News
Opengrep SAST After One Year: Faster, Deterministic Static Analysis
5+ day, 21+ hour ago (752+ words) Your Complete Security HQ Advanced App Sec suite, built for devs. in-app runtime defense and threat detection. Real-time malware & vuln threats It's been a year since a group of security vendors: Aikido Security, Arnica, Amplify, Endor Labs, Jit, Kodem, Legit,…...
Why shadow AI risks start with fear (and banning makes them worse)
5+ day, 20+ hour ago (418+ words) Your Complete Security HQ Advanced App Sec suite, built for devs. in-app runtime defense and threat detection. Real-time malware & vuln threats This post is based on Mackenzie's conversation with Noora Ahmed-Moshe on The Secure Disclosure podcast. Listen to the full…...
Security Checklist for Git Hub Actions
6+ day, 22+ hour ago (1695+ words) Your Complete Security HQ Advanced App Sec suite, built for devs. in-app runtime defense and threat detection. Real-time malware & vuln threats Git Hub Actions has been exploited a lot in a lot of supply chain attacks lately, and workflow misconfigurations…...
Coinbase's layoffs signal a dangerous move into a vibe-coding security mess
1+ week, 3+ day ago (833+ words) Your Complete Security HQ Advanced App Sec suite, built for devs. in-app runtime defense and threat detection. Real-time malware & vuln threats Among the laundry list of problems with the tweet (including the tweet being written by AI itself), one of…...
Developer Security at Scale: A CISO's Rollout Guide
1+ week, 5+ day ago (1074+ words) Your Complete Security HQ Advanced App Sec suite, built for devs. in-app runtime defense and threat detection. Real-time malware & vuln threats Large engineering organizations like to believe their biggest problems are technical. If only someone would approve the budget for…...
Mythos-Ready Checklist
2+ week, 4+ day ago (557+ words) Your Complete Security HQ Advanced App Sec suite, built for devs. in-app runtime defense and threat detection. Real-time malware & vuln threats For the teams that want to prepare for Mythos, this is for you. In this new Mythos-Ready checklist, each…...
Mini Shai-Hulud Targets SAP npm Packages With a Bun-Based Secret Stealer
2+ week, 5+ day ago (872+ words) Your Complete Security HQ Advanced App Sec suite, built for devs. in-app runtime defense and threat detection. Real-time malware & vuln threats A new npm supply-chain compromise is targeting the SAP developer ecosystem. The affected packages we are tracking so far…...
Is Shai-Hulud Back? Compromised Bitwarden CLI Contains a Self-Propagating npm Worm
3+ week, 3+ day ago (484+ words) Your Complete Security HQ Advanced App Sec suite, built for devs. in-app runtime defense and threat detection. Real-time malware & vuln threats @bitwarden/cli@2026. 4. 0 introduced a malicious preinstall hook pointing to a new file bw_setup. js. This fires automatically on npm install…...
GPT-Proxy Backdoor in npm and Py PI turns Servers into Chinese LLM Relays
3+ week, 4+ day ago (819+ words) Your Complete Security HQ Advanced App Sec suite, built for devs. in-app runtime defense and threat detection. Real-time malware & vuln threats Both packages ship a compiled native binary as their payload carrier. The two stage 1 files are: The npm dropper…...
Glass Worm goes native: New Zig dropper infects every IDE on your machine
1+ mon, 1+ week ago (313+ words) Your Complete Security HQ Advanced App Sec suite, built for devs. in-app runtime defense and threat detection. Real-time malware & vuln threats Once loaded, the binary's first job is to find every IDE installed on the machine that supports the VS…...