preserving prompt variants to trigger policy-violating outcomes against both closed-source and open-weight pre-trained models. "The broader implication is that guardrails should be treated as probabilistic controls that require continuous adversarial evaluation, not as definitive security boundaries," Unit 42 said. The findings reinforce that security for LLM applications cannot rely on a single layer, necessitating that organizations define and enforce application scope, use robust, multi-signal content controls, treat user input as untrusted and isolate it from privileged instructions, validate outputs against scope and policy, and monitor for misuse, and apply standard security controls, such as authentication, rate limiting, and and least privilege tool permissions. SEO Campaign Delivers AsyncRAT — Since October 2025, an unknown threat actor has been running an active SEO poisoning campaign, using impersonation sites of over 25 popular applications to direct victims to malicious installers, including VLC Media Player, OBS Studio, KMS Tools, and CrosshairX. The campaign uses ScreenConnect, a legitimate remote management tool, to establish initial access and to deliver AsyncRAT. "Most notable in this campaign is the RAT’s added cryptocurrency clipper, dynamic plugin system capable of loading arbitrary capabilities at runtime, and a geo-fencing mechanism that deliberately excludes targets across the Middle East, North Africa, and Central Asia," NCC Group said. AsyncRAT has also been delivered as part of a series of attacks on Libyan organizations between November 2025 and February 2026. The attacks targeted an oil refinery, a telecoms organization, and a state institution. "AsyncRAT is a remote access Trojan with a variety of capabilities, including keylogging, screen capture, and remote command execution capabilities, making it ideal for use in intelligence gathering and espionage attacks," Symantec and Carbon Black said. "It is also modular, meaning it can be updated and customized, which is attractive for attackers." Nigerian National Sentenced to 7 Years in Prison — A Nigerian man has been sentenced to more than seven years in a U.S. prison for his role in a scheme that broke into business email accounts and tricked victims into sending millions of dollars to fraudulent bank accounts. James Junior Aliyu, 31, received a 90-month prison sentence for conspiracy to commit wire fraud and money laundering. The court also ordered Aliyu to forfeit $1.2 million and repay nearly $2.39 million to the victims. Aliyu, who pleaded guilty in August 2025, acknowledged that he conspired with others, including Kosi Goodness Simon-Ebo, 31, and Henry Onyedikachi Echefu, 34, to deceive and defraud multiple American victims from February 2017 until at least July 2017. The business email compromise scheme targeted American businesses and individuals by compromising email accounts and sending false wiring instructions to deceive victims into sending money to bank accounts under their control. "Aliyu and his accomplices conspired to commit money laundering by disbursing the fraudulently obtained funds in the drop accounts to other accounts," the U.S. Justice Department said. "Co-conspirators moved the stolen money by initiating account transfers, withdrawing cash, and obtaining cashier’s checks. They also wrote checks to other individuals and entities to hide the true ownership and source of these assets. In total, Aliyu and his co-conspirators attempted to defraud victims of at least $10.4 million, and the victims suffered an actual loss of at least $2,389,130." Sensor Technology to Combat Deepfakes — Researchers at ETH Zürich have developed a sensor system that stamps a cryptographic signature onto images, video, and audio within a sensor chip at the exact moment they are captured, making it impossible to tamper with the data without being detected. "If the signatures are uploaded to a public ledger (e.g., a blockchain), anyone can verify the authenticity of videos and other data," ETH Zürich said. "The technology can, in principle, be integrated into any type of sensor or camera. It would then be possible to identify manipulated content on online platforms with minimal effort." Middle East Conflict Fuels Cyber Attacks — Threat actors have been capitalizing on geopolitical tensions in the Middle East region to spread Android spyware by distributing trojanized versions of Israel's Red Alert apps via SMS phishing messages. The espionage campaign has been codenamed Operation False Siren by CYFIRMA. ZIP archives containing lures related to the conflict are also being used to launch malicious payloads that lead to the deployment of PlugX and LOTUSLITE backdoors. These ZIP-based phishing campaigns have been attributed to a Chinese nation-state actor known as Mustang Panda. Elsewhere, an Iran-themed fake news blog site hosting malicious JavaScript has been found, leading to the deployment of StealC malware. Apple Tests Ways to Block Malicious Copy-Pastes in macOS — With the release of macOS 26.4 last week, Apple has introduced a new feature that warns Mac users if they paste harmful commands in the Terminal app to curb ClickFix-style attacks that have increasingly targeted macOS in recent months. "Scammers often encourage pasting text into Terminal to try and harm your Mac or compromise your privacy," the message reads. "These instructions are commonly offered via websites, chat agents, apps, files, or a phone call." The alert comes with a "Paste Anyway" for those who wish to proceed. The disclosure comes as multiple ClickFix campaigns have come to light, including using a Cloudflare-themed verification page to deliver a Python-based macOS stealer dubbed Infiniti Stealer. A similar Cloudflare verification, but for Windows, has been used to launch PowerShell commands that ultimately drop StealC, Lumma, Rhadamanthys, Vidar Stealer, and Aura Stealer malware. The ClickFix strategy has also been adopted by a traffic distribution system known as KongTuke to redirect visitors of compromised WordPress websites to phishing pages and malware payloads. According to eSentire, ClickFix lures have been used to deliver EtherRAT, a Node.js-based backdoor linked to North Korean threat actors. "EtherRAT allows threat actors to run arbitrary commands on compromised hosts, gather extensive system information, and steal assets such as cryptocurrency wallets and cloud credentials," the Canadian security company said. "Command-and-Control (C2) addresses are retrieved using 'EtherHiding,' a technique to make C2 addresses more resilient by storing and updating them in Ethereum smart contracts, allowing threat actors to rotate infrastructure at a small cost and avoid takedowns by law enforcement." Recorded Future said it has identified five distinct clusters leveraging ClickFix to facilitate initial access to Windows and macOS systems since May 2024. "This indicates that the ClickFix methodology has transitioned into a standardized, high-ROI template adopted across a fragmented ecosystem of threat actors," Insikt Group said. "While visually diverse, all analyzed clusters use a consistent execution framework that bypasses traditional browser security controls by shifting the point of exploitation to user-assisted manual commands. These campaigns target a wide variety of sectors, including accounting (QuickBooks), travel (Booking.com), and system optimization (macOS)." Apple Rolls Out Mandatory Age Verification in U.K. — In more Apple news, the tech giant has rolled out mandatory U.K. age verification with iOS 26.4, requiring users to provide a credit card or ID to confirm if they are an adult before "downloading apps, changing certain settings, or taking other actions with your Apple Account." The move comes at a time when online child safety is increasingly drawing attention from regulators, causing many digital services, including social media apps and porn sites, to roll out similar checks. Discord, which announced plans to verify the ages of all its users last month, has since paused the effort until H2 2026 after concerns were raised about how IDs and personal information would be handled. Discord has reiterated that it does not receive any identifying personal information from users who need to manually verify their age. Instead, it is partnering with third-party age verification companies, who will "handle verification and only pass back your age group." The company also said it's no longer working with age verification vendor Persona, which has attracted criticism over allegations that it shared users' data with other companies and left its frontend source code exposed to the internet. 🔧 Cybersecurity Tools OpenClaw Security Handbook → It is a detailed security guide published by ZAST AI for users of OpenClaw, a multi-channel AI gateway that connects messaging platforms, LLMs, and local system capabilities. Because that combination creates a serious attack surface, the handbook covers the real risks — prompt injection, malicious skills, exposed ports, credential theft — backed by documented incidents and CVEs, with practical configuration guidance for locking it down. VulHunt → It is an open-source framework from Binarly's research team for hunting vulnerabilities in software binaries and UEFI firmware. It uses customizable rulepacks for scanning and can connect to Binarly's Transparency Platform for large-scale triage. It also supports running as an MCP server, letting AI assistants interact with it directly. Disclaimer: For research and educational use only. Not security-audited. Review all code before use, test in isolated environments, and ensure compliance with applicable laws. Conclusion That's the week. Some of it will age well, some of it is already being quietly exploited while you're reading this sentence. The through-line, if there is one: patience. Attackers are playing long games. The detections, the arrests, the patches — they matter, but they're almost always trailing. Stay sharp, check the CVE list, and see you next Monday.
