Rust: arrayref, internment and append-only-vec Ran Malware at Build Time
Three compromised crates.io releases executed a malicious build script. Understand the 86–107 minute window, Cargo cache, lockfiles, CI and response.
Risk across dependencies, packages, suppliers and CI/CD, with practical ways to verify provenance, integrity and the organisational impact of change.
Three compromised crates.io releases executed a malicious build script. Understand the 86–107 minute window, Cargo cache, lockfiles, CI and response.
CVE-2026-73623–73625 bypass option controls through templates, diff output and kwarg value smuggling. We examine the fixes and CI exposure.
OIDC client flaws allowed discovery redirects, verifier-cache poisoning and ServiceAccount token disclosure. Fulcio 1.8.6 fixes all three paths.
The archived cloudflare/pages-action is vulnerable in every release and will not be patched. Migration to wrangler-action also requires tighter tokens.
A 32-bit integer wrap corrupts the shared CSPRNG pool offset. Later IDs can become a constant string, so updating alone may not complete the response.
A small HDF5 file can declare petabytes of data and stop load_model(). We examine the patch, model supply-chain risk and layered defensive controls.
Compromised TrueConf servers distributed a client containing the PhantomPxPigeon backdoor. We examine supply-chain trust, code signing and response.
An evil-twin campaign in Open VSX used lookalike names and extension code to harvest developer workstation data. Here is the mechanism and IDE supply-chain response.
Malicious JavaScript from Adform's advertising domain could replace BTC, ETH and TRON addresses in clipboards and forms. We analyse the supply-chain risk.
Malicious takeovers of orphaned AUR packages forced a temporary block on adoption and pushes. We analyse the loader, stealer, SSH worm and safeguards.
Bitsight found firmware-bundled apps that spoofed TV boxes as phones, clicked ads and sold the owner's connection as a SOCKS5 residential proxy.
Amazon attributes the debug, chalk, axios and typo-crypto incidents to a DPRK-linked actor with medium confidence. We assess the evidence.
The FCC added foreign-produced robots and connected inverters to its Covered List. We explain the scope, exceptions and technical risk.
Two Joyfill prereleases contained a RAT loaded on module import. We explain the blockchain C2 resolver, exposure evidence and response plan.
Learn what an SBOM is, how CycloneDX and SPDX differ, where VEX fits, which minimum elements matter and how to build a trustworthy CI/CD process.
AI found hundreds of potential flaws across major open-source projects, but triage, reproduction, safe patches and maintainer review remain essential.
Signing without key management (Sigstore) and verifiable build provenance (SLSA) are the new supply chain defense. We translate Fulcio, Rekor, cosign and SLSA levels.
A single dependency can compromise thousands of companies at once. We explain how supply chain attacks work and how to limit dependency risk.
Your security ends at your weakest supplier. How to assess contractor risk, what to put in contracts and how to monitor suppliers efficiently.
Pickle, SafeTensors, ONNX, and AI checkpoints explained: prevent code execution and build a controlled, verifiable model supply-chain pipeline.
In May 2026 the Mini Shai-Hulud worm hit npm and PyPI at once, stealing CI/CD secrets. We analyse the attack and how to harden your pipeline.
Technical analysis of the March 2026 supply-chain wave: hijacked Trivy and KICS tags, LiteLLM .pth execution, axios, CI/CD secrets and recovery.
In autumn 2025 the Shai-Hulud worm infected hundreds of npm packages, spreading itself. We analyse the supply chain attack and how to secure your pipeline.
In 2025, stolen OAuth tokens from Salesloft exposed hundreds of firms' Salesforce data — with no cracked passwords. A lesson on integration risk.
We turn current threats into role-based training, safe exercises and a clear reporting path. The free Academy remains available for self-directed learning.