Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
2026 Mid-Year Update: On Pace for Our Biggest Year Yet
1+ day, 12+ hour ago (590+ words) Six months ago, in our 2025 year-in-review, we shared that StepSecurity had grown ARR more than 5x for the second consecutive year, repeating the milestone we first announced in our 2024 year-in-review. We also committed to an ambitious 2026 roadmap: secure the developer machine,…...
How Aerospike Moved from Reactive to Proactive CI/CD Security with StepSecurity
2+ day, 12+ hour ago (537+ words) Aerospike is the operational database that keeps applications predictable, even as conditions change, powering some of the world's largest enterprises. As a member of the leadership team, I oversee strategic decisions around how we build, secure, and scale our engineering…...
SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor
6+ day, 9+ hour ago (755+ words) The releases were published straight to the registry with no matching commit or tag in the source projects. Two of the gems had been dormant for years before suddenly shipping new versions. StepSecurity ran every compromised version inside Harden-Runner in…...
Harden-Runner Block Mode Now Available for macOS and Windows GitHub-Hosted Runners
1+ week, 3+ day ago (338+ words) Until now, Harden-Runner could answer "no" on Linux GitHub-hosted runners with egress-policy: block. On macOS and Windows GitHub-hosted runners, teams had audit mode: full visibility into outbound traffic, but no enforcement. With Harden-Runner v2.20.0, block mode is now supported on macOS…...
Introducing Device Policy: Enforce Approved VS Code Extensions Across Your Fleet
1+ week, 3+ day ago (555+ words) The pattern is consistent: extensions run with the developer's privileges, and anyone on the team can install anything the marketplace offers. Most security teams have no control over that decision. Last year, Dev Machine Guard gave you visibility into every…...
Runtime Security for Third-Party GitHub Actions Runners: Bitrise, Blacksmith, Depot, Namespace, and Warp
1+ week, 3+ day ago (410+ words) Supply chain attacks do not check your runs-on label. When the Sha1-Hulud worm compromised prominent npm packages, the malicious code executed wherever npm install ran. When the Velora DEX SDK compromise dropped a macOS backdoor through npm, it did not…...
Announcing Dependabot Configuration Enhancements: Cooldown and Group Support
1+ week, 4+ day ago (826+ words) StepSecurity now supports cooldown and group attributes for Dependabot configuration management. These additions give organizations precise control over how dependency updates are batched and how frequently they arrive, across npm, pip, Docker, GitHub Actions, and other Dependabot supported ecosystems. A…...
Coordinated AsyncAPI Supply Chain Attack: Miasma RAT Delivered via Compromised CI/CD Pipelines in Two Repositories
1+ week, 4+ day ago (596+ words) The attacker pushed a series of commits between 07:51 and 08:28 UTC. The key events: We ran the payload chain in a monitored, isolated GitHub Actions job wrapped with Harden-Runner to capture the actual runtime network behavior of the second-stage sync.js…...
jscrambler npm package publishes malicious preinstall binary
2+ week, 8+ hour ago (595+ words) If you installed jscrambler 8.14.0: Treat the host as compromised. Downgrade to 8.13.0, rotate every credential that was logged into a browser on that machine, and audit any crypto wallet browser extensions for unauthorized activity. jscrambler is the official npm CLI for…...
Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised
1+ mon, 18+ hour ago (377+ words) The following 20 packages are confirmed malicious at the listed versions. All were published simultaneously by an unauthorized actor who gained access to the Leo Platform maintainer credentials. On June 3, 2026 we published a detailed technical analysis of the Miasma campaign, which…...