thehackernews.comMar 30, 2026extracted
Chainguard locks down CI/CD with secure-by-default actions
Chainguard locks down CI/CD with secure-by-default actions Chainguard has announced Chainguard Actions, secure-by-default workflows for CI/CD pipelines that allow developers and AI agents to ship quickly without introducing software supply chain risk. Using an agentic approach, Chainguard Actions provides a continuously secured catalog of workflows maintained by the Chainguard Factory, the infrastructure that has become the industry standard for delivering trusted open source artifacts. Chainguard Actions ingests widely used third-party CI/CD workflows, starting with GitHub Actions, and evaluates them against a security best-practices ruleset, automatically fixes failures, and publishes secured versions that engineering teams can safely integrate into their workflows. The most privileged and least protected layer in the CI/CD pipeline CI/CD workflows operate with the highest privileges in modern software delivery, yet they remain among the least protected components in the development stack. As engineering teams increasingly build with AI-assisted coding agents to accelerate releases, code development is outpacing security teams’ ability to manually review that code. Unaddressed vulnerabilities in CI/CD workflows can silently introduce malware, leak credentials, or compromise production systems. Last year, attackers compromised the widely used tj-actions/changed-files GitHub Action and exposed secrets across more than 23,000 repositories by redirecting version tags to a malicious commit. More recently, an autonomous AI bot known as hackerbot-claw demonstrated how easily these workflows can be exploited. The bot scanned public repositories continuously for a week to find vulnerable GitHub Actions configurations. It then successfully breached multiple major organizations. Together, these attacks illustrate new ways that attackers can automatically probe and exploit vulnerable workflows at scale, and how they are getting more sophisticated in their approaches. “CI/CD pipelines power modern software delivery, but the privileged workflows inside them remain one of the least secured layers of the stack,” said Dan Lorenc, CEO of Chainguard. “Chainguard Actions extends our industry-leading secure-by-default approach to the CI/CD layer. Our vision is to enable a software delivery lifecycle that developers and their AI agents can trust end to end.” Secure-by-default CI/CD workflows Using agents, Chainguard Actions ingests popular third-party CI/CD workflows, starting with GitHub Actions, and evaluates them against a comprehensive security ruleset that detects unsafe patterns, excessive permissions, and supply chain risks. Actions that fail the review are automatically remediated and published in a secure catalog, ready for use in production workflows. Whenever upstream Actions change or the Chainguard ruleset evolves, affected workflows are automatically resecured without requiring manual intervention. With Chainguard Actions, organizations can: Protect against attacks on the most privileged open source layer: Every Action is built from source and continuously scanned, preventing tag hijacking, dependency confusion, and pull_request_target abuse before they ever reach CI/CD pipelines. Avoid CI/CD incident response cycles: While the rest of the industry responds to compromised Actions elsewhere, engineering teams can remain focused on shipping new releases. Establish trust in every automation workflow: Each Action ships with a software bill of materials (SBOM) and provenance attestation, providing verifiable insight into what is running, where it originated, and how it was built. Solving the trust problem in the CI/CD Security reviews of CI/CD workflows are typically treated as a point-in-time exercise, but the threat landscape evolves continuously as maintainers are compromised, new exploitation techniques emerge, and automated attackers scan repositories for vulnerable patterns. Chainguard addresses this challenge through the AI-native Chainguard Factory, the infrastructure that already monitors, builds, and continuously updates millions of open source artifacts. The Chainguard Factory’s same reconciliation model now powers Chainguard Actions, continuously comparing the desired secure state with what exists in upstream automation marketplaces and automatically correcting any drift. Chainguard Actions are built with: Rules to prevent exploits, AI to infer attacks: Hard-coded security checks identify known dangerous patterns, while AI agents identify emerging or subtle issues such as overly permissive workflows. Auditable CI/CD artifacts: Each security fix appears as an individual Git commit with a complete pull request trail, allowing security teams to understand what changed and why. Continuous monitoring as attacks evolve: Whenever Chainguard introduces new security rules, every Action in the catalog is automatically reevaluated and resecured if necessary. For developers, Chainguard Actions removes the fear associated with strangers accessing the layer through which their organization’s most sensitive information passes. It also reduces the risk of a breach and the commensurate triage if one occurs. Instead, teams can rely on a continuously secured catalog of Actions and focus on shipping software.
helpnetsecurity.comMar 17, 2026extracted
What Boards Must Demand in the Age of AI-Automated Exploitation
“You knew, and you could have acted. Why didn’t you?” This is the question you do not want to be asked. And increasingly, it’s the question leaders are forced to answer after an incident. For years, many executive teams and boards have treated a large vulnerability backlog as an uncomfortable but tolerable fact of life: “we’ve accepted the risk.” If you’ve ever seen a report showing thousands (or tens of thousands) of open Highs and Critical CVEs, you’ve probably also heard the usual rationalizations from folks that would rather look the other way: we have other priorities, this will take years of engineering time to fix, how do you know these are really Critical, we’re still prioritizing, we’ll get to it. In the old world, that story, while not good, was often survivable. Exploitation was slower, more manual, and required more operator skill. Even the most sophisticated attackers had constraints. Organizations leaned on those constraints as an unspoken part of the risk model: “If it was really as bad as you say, we’d be compromised right now.” That world is gone. AI has collapsed the cost of exploitation We’re now watching threat actors use agentic AI systems to accelerate the entire offensive workflow: reconnaissance, vulnerability discovery, exploit development, and operational tempo. Anthropic publicly detailed disrupting a cyber-espionage campaign in which attackers used Claude in ways that materially increased their speed and scale, and they explicitly warned that this kind of capability can allow less experienced groups to do work that previously required far more skill and staffing. As security leaders, we know that AI enables attackers to move faster. But now, automation turns a backlog into a weapon. In the old model, having 13,000 Highs in production could be rationalized as a triage problem. In the new model, attackers can move from chain discovery to validation and exploitation in dramatically less time. “We’re working the backlog” stops sounding like a strategy and starts sounding like an excuse. The most dangerous sentence in the boardroom “Don’t worry, the CISO has it handled.” I’ve lived the reality behind that sentence. CISOs can build programs, establish priorities, report metrics, and drive cross-functional remediation, but in many enterprises, the vulnerability problem is structurally bigger than any one executive’s responsibility. It’s a system problem: legacy dependencies, release velocity constraints, fragile production environments, and limited engineering resources. Boards can’t delegate governance. Delaware’s Caremark line of cases is frequently cited in director oversight discussions: boards must have reporting systems designed to surface consequential risk and must actually engage with what those systems report. The point isn’t to scare directors with legal theory – it’s to make the practical governance point that if your reporting says “we have thousands of serious vulnerabilities open,” the board’s job is to exercise oversight. What boards should demand (and how CISOs should answer) If you’re a board member, you should seek operational truth. Focus on the resiliency of your company’s tech, not just compliance. And if you’re a security leader, you should be creating the operating systems that provide it. These are the questions teams can use that cut through performative cybersecurity: What does our vulnerability management program look like end-to-end? How many vulnerabilities (especially Criticals and Highs) exist in our products right now? How long did it take to fully remediate new Criticals and Highs in the past quarter? The past year? If a new 0-day was discovered in our top-selling product today, how long would it take before we could tell customers it was safe? What is the dollar cost of our current vulnerability backlog? (Multiply people-hours to fix by fully loaded engineering cost, and you get a number the board can govern.) This is how you make the backlog tangible enough that leadership stops hiding behind abstractions. “Patch faster” is not a complete answer Many organizations respond to board pressure by promising to patch faster. That helps, until it breaks production. If emergency patching reliably causes customer impact (and in some environments it does), you’re forced into a terrible tradeoff: accept exposure or accept downtime. The modern enterprise needs a model that reduces the frequency and blast radius of emergency remediation, not one that merely accelerates the same fragile process. The supply chain reality: liabilities are shifting We’re seeing liabilities shift as regulators and courts focus on software supply chain hygiene and operational resilience. In the EU, the Cyber Resilience Act (CRA) is now in force, with its main obligations taking effect in December 2027. Many organizations will face stronger expectations for vulnerability handling, secure-by-design practices, and accountability throughout the software lifecycle. In financial services, DORA (Digital Operational Resilience Act) has entered into application, bringing harmonized ICT risk management and operational resilience requirements across the EU. We’re also seeing this dynamic play out in the US, where negligence claims are brought in class action lawsuits against firms, with plaintiffs alleging a lack of due care that led to data breaches. You can reduce the backlog by design In the age of AI-accelerated exploitation, “managed risk” too often means assuming attackers will keep moving at yesterday’s pace. Boards should stop accepting that assumption. CISOs should stop pretending “patch faster” or getting a risk acceptance is sufficient. And organizations should invest in reducing vulnerability exposure at the source so the next audit report isn’t a spreadsheet of accepted risks, but evidence of a shrinking attack surface. Shameless plug, this is where Chainguard’s approach is designed to change the math: start with secure-by-default software components that minimize vulnerabilities from the outset and reduce vulnerability accrual over time. That means fewer critical findings landing in your environment, fewer emergency patch cycles, and less operational disruption when the next high-profile CVE hits. By structurally reducing vulnerability backlog and remediation toil, teams can redirect engineering time from zero-ROI firefighting into high-ROI innovation that actually drives competitive advantage and revenue. Because when the finger-pointing starts after the breach, and someone asks why the company chose to live with 13,000 Highs in production, the only defensible answer is: we didn’t. We changed the system. For more hot takes and practical advice from – and for – engineering and security leaders, subscribe to Unchained or reach out to learn more about Chainguard. Note: This article was expertly written and contributed byQuincy Castro, CISO, Chainguard.
thehackernews.comMar 11, 2026extracted
npm’s Update to Harden Their Supply Chain, and Points to Consider
In December 2025, in response to the Sha1-Hulud incident, npm completed a major authentication overhaul intended to reduce supply-chain attacks. While the overhaul is a solid step forward, the changes don’t make npm projects immune from supply-chain attacks. npm is still susceptible to malware attacks – here’s what you need to know for a safer Node community. Let’s start with the original problem Historically, npm relied on classic tokens: long-lived, broadly scoped credentials that could persist indefinitely. If stolen, attackers could directly publish malicious versions to the author’s packages (no publicly verifiable source code needed). This made npm a prime vector for supply-chain attacks. Over time, numerous real-world incidents demonstrated this point. Shai-Hulud, Sha1-Hulud, and chalk/debug are examples of recent, notable attacks. npm’s solution To address this, npm made the following changes: npm revoked all classic tokens and defaulted to session-based tokens instead. The npm team also improved token management. Interactive workflows now use short-lived session tokens (typically two hours) obtained via npm login, which defaults to MFA for publishing. The npm team also encourages OIDC Trusted Publishing, in which CI systems obtain short-lived, per-run credentials rather than storing secrets at rest. In combination, these practices improve security. They ensure credentials expire quickly and require a second factor during sensitive operations. Two important issues remain First, people need to remember that the original attack on tools like ChalkJS was a successful MFA phishing attempt on npm’s console. If you look at the original email attached below, you can see it was an MFA-focused phishing email (nothing like trying to do the right thing and still getting burned). The campaign tricked the maintainer into sharing both the user login and one-time password. This means in the future, similar emails could get short-lived tokens, which still give attackers enough time to upload malware (since that would only take minutes). Second, MFA on publish is optional. Developers can still create 90-day tokens with MFA bypass enabled in the console, which are extremely similar to the classic tokens from before. These tokens allow you to read and write to a token author’s maintained packages. This means that if bad actors gain access to a maintainer’s console with these token settings, they can publish new, malicious packages (and versions) on that author’s behalf. This circles us back to the original issue with npm before they adjusted their credential policies. To be clear, more developers using MFA on publish is good news, and future attacks should be fewer and smaller. However, making OIDC and MFA on-publish optional still leaves the core issue unresolved. In conclusion, if (1) MFA phishing attempts to npm’s console still work and (2) access to the console equals access to publish new packages/versions, then developers need to be aware of the supply-chain risks that still exist. Recommendations In the spirit of open source security, here are three recommendations that we hope GitHub and npm will consider in the future. Ideally, they continue to push for the ubiquity of OIDC in the long term. OIDC is very hard to compromise and would almost completely erase the issues surrounding supply-chain attacks. More realistically, enforcing MFA for local package uploads (either via an email code or a one-time password) would further reduce the blast radius of worms like Shai-Hulud. In other words, it would be an improvement to not allow custom tokens that bypass MFA. At a minimum, it would be nice to add metadata to package releases, so developers can take precautions and avoid packages (or maintainers) who do not take supply chain security measures. In short, npm has taken an important step forward by eliminating permanent tokens and improving defaults. Until short-lived, identity-bound credentials become the norm — and MFA bypass is no longer required for automation — supply-chain risk from compromised build systems remains materially present. A new way to do it This entire time, we’ve been talking about supply-chain attacks by uploading packages to npm on a maintainer’s behalf. If we could build every npm package from verifiable upstream source code rather than downloading the artifact from npm, we’d be better off. That’s exactly what Chainguard does for its customers with Chainguard Libraries for JavaScript. We’ve looked at the public database for compromised packages across npm and discovered that for 98.5% of malicious packages, the malware was not present in the upstream source code (just the published artifact). This means an approach of building from source would reduce your attack surface by some 98.5%, based on past data, because Chainguard’s JavaScript repository would never publish the malicious versions available on npm. In an ideal world, customers are most secure when they use Chainguard Libraries and apply the recommendations above. Per the “Swiss cheese model of security,” all of these features are layers of additive security measures, and companies would be best off using a combination of them. If you’d like to learn more about Chainguard Libraries for JavaScript, reach out to our team. Note: This article was thoughtfully written and contributed for our audience by Adam La Morre, Senior Solutions Engineer at Chainguard.
