Skip to content
Navigation menu
Search
Powered by Algolia
Search
Log in
Create account
DEV Community
Close
#
supplychain
Follow
Hide
Posts
Left menu
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
Right menu
Trivy Project Compromised by Malicious Supply Chain Attack: Enhanced CI/CD Security Measures Proposed
Marina Kovalchuk
Marina Kovalchuk
Marina Kovalchuk
Follow
Mar 25
Trivy Project Compromised by Malicious Supply Chain Attack: Enhanced CI/CD Security Measures Proposed
#
cybersecurity
#
supplychain
#
cicd
#
malware
Comments
Add Comment
12 min read
LiteLLM 1.82.7 and 1.82.8: Critical Security Compromise Exposed – How to Protect Your AI Projects
Arkaprabha Banerjee
Arkaprabha Banerjee
Arkaprabha Banerjee
Follow
Mar 25
LiteLLM 1.82.7 and 1.82.8: Critical Security Compromise Exposed – How to Protect Your AI Projects
#
security
#
artificialintelligen
#
python
#
supplychain
Comments
Add Comment
4 min read
When Your LLM Proxy Becomes the Attack Vector
Wu Long
Wu Long
Wu Long
Follow
Mar 24
When Your LLM Proxy Becomes the Attack Vector
#
security
#
ai
#
python
#
supplychain
Comments
Add Comment
3 min read
The Comforting Lie Of SHA Pinning
Aiden Vaines
Aiden Vaines
Aiden Vaines
Follow
Mar 24
The Comforting Lie Of SHA Pinning
#
thoughtleadership
#
security
#
supplychain
#
githubactions
Comments
Add Comment
5 min read
How to Detect and Recover From a Compromised PyPI Package
Alan West
Alan West
Alan West
Follow
Mar 25
How to Detect and Recover From a Compromised PyPI Package
#
python
#
security
#
supplychain
#
pypi
Comments
Add Comment
5 min read
The Attack Cost Escalation Model: Why Physical Security Changes Adversary Economics
Kalyan Tamarapalli
Kalyan Tamarapalli
Kalyan Tamarapalli
Follow
Mar 23
The Attack Cost Escalation Model: Why Physical Security Changes Adversary Economics
#
security
#
cybersecurity
#
devops
#
supplychain
Comments
Add Comment
3 min read
Ataque Ă Cadeia de Suprimentos: O Pacote NPM Que Pode Derrubar Sua Empresa
Gabriel Lima Ferreira
Gabriel Lima Ferreira
Gabriel Lima Ferreira
Follow
Mar 23
Ataque Ă Cadeia de Suprimentos: O Pacote NPM Que Pode Derrubar Sua Empresa
#
supplychain
#
npm
#
devsecops
#
sca
Comments
Add Comment
2 min read
Agent Skill Marketplace Vulnerable to Supply Chain Attacks: Standardized Security Scanning Proposed
Ksenia Rudneva
Ksenia Rudneva
Ksenia Rudneva
Follow
Mar 22
Agent Skill Marketplace Vulnerable to Supply Chain Attacks: Standardized Security Scanning Proposed
#
security
#
github
#
ai
#
supplychain
Comments
Add Comment
14 min read
Add Real-Time Supply Chain Risk Data to Your AI Agent in 60 Seconds
Scott Sage
Scott Sage
Scott Sage
Follow
Mar 22
Add Real-Time Supply Chain Risk Data to Your AI Agent in 60 Seconds
#
mcp
#
ai
#
supplychain
#
opensource
Comments
Add Comment
2 min read
ONNX `silent=True` Disables Security Checks, Exposing ML Models to Supply Chain Attacks: Solution Needed
Ksenia Rudneva
Ksenia Rudneva
Ksenia Rudneva
Follow
Mar 21
ONNX `silent=True` Disables Security Checks, Exposing ML Models to Supply Chain Attacks: Solution Needed
#
onnx
#
security
#
machinelearning
#
supplychain
Comments
Add Comment
11 min read
Trivy Vulnerability Scanner Compromised in Supply Chain Attack: Mitigation Steps and User Guidance
Marina Kovalchuk
Marina Kovalchuk
Marina Kovalchuk
Follow
Mar 21
Trivy Vulnerability Scanner Compromised in Supply Chain Attack: Mitigation Steps and User Guidance
#
cybersecurity
#
supplychain
#
opensource
#
vulnerability
1
 reaction
Comments
Add Comment
8 min read
Evidence Stores for Supply Chain Security
Pavel
Pavel
Pavel
Follow
Mar 20
Evidence Stores for Supply Chain Security
#
tooling
#
security
#
supplychain
#
evidence
Comments
Add Comment
3 min read
Trivy Scanner Compromised Again: Malicious Code Found in v0.69.4 and GitHub Actions, Raising Security Concerns
Marina Kovalchuk
Marina Kovalchuk
Marina Kovalchuk
Follow
Mar 20
Trivy Scanner Compromised Again: Malicious Code Found in v0.69.4 and GitHub Actions, Raising Security Concerns
#
security
#
supplychain
#
opensource
#
vulnerability
Comments
Add Comment
8 min read
Your AI Agent Has a Supply Chain. Nobody Is Auditing It.
ArkForge
ArkForge
ArkForge
Follow
Mar 16
Your AI Agent Has a Supply Chain. Nobody Is Auditing It.
#
security
#
agents
#
supplychain
#
auditability
1
 reaction
Comments
Add Comment
5 min read
The Global Chip Supply Chain's Hidden Weakness Isn't Silicon. It's Helium.
Kunal
Kunal
Kunal
Follow
Mar 14
The Global Chip Supply Chain's Hidden Weakness Isn't Silicon. It's Helium.
#
semiconductors
#
supplychain
#
geopolitics
#
manufacturing
Comments
1
 comment
6 min read
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
We're a place where coders share, stay up-to-date and grow their careers.
Log in
Create account