thehackernews.comFeb 13, 2026extracted
Seven habits that help security teams reduce risk without slowing delivery
ON-PREM US datacenters tripled their water footprint in 10 years... and those are figures from the start of the AI boom. It can only be worse now. Silo-ed reporting isn't helping ai and ML AI slop is good for business if you know what you're doingYour irresponsibility is someone else's opportunity SAAS Salesforce partners not seeing meaningful revenue from Agentforce AI platform, report saysShow us the money ai and ml AI companies are burning books, advocates complain to FTCFahrenheit 203, the temperature GPUs stop gorging on literature DEVOPS Go updates may delight diehard gophers but displease AI overlordsv 1.27 expands generics to support methods Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash anotherWord up GNOME can look like Windows – and Flashback can do it without extensionsNew 'Simple-taskbar' is an option, but there's a simpler, stabler way A moment of silence, please, for the final release of Debian on x86-32New Debian versions hit FOSSland in the form of 13.6 and 12.15 Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websitesFlaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide Frame: A new X11 server – implemented directly in assemblyJoins yserver, Phoenix, and of course XLibre – and outlier Arcan Cinnamon 6.8 will support Wayland – if you want itNext version of Linux Mint’s desktop has both kinds of display server
go.theregister.comJan 29, 2026extracted
The State of Trusted Open Source
Chainguard, the trusted source for open source, has a unique view into how modern organizations actually consume open source software and where they run into risk and operational burdens. Across a growing customer base and an extensive catalog of over 1800 container image projects, 148,000 versions, 290,000 images, and 100,000 language libraries, and almost half a billion builds, they can see what teams pull, deploy, and maintain day-to-day, along with the vulnerabilities and remediation realities that come hand in hand. That’s why they created The State of Trusted Open Source, a quarterly pulse on the open source software supply chain. As they analyzed anonymized product usage and CVE data, the Chainguard team noticed common themes around what open source engineering teams are actually building with and the risks associated. Here’s what they found: AI is reshaping the baseline stack: Python led the way as the most popular open source image among Chainguard’s global customer base, powering the modern AI stack. Over half of production happens outside of the most popular projects: Most teams may standardize on a familiar set of images, but real-world infrastructure is powered by a broad portfolio that extends far beyond the top 20 most popular, which they refer to in this report as longtail images. Popularity doesn’t map to risk: 98% of the vulnerabilities found and remediated in Chainguard images occurred outside of the top 20 most popular projects. That means the biggest security burden accumulates in the less-visible part of the stack, where patching is hardest to operationalize. Compliance can be the catalyst for action: Compliance takes many forms today: from SBOM and vulnerability requirements to industry frameworks like PCI DSS, SOC 2, and regulations like the EU’s Cyber Resilience Act. FIPS is just one example, focused specifically on U.S. federal encryption standards. Even so, 44% of Chainguard customers run a FIPS image in production, underscoring how frequently regulatory needs shape real-world software decisions. Trust is built on remediation speed: Chainguard eliminated Critical CVEs, on average, in under 20 hours. Before we dive in, a note on the methodology: This report analyzes 1800+ unique container image projects, 10,100 total vulnerability instances, and 154 unique CVEs tracked from September 1, 2025, through November 30, 2025. When we use terms like “top 20 projects” and “longtail projects” (as defined by images outside of the top 20), we’re referring to real usage patterns observed across Chainguard’s customer portfolio and in production pulls. Usage: What teams actually run in production If you zoom out, today’s production container footprint looks exactly like you’d expect: foundational languages, runtimes, and infrastructure components dominate the most popular list. Most popular images: AI is reshaping the baseline stack Across all regions, the top images are familiar staples: Python (71.7% of customers), Node (56.5%), nginx (40.1%), go (33.5%), redis (31.4%), followed by JDK, JRE, and a cluster of core observability and platform tooling like Grafana, Prometheus, Istio, cert-manager, argocd, ingress-nginx, and kube-state-metrics. This indicates that customers operate a portfolio of critical building blocks – including languages, gateways, service mesh, monitoring, and controllers – that collectively form the foundation of their business. It’s not surprising to see Python leading the way globally, as the default glue language for the modern AI stack. Teams typically standardize on Python for model development, data pipelines, and increasingly for production inference services as well. Most popular by region: Similar foundations, different longtail mix North America shows a broad and consistent set of default production building blocks: Python (71.7% of customers), Node (56.6%), nginx (39.8%), go (31.9%), redis (31.5%), plus strong penetration of Kubernetes ecosystem components (cert-manager, istio, argocd, prometheus, kube-state-metrics, node-exporter, kubectl). Notably, even utility images like busybox show up meaningfully. Outside North America, the same core stack appears, but the portfolio spreads differently: Python (72% of customers), Node (55.8%), Go (44.2%), nginx (41.9%), and a noticeable presence of .NET runtimes (aspnet-runtime, dotnet-runtime, dotnet-sdk) and PostgreSQL. The longtail of images is crucial to production, not edge cases Chainguard’s most popular images represent only 1.37% of all available images and account for roughly half of all container pulls. The other half of production usage comes from everywhere else: 1,436 longtail images that make up 61.42% of the average customer’s container portfolio. In other words, half of all production workloads run on longtail images. These aren’t edge cases. They’re core to Chainguard’s customers’ infrastructure. It’s relatively straightforward to keep the top handful of images polished, but what trusted open source requires is maintaining that security and velocity across the breadth of what customers actually run. FIPS usage: Compliance is a catalyst for action FIPS encryption is an essential technology in the compliance landscape, focused on satisfying U.S. federal encryption requirements. And it offers a useful window into how regulatory pressure drives adoption. In the data, 44% of customers run at least one FIPS image in production. The pattern is consistent: when working within compliance frameworks like FedRAMP, DoD IL-5, PCI DSS, SOC 2, CRA, Essential Eight or HIPAA, teams need hardened, trusted open source software that mirrors their commercial workloads. The most used FIPS images align with the broader portfolio, simply with cryptographic modules strengthened for audit and verification. Top FIPS image projects include Python-fips (62% of customers with at least one FIPS image in production), Node-fips (50%), nginx-fips (47.2%), go-fips (33.8%), redis-fips (33.1%), plus platform components like istio-pilot-fips, istio-proxy-fips, and cert-manager variants. Even supporting libraries and crypto foundations show up, such as glibc-openssl-fips. FIPS is not the whole story, but it illustrates a broader truth: compliance is a universal driver, emphasizing the need for trusted open source across the entire software stack. CVEs: Popularity doesn’t map to risk When looking across Chainguard’s catalog of images, risk is overwhelmingly concentrated outside of the most popular images. Of the CVEs Chainguard remediated in the past three months, 214 occurred in the top 20 images, accounting for only 2% of the total CVEs. Go beyond those top images, and you’ll find the other 98% of CVEs Chainguard remediated (10,785 CVE instances). That’s 50 times the number of CVEs in the top 20 images! The largest volume of CVEs are categorized as Medium, but operational urgency often stems from how quickly Critical and High CVEs are addressed, and whether customers can rely on that speed across their entire portfolio, not just the most common images. Trust is built on remediation speed For us, trust is measured in time-to-fix, and Chainguard knows this is most important when it comes to Critical CVEs. During the three-month period analyzed, Chainguard’s team achieved a less than 20-hour average remediation time for Critical CVEs, with 63.5% of Critical CVEs being resolved within 24 hours, 97.6% within two days, and 100% within three days. In addition to Critical CVE remediation, the team addressed High CVEs in 2.05 days, Medium CVEs in 2.5 days, and Low CVEs in 3.05 days, notably faster than Chainguard’s SLAs (seven days for Critical CVEs and 14 days for high, medium, and low CVEs). And this speed isn’t confined to the most popular packages. For every single CVE remediated in a top 20 image project, they resolved 50 CVEs in less-popular images. That longtail is where most of your real exposure hides and it can feel hopeless trying to keep up. Most engineering organizations simply can’t allocate resources to patch vulnerabilities in packages that fall outside their core stack, but the data makes it clear that you have to secure the “quiet majority” of your software supply chain with the same rigor as your most critical workloads. A new baseline for trusted open source Across the data, one takeaway stands out: modern software is powered by a wide, shifting portfolio of open source components, most of which live outside the top 20 most popular images. That’s not where developers spend their time, but it’s where the bulk of security and compliance risk accumulates. This creates a concerning disconnect: it’s rational for engineering teams to focus on the small set of projects that matter most to their stack, but the majority of exposure sits in the vast set of dependencies they don’t have the time to manage. That’s why breadth matters. Chainguard is built to absorb the operational burden of the longtail, providing coverage and remediation at a scale that individual teams can’t justify on their own. As open source supply chains grow more complex, Chainguard will continue to track usage patterns and shine a light on where risk truly resides, so you don’t have to fight the battle against the longtail alone. Ready to get started with the trusted source for open source? Contact Chainguard to learn more. Note: This article was expertly written and contributed by Ed Sawma, VP Product Marketing, Sasha Itkis, Product Analyst.
thehackernews.comJan 8, 2026extracted
Shai-Hulud v2 Campaign Spreads From npm to Maven, Exposing Thousands of Secrets
The second wave of the Shai-Hulud supply chain attack has spilled over to the Maven ecosystem after compromising more than 830 packages in the npm registry. The Socket Research Team said it identified a Maven Central package named org.mvnpm:posthog-node:4.18.1 that embeds the same two components associated with Sha1-Hulud: the "setup_bun.js" loader and the main payload "bun_environment.js." The company told The Hacker News that org.mvnpm:posthog-node:4.18.1 was the only Java package identified so far. "This means the PostHog project has compromised releases in both the JavaScript/npm and Java/Maven ecosystems, driven by the same Shai Hulud v2 payload," the cybersecurity company said in a Tuesday update. It's worth noting that the Maven Central package is not published by PostHog itself. Rather, the "org.mvnpm" coordinates are generated via an automated mvnpm process that rebuilds npm packages as Maven artifacts. The Maven Central said they are working to implement extra protections to prevent already known compromised npm components from being rebundled. As of November 25, 2025, 22:44 UTC, all mirrored copies have been purged. The development comes as the "second coming" of the supply chain incident has targeted developers globally with an aim to steal sensitive data like API keys, cloud credentials, and npm and GitHub tokens, and facilitate deeper supply chain compromise in a worm-like fashion. The latest iteration has also evolved to be more stealthy, aggressive, scalable, and destructive. Besides borrowing the overall infection chain of the initial September variant, the attack allows threat actors to gain unauthorized access to npm maintainer accounts and publish trojanized versions of their packages. When unsuspecting developers download and run these libraries, the embedded malicious code backdoors their own machines and scans for secrets and exfiltrates them to GitHub repositories using the stolen tokens. The attack accomplishes this by injecting two rogue workflows, one of which registers the victim machine as a self-hosted runner and enables arbitrary command execution whenever a GitHub Discussion is opened. A second workflow is designed to systematically harvest all secrets. Over 28,000 repositories have been affected by the incident. "This version significantly enhances stealth by utilizing the Bun runtime to hide its core logic and increases its potential scale by raising the infection cap from 20 to 100 packages," Cycode's Ronen Slavin and Roni Kuznicki said. "It also uses a new evasion technique, exfiltrating stolen data to randomly named public GitHub repositories instead of a single, hard-coded one." The attacks illustrate how trivial it is for attackers to take advantage of trusted software distribution pathways to push malicious versions at scale and compromise thousands of downstream developers. What's more, the self-replication nature of the malware means a single infected account is enough to amplify the blast radius of the attack and turn it into a widespread outbreak in a short span of time. Further analysis by Aikido has uncovered that the threat actors exploited vulnerabilities, specifically focusing on CI misconfigurations in pull_request_target and workflow_run workflows, in existing GitHub Actions workflows to pull off the attack and compromise projects associated with AsyncAPI, PostHog, and Postman. The vulnerability "used the risky pull_request_target trigger in a way that allowed code supplied by any new pull request to be executed during the CI run," security researcher Ilyas Makari said. "A single misconfiguration can turn a repository into a patient zero for a fast-spreading attack, giving an adversary the ability to push malicious code through automated pipelines you rely on every day." It's assessed that the activity is the continuation of a broader set of attacks targeting the ecosystem that commenced with the August 2025 S1ngularity campaign impacting several Nx packages on npm. "As a new and significantly more aggressive wave of npm supply chain malware, Shai-Hulud 2 combines stealthy execution, credential breadth, and fallback destructive behavior, making it one of the most impactful supply chain attacks of the year," Nadav Sharkazy, a product manager at Apiiro, said in a statement. "This malware shows how a single compromise in a popular library can cascade into thousands of downstream applications by trojanizing legitimate packages during installation." Data compiled by GitGuardian, OX Security, and Wiz shows that the campaign has leaked hundreds of GitHub access tokens and credentials associated with Amazon Web Services (AWS), Google Cloud, and Microsoft Azure. More than 5,000 files were uploaded to GitHub with the exfiltrated secrets. GitGuardian's analysis of 4,645 GitHub repositories has identified 11,858 unique secrets, out of which 2,298 remained valid and publicly exposed as of November 24, 2025. Users are advised to rotate all tokens and keys, audit all dependencies, remove compromised versions, reinstall clean packages, and harden developer and CI/CD environments with least-privilege access, secret scanning, and automated policy enforcement. "Sha1-Hulud is another reminder that the modern software supply chain is still way too easy to break," Dan Lorenc, co-founder and CEO of Chainguard, said. "A single compromised maintainer and a malicious install script is all it takes to ripple through thousands of downstream projects in a matter of hours." "The techniques attackers are using are constantly evolving. Most of these attacks don't rely on zero-days. They exploit the gaps in how open source software is published, packaged, and pulled into production systems. The only real defense is changing the way software gets built and consumed."
thehackernews.comNov 26, 2025extracted
AI Security Firm Polygraf Raises $9.5 Million in Seed Funding
Polygraf AI announced on Tuesday that it has raised $9.5 million in a seed funding round that will enable it to enhance its AI security solutions. The funding round was led by Allegis Capital, with participation from Alumni Ventures, DataPower VC, Domino Ventures and others. In addition to enabling Polygraf AI to improve its product, the new investment will be used for go-to-market efforts. The startup has developed proprietary small language model (SLM) technology designed to help organizations detect and mitigate AI risks. Specifically, the platform aims to facilitate safe AI adoption by preventing the leakage of personal and proprietary information, by detecting AI-generated or manipulated content, and by helping maintain compliance with GDPR, HIPAA and other regulations. For instance, Polygraf AI can detect when personal or confidential information is exposed by employees in a chat with an AI model. It can also scan files and folders for data that may be inadvertently exposed due to the use of AI tools for content management. The solution can also redact sensitive data in documents, and authenticate prompts and calls with a provenance layer to prevent deepfake fraud. “The world is realizing that large, cloud-trained models come with large, unpredictable risks,” said Yagub Rahimov, co-founder and CEO of Polygraf AI. Rahimov added, “At Polygraf, we are on a mission to eliminate those risks. We’re proving that you can have both intelligence and integrity—a private AI for sensitive missions that is small, local, explainable, and trustworthy. This funding enables us to double down on our vision to protect the world’s most critical operations, where failure simply isn’t an option.” Related: OpenAI Atlas Omnibox Is Vulnerable to Jailbreaks Related: Sublime Security Raises $150 Million for Email Security Platform Related: Chainguard Raises $280 Million in Growth Funding Related: SimSpace Raises $39 Million for Cyber Range Platform
securityweek.comOct 29, 2025extracted
CyberRidge Emerges From Stealth With $26 Million for Photonic Encryption Solution
Israeli security startup CyberRidge has emerged from stealth mode with $26 million in funding for its photonic encryption solution. Following a $10 million seed investment round led by Awz, the company raised a $16 million extension from Arkin Capital, Elron Ventures, Redseed VC, and the EU Horizon-EIC program. Founded in 2021, Tel Aviv-based CyberRidge has built a plug-and-play photonic layer transmission system that transforms transmitted data into encrypted optical noise to prevent interception and deciphering. According to the deep-tech cybersecurity startup, its photonic encryption solution makes the data immune to traditional in-transit interception tools, while also preventing quantum analysis. To process the transmitted data, a proprietary photonic key is required. The key changes constantly and should be present the instant the data arrives, or it is lost forever. CyberRidge has built the data transmission solution in preparation for the post-quantum era, to prevent ‘harvest now, decrypt later’ attacks, in which encrypted data is captured and stored to be decrypted using quantum computers, when they become available. The real-time, photonics-based protection, the startup says, prevents data harvesting entirely, adding a protective photonic “shield” that is being transmitted through public infrastructure. Multiple organizations in the defense, intelligence, and telecommunications sectors in Europe, Australia, and Singapore, including Israel’s military intelligence unit, are already deploying the system, CyberRidge says. The company has 30 employees and partners operating across Israel, Switzerland, and the US, and it recently received a flagship grant from the European Innovation Council (EIC). “Encryption assumes your data will be stolen and tries to slow attackers down. We’re taking a fundamentally different approach: eliminate the ability to record the data in the first place. If no raw data exists, there’s nothing to hack, today or years from now, no matter how powerful the computer,” CyberRidge founder and CEO Dan Sadot said. Related: SimSpace Raises $39 Million for Cyber Range Platform Related: Chainguard Raises $280 Million in Growth Funding Related: Keycard Emerges From Stealth Mode With $38 Million in Funding
securityweek.comOct 29, 2025extracted
Chainguard Raises $280 Million in Growth Funding
Chainguard announced last week that it has raised $280 million in a growth funding round from General Catalyst’s Customer Value Fund (CVF). Chainguard has raised $636 million in the last six months alone, and a total of nearly $900 million in total. When it announced raising $365 million in a Series D round in April, Chainguard had been valued at $3.5 billion. The Kirkland, Washington-based company provides solutions for securing the open source supply chain. Chainguard has created secure-by-default container images that are not plagued by known vulnerabilities, making it easier for developers to build secure software. The company provides more than 1,700 such images, including for AI applications. Chainguard also provides a catalog of secure language libraries and purpose-built VM images. The latest investment will be used for got-to-market efforts. “This growth capital reflects the strength of Chainguard’s business, and how we’re scaling rapidly, operating with discipline, and planning for the long term,” said Eyal Bar, Chainguard’s CFO. “Our partnership with General Catalyst’s Customer Value Fund (CVF) is an important part of that strategy: it enables us to scale go-to-market investment without diluting ownership or slowing innovation. This structure allows our commercial motion to fund its own growth while giving us the flexibility to double down on product and engineering — where our differentiation lies, and build the operational scale and financial profile required for the next stage of growth,” Bar added. Related: Defakto Raises $30 Million for Non-Human IAM Platform Related: Matters.AI Raises $6.25 Million to Safeguard Enterprise Data
securityweek.comOct 27, 2025extracted
Keycard emerges from stealth with identity and access solution for AI agents
Keycard emerges from stealth with identity and access solution for AI agents Keycard emerged from stealth with its identity and access platform for AI agents that integrates with organizations’ existing user identity solutions. Keycard’s platform identifies AI agents, lets users assign task-based permissions and dynamically enforces policy while tracking all activity. With Keycard, organizations can deploy AI agents into production with complete trust, knowing they are only capable of performing the intended actions of their users and builders. “AI agents represent a once-in-a-generation shift, greater than the SaaS and cloud wave combined. But without trusted access controls, they can’t leave the lab. Keycard provides the guardrails that allow agents to act safely on behalf of people and businesses, unlocking the true potential of the agent economy,” said Ian Livingstone, CEO of Keycard. Keycard was co-founded by Ian Livingstone, Matthew Creager and Jared Hanson. Livingstone and Creager served as senior leaders at Snyk where they built the platform engineering and developer experience divisions as revenues grew from $30 million to $300 million. Hanson was the Chief Architect at Auth0 before joining Okta as a senior technical leader, and he created Passport.js, the most popular authentication framework for Node.js that is downloaded millions of times every week. At these companies, the trio witnessed how developers constantly struggled to connect services and applications together within and across organizations at enterprise scale, often leading to painful security incidents and significant product delays. This problem has only been exacerbated with AI agents. Today they spawn by the thousands and operate autonomously across systems and organizational boundaries. They need different permissions based on the task they are working on, which people and companies they are doing the task for, the resources they are accessing and who owns those resources. Existing solutions were not architected for AI agents. They were built for a world of static, human-driven point-and-click interactions and not the machine-driven dynamic, ephemeral and autonomous nature of AI agents. AI is expected to drive the creation of the greatest number of new identities with privileged and sensitive access according to CyberArk’s 2025 Identity Security Landscape. Keycard purpose-built its identity and access platform for AI agents. Its approach is dynamic, contextual and built for trust in an AI agent driven world: Keycard cryptographically proves who an agent is, who they act for and whether they are authorized backed by federated, standards-based protocols – preventing lock-in to a few centralized platforms while interoperating with leading agents from companies like Anthropic, Microsoft and OpenAI. Keycard replaces static secrets and API keys with dynamic, identity-bound and task-scoped tokens that enable the enforcement of policy that adapts to the changing trust landscape of users, systems and companies without any code changes. These tokens are tied to the agent’s attested workload identity, compute provider or device for end-to-end trust. Keycard enforces contextual access controls at runtime, giving users and companies the tools to express relationship and task-based policy using its identity-aware data model, enabling the immediate revocation of access with a single API call. Keycard operates at internet scale, designed for agentic performance expectations: dynamic, ephemeral, performance-obsessed, globally available infrastructure that models the complex mixed-identity and resource relationships of human and agent interactions, a fundamentally different design than existing solutions. Keycard provides developers with a set of SDKs they can use to build trusted agentic applications without needing to be identity or security experts, which gives security the context and feedback loops required to govern AI agents as they are developed instead of after they are in production. Keycard contributes to emerging standards including Model Context Protocol (MCP), WIMSE and OAuth extensions for agents and is the first production implementation with support for OAuth 2.1 Client ID Metadata Documents in MCP. Keycard raises $38 million to expand its AI identity platform Keycard also announced that it has raised $38 million in seed and Series A funding. Andreessen Horowitz and boldstart ventures co-led the $8 million seed round, and Acrew Capital led the $30 million Series A. Angels who participated include Ian Andrews (CRO at Groq), Ryan Carlson (president at Chainguard), Emilio Escobar (CISO at Datadog), Karl McGuinness (former Chief Product Architect at Okta) and Matias Woloski (co-founder and former CTO at Auth0). “This is the Auth0 moment for agent access. The agent ecosystem needs foundational authorization infrastructure. This team has the rare combination of infrastructure expertise and standards leadership required to build it,” said Zane Lackey, partner at Andreessen Horowitz. “Winning in agentic security takes a rare mix: build for developers and nail security from day one. Ian, Matthew and Jared did it before at Snyk and Auth0 and they’re doing it again with Keycard. We’re thrilled to back Ian and Matthew a second time (their first company was acquired by Snyk) alongside Jared. This is the team to define the identity and trust category for the agent era,” continued Ed Sim, general partner at boldstart ventures. “Trusted agents define the next chapter of computing. Developers will lead the way and need durable identity and access foundations. Keycard extends trust and control to the agent layer,” concluded Asad Khaliq, founding partner at Acrew Capital. Keycard plans to use the funding to continue to advance its identity and access platform and to expand its R&D team.
helpnetsecurity.comOct 22, 2025extracted
Chainguard Libraries for JavaScript provides developers with malware-free dependencies
Chainguard Libraries for JavaScript provides developers with malware-free dependencies Chainguard released Chainguard Libraries for JavaScript, a collection of trusted builds of thousands of common JavaScript dependencies that are malware-resistant and built from source on SLSA L2 infrastructure. By securely building every library and all of its dependencies from source, Chainguard Libraries for JavaScript provides security and engineering teams with confidence that malware has not been inserted during the build or distribution of libraries in the JavaScript ecosystem, eliminating a significant gap in the threat landscape. Demonstrated risk in the JavaScript ecosystem The risk in the JavaScript ecosystem isn’t theoretical. Earlier this month, a number of packages used by millions of developers were compromised via malicious code. These malware attacks against popular JavaScript registries like npm, which developers download billions of times per week, demonstrated the risk of relying on traditional mechanisms for language library consumption. These public registries do not guarantee all host artifacts are vetted and do not provide assurance that the distributed library matches its source code, exposing enterprises to supply chain attacks. Compounding the issue, AI has fueled a surge in JavaScript development, multiplying both the volume and complexity of dependencies — and with it, the opportunities for attackers. According to Gartner, “A source estimates costs from software supply chain attacks will rise from $46 billion in 2023 to $138 billion by 2031.” The firm also predicted that “by 2028, 85% of large enterprises will have deployed software supply chain security tools to combat these risks.” Mitigating malware attacks across JavaScript dependencies With Chainguard Libraries for JavaScript, Chainguard offers protection for the language dependencies that developers rely on to build and deploy applications. Until now, there was no way for security teams to mitigate malware at scale without disrupting engineering workflows and productivity. This gap left organizations susceptible to the risks of malicious code that could waste resources, steal application secrets, break production systems, or even leak customer data. Chainguard Libraries for JavaScript integrates with existing artifact managers, such as JFrog Artifactory and Sonatype Nexus, to empower application security teams to close this massive security hole while meeting developers how they work. As with Chainguard Libraries for Java and Python, Chainguard is building every dependency for every JavaScript library from source, combating malware injection at the build and distribution links of the open source supply chain. Isolating and rebuilding the shared system dependencies required by JavaScript libraries allows Chainguard to eliminate an additional hidden attack vector stemming from bundled software components. “Chainguard is the first to rebuild JavaScript libraries from source at scale. We are expanding on the work already completed with Chainguard Libraries for Java and Python to JavaScript, the most popular programming language in the world,” said Patrick Donahue, SVP of Product, Chainguard. “We’re rebuilding every component we publish from source so organizations can mitigate malware, have clear visibility into what exactly is in their software, and eliminate the risk of hidden supply chain vulnerabilities. Ultimately, we’re providing a secure, trusted source of JavaScript libraries that allows enterprises to remove friction and add security without asking developers to change how they build and deploy software.” Chainguard Libraries for JavaScript furthers the company’s mission to make open source software trustworthy by default and gives customers greater confidence to ship products more efficiently and securely. Chainguard now helps organizations secure even more of development stack, starting with the OS and runtime environment with minimal, zero-CVE containers and virtual machines, and up to the application layer with language libraries for Python, Java, and now JavaScript. “The recent compromises in popular npm packages highlight just how easy it still is for attackers to slip malicious code into the software supply chain. Chainguard’s approach to open source software security flips that paradigm — by rebuilding every JavaScript library from source, they will give development teams a way to eliminate common supply chain attacks and actually have a trusted source for packaged libraries. The open source community has done a herculean effort to bring software to the masses, but policing it falls to commercial entities,” said Rob Gil, Security Architect at Okta. “JavaScript has long been the backbone of modern application development, but the ecosystem’s dependency sprawl and security gaps come with risks,” explains Kate Holterhoff, senior analyst at RedMonk. “Chainguard’s decision to rebuild libraries from source addresses these risks by providing a trusted supply of JavaScript dependencies that is more able to resist malware.” Chainguard Libraries for JavaScript is now available in closed beta.
helpnetsecurity.comSep 25, 2025extracted
Watch Now: CodeSecCon – Where Software Security’s Next Chapter Unfolds (Virtual Event)
Software is moving faster than ever…and so are the threats chasing it. From AI-powered attacks to hidden risks in the software supply chain, security and development teams are being forced to solve problems they’ve never faced before. CodeSecCon 2025 took place August 12-13 and united security leaders, engineers, and DevOps pros to tackle today’s most urgent challenges and to explore the breakthroughs that could redefine how we build and protect modern applications. All sessions are now available on demand! From Unsolved Problems to Emerging Risks Even with decades of progress, application security still has unfinished business. Clinton Herget of Snyk will open the conversation on persistent gaps — from inaccurate static testing to the elusive dream of risk-based prioritization — asking whether AppSec is keeping pace with innovation or falling behind. And while open source fuels innovation, Adam La Morre of Chainguard will expose a lesser-known risk: the mismatch between published packages and their upstream source, a silent supply chain vulnerability that could affect millions of applications. Rethinking Compliance, Training, and Trust SBOMs have been hyped, criticized, and regulated. Michael Lieberman of Kusari will move beyond the debate to show how to make them actionable, turning a compliance requirement into a security asset. Shifting left is one thing, but Boomie Odumade argues that lasting security comes from teaching right. Her session will unpack how relevant, behavior-shaping training can embed security into the developer mindset. And with non-human identities already outnumbering humans in enterprise systems, Dwayne McDaniel of GitGuardian will explore how to secure this fast-growing, easily exploited attack surface. AI: The Opportunity and the Threat AI runs through much of this year’s agenda — both as a defensive tool and a new frontier for attackers. Anupam Chansarkar of Amazon will show how LLM hallucinations can create exploitable vulnerabilities, and how cross-verification can help. Nikhil Kassetty will outline a DevSecOps blueprint for embedding AI into applications without exposing new risks. David Burns of BrowserStack will explore the Model Context Protocol (MCP) and the security challenges of AI agents that can act, browse, and automate. Building Security for Scale Other sessions dive into scaling security for modern architectures: Hitesh Subnani of Amazon on code-to-cloud visibility for tighter feedback loops. Manas Sharma of Google on ML-driven database defenses that adapt in milliseconds. Vaishnavi Gudur of Microsoft on AI-powered web security that detects and stops threats in real time. CodeSecCon is a live conversation about where software security is headed, and how we can get there safely. If you’re building, defending, or governing modern applications, this is where you’ll find the strategies, tools, and peers to help you keep up. 📅 August 12–13, 2025 🌐 See the full agenda at codeseccon.com
securityweek.comAug 16, 2025extracted
Now Live: CodeSecCon – Where Software Security’s Next Chapter Unfolds (Virtual Event)
Software is moving faster than ever…and so are the threats chasing it. From AI-powered attacks to hidden risks in the software supply chain, security and development teams are being forced to solve problems they’ve never faced before. CodeSecCon 2025, taking place today and tomorrow (August 12-13), is where those problems get pulled into the light. Over two days, the free, virtual conference will unite security leaders, engineers, and DevOps pros to tackle today’s most urgent challenges and to explore the breakthroughs that could redefine how we build and protect modern applications. From Unsolved Problems to Emerging Risks Even with decades of progress, application security still has unfinished business. Clinton Herget of Snyk will open the conversation on persistent gaps — from inaccurate static testing to the elusive dream of risk-based prioritization — asking whether AppSec is keeping pace with innovation or falling behind. And while open source fuels innovation, Adam La Morre of Chainguard will expose a lesser-known risk: the mismatch between published packages and their upstream source, a silent supply chain vulnerability that could affect millions of applications. Rethinking Compliance, Training, and Trust SBOMs have been hyped, criticized, and regulated. Michael Lieberman of Kusari will move beyond the debate to show how to make them actionable, turning a compliance requirement into a security asset. Shifting left is one thing, but Boomie Odumade argues that lasting security comes from teaching right. Her session will unpack how relevant, behavior-shaping training can embed security into the developer mindset. And with non-human identities already outnumbering humans in enterprise systems, Dwayne McDaniel of GitGuardian will explore how to secure this fast-growing, easily exploited attack surface. AI: The Opportunity and the Threat AI runs through much of this year’s agenda — both as a defensive tool and a new frontier for attackers. Anupam Chansarkar of Amazon will show how LLM hallucinations can create exploitable vulnerabilities, and how cross-verification can help. Nikhil Kassetty will outline a DevSecOps blueprint for embedding AI into applications without exposing new risks. David Burns of BrowserStack will explore the Model Context Protocol (MCP) and the security challenges of AI agents that can act, browse, and automate. Building Security for Scale Other sessions dive into scaling security for modern architectures: Hitesh Subnani of Amazon on code-to-cloud visibility for tighter feedback loops. Manas Sharma of Google on ML-driven database defenses that adapt in milliseconds. Vaishnavi Gudur of Microsoft on AI-powered web security that detects and stops threats in real time. CodeSecCon is a live conversation about where software security is headed, and how we can get there safely. If you’re building, defending, or governing modern applications, this is where you’ll find the strategies, tools, and peers to help you keep up. 📅 August 12–13, 2025 🌐 See the full agenda at codeseccon.com
securityweek.comAug 12, 2025extracted
CodeSecCon 2025: Where Software Security’s Next Chapter Unfolds
Software is moving faster than ever…and so are the threats chasing it. From AI-powered attacks to hidden risks in the software supply chain, security and development teams are being forced to solve problems they’ve never faced before. CodeSecCon 2025, taking place August 12-13, is where those problems get pulled into the light. Over two days, the free, virtual conference will unite security leaders, engineers, and DevOps pros to tackle today’s most urgent challenges and to explore the breakthroughs that could redefine how we build and protect modern applications. From Unsolved Problems to Emerging Risks Even with decades of progress, application security still has unfinished business. Clinton Herget of Snyk will open the conversation on persistent gaps — from inaccurate static testing to the elusive dream of risk-based prioritization — asking whether AppSec is keeping pace with innovation or falling behind. And while open source fuels innovation, Adam La Morre of Chainguard will expose a lesser-known risk: the mismatch between published packages and their upstream source, a silent supply chain vulnerability that could affect millions of applications. Rethinking Compliance, Training, and Trust SBOMs have been hyped, criticized, and regulated. Michael Lieberman of Kusari will move beyond the debate to show how to make them actionable, turning a compliance requirement into a security asset. Shifting left is one thing, but Boomie Odumade argues that lasting security comes from teaching right. Her session will unpack how relevant, behavior-shaping training can embed security into the developer mindset. And with non-human identities already outnumbering humans in enterprise systems, Dwayne McDaniel of GitGuardian will explore how to secure this fast-growing, easily exploited attack surface. AI: The Opportunity and the Threat AI runs through much of this year’s agenda — both as a defensive tool and a new frontier for attackers. Anupam Chansarkar of Amazon will show how LLM hallucinations can create exploitable vulnerabilities, and how cross-verification can help. Nikhil Kassetty will outline a DevSecOps blueprint for embedding AI into applications without exposing new risks. David Burns of BrowserStack will explore the Model Context Protocol (MCP) and the security challenges of AI agents that can act, browse, and automate. Building Security for Scale Other sessions dive into scaling security for modern architectures: Hitesh Subnani of Amazon on code-to-cloud visibility for tighter feedback loops. Manas Sharma of Google on ML-driven database defenses that adapt in milliseconds. Vaishnavi Gudur of Microsoft on AI-powered web security that detects and stops threats in real time. CodeSecCon is a live conversation about where software security is headed, and how we can get there safely. If you’re building, defending, or governing modern applications, this is where you’ll find the strategies, tools, and peers to help you keep up. 📅 August 12–13, 2025 🌐 See the full agenda at codeseccon.com
securityweek.comAug 8, 2025extracted
Webinar: How to Stop Python Supply Chain Attacks—and the Expert Tools You Need
Python is everywhere in modern software. From machine learning models to production microservices, chances are your code—and your business—depends on Python packages you didn’t write. But in 2025, that trust comes with a serious risk. Every few weeks, we’re seeing fresh headlines about malicious packages uploaded to the Python Package Index (PyPI)—many going undetected until after they’ve caused real harm. One of the most dangerous recent examples? In December 2024, attackers quietly compromised the Ultralytics YOLO package, widely used in computer vision applications. It was downloaded thousands of times before anyone noticed. This wasn’t an isolated event. This is the new normal. Python supply chain attacks are rising fast—and your next pip install could be the weakest link. Join our webinar to learn what’s really happening, what’s coming next, and how to secure your code with confidence. Don’t wait for a breach. Watch this webinar now and take control.. What’s Really Going On? Attackers are exploiting weak links in the open-source supply chain. They’re using tricks like: Typo-squatting: Uploading fake packages with names like requessts or urlib. Repojacking: Hijacking abandoned GitHub repos once linked to trusted packages. Slop-squatting: Publishing popular misspellings before a legit maintainer claims them. Once a developer installs one of these packages—intentionally or not—it’s game over. And it’s not just rogue packages. Even the official Python container image ships with critical vulnerabilities. At the time of writing, there are over 100 high and critical CVEs in the standard Python base image. Fixing them isn’t easy, either. That’s the “my boss told me to fix Ubuntu” problem—when your app team inherits infra problems no one wants to own. It’s Time to Treat Python Supply Chain Security Like a First-Class Problem The traditional approach—“just pip install and move on”—won’t cut it anymore. Whether you’re a developer, a security engineer, or running production systems, you need visibility and control over what you’re pulling in. And here’s the good news: you can secure your Python environment without breaking your workflow. You just need the right tools, and a clear playbook. That’s where this webinar comes in. In this session, we’ll walk through: The Anatomy of Modern Python Supply Chain Attacks: What happened in recent PyPI incidents—and why they keep happening. What You Can Do Today: From pip install hygiene to using tools like pip-audit, Sigstore, and SBOMs. Behind the Scenes: Sigstore & SLSA: How modern signing and provenance frameworks are changing how we trust code. How PyPI is Responding: The latest ecosystem-wide changes and what they mean for package consumers. Zero-Trust for Your Python Stack: Using Chainguard Containers and Chainguard Libraries to ship secure, CVE-free code out of the box. The threats are getting smarter. The tooling is getting better. But most teams are stuck somewhere in the middle—relying on default images, no validation, and hoping their dependencies don’t betray them. You don’t have to become a security expert overnight—but you do need a roadmap. Whether you're early in your journey or already doing audits and signing, this session will help you take your Python supply chain to the next level. Watch this Webinar Now Your application is only as secure as the weakest import. It’s time to stop trusting blindly and start verifying. Join us. Get practical. Get secure.
thehackernews.comAug 7, 2025extracted