Advertisement Β· 728 Γ— 90

Posts by Paul

Preview
March, 19-21: God is a comedian A stiff drink is recommended

This is an excellent summary of the US War on Iran current situation.

I’m an existentialist and borderline absurdist and even I struggle with the current moment.

This summary is just fantastic.

4 weeks ago 3198 1429 88 423

As someone deep into MCP (hello, I am one of the Core Maintainers of the protocol), what Kelsey alludes to here is 🎯

MCP completely removes the need to care about underlying API shape. Intent is what matters in a universal adapter. Behind the scenes you can use SOAP/XML for all we care.

2 months ago 59 7 6 0
Preview
Safer Docker Hub Pulls via a Sonatype-Protected Proxy | Docker Learn from Docker experts to simplify and advance your app development and management with Docker. Stay up to date on Docker events and new version

Running Docker Hub pulls at scale?

This post shows how to add a Sonatype-protected proxy to centralize policy checks, cache trusted images, and keep existing workflows intact.
Learn how β†’ https://bit.ly/4jQBm2g

2 months ago 1 1 0 0
EU Launches GCVE, A Decentralized Vulnerability Database Europe launches GCVE, a decentralized EU vulnerability database designed to reduce reliance on CVE and strengthen digital sovereignty.

New EU Vulnerability Platform GCVE Goes Live, Reducing Reliance on Global Systems

3 months ago 1 3 0 0

Framing bans as existential while treating sexual abuse as a regulatory detail is the real slippery slope. Why the digital exceptionalism - this would never be accepted in printed material. The harm was foreseeable, the safeguards were obvious, and limited action only came under pressure.

3 months ago 17 0 0 1

Comics peeps. I am finally clocking off from work tomorrow and doing my annual splurge on as many of the year's best titles as I can get my hands on. What've been your highlights of 2025? Ongoing weeklies, collected tpbs, one-off graphic novels, reissues, indies, whatever you've got.

4 months ago 31 18 21 0
Preview
Socket Firewall Now Available in Docker Hardened Images - So... Socket Firewall Free is now bundled into Docker Hardened Images, adding build-time and dependency-install supply chain protection on top of hardened b...

Read more here: socket.dev/blog/socket-...

4 months ago 4 1 1 0
Preview
The Mend.io AppSec Blog The latest news and insights on application security and securing the software supply chain. Read the Mend.io blog here.

www.mend.io/blog/

4 months ago 0 0 0 0
Preview
StepSecurity Blog | GitHub Actions Security Insights Dive deep into the world of GitHub Actions and CI/CD security with StepSecurity's blog.

www.stepsecurity.io/blog

4 months ago 0 0 1 0
Advertisement
Preview
Blog - Aikido Security Discover today's best security practices and the latest trends that your software company should be aware of. Stay ahead of the game and read Aikido's industry-leading blog today.

www.aikido.dev/blog

4 months ago 0 0 1 0
HelixGuard Supply chain security, vulnerability intelligence, and malware detection.

helixguard.ai/blog/

4 months ago 0 0 1 0
Preview
Wiz Blog | Latest stories about Cloud Security Guides, announcements, and articles about Cloud Security and the Wiz platform.

www.wiz.io/blog

4 months ago 0 0 1 0
Preview
Blog - Socket Learn about the latest security news, Socket updates and announcements.

Also in no particular order blogs that will keep you up-to-date with the latest supply chain attacks

socket.dev/blog

4 months ago 0 0 1 0
Preview
Compromises Catalog of Supply Chain Compromises This repository contains links to articles of software supply chain compromises. The goal is not to catalog every known supply chain attack, but rather to capture m...

Catalog of Supply Chain Compromises

tag-security.cncf.io/community/ca...

4 months ago 0 0 1 0
A Timeline of SSC Attacks, Curated by Sonatype View the history of software supply chain attacks, open source components analyzed by Sonatype

Good resources documenting software supply chain incidents

www.sonatype.com/resources/vu...

4 months ago 0 0 1 0
Post image

Version 1 of the OWASP AI testing guide just got published.

I promise you, from my own experience, this will save you a lot of heartache.

github.com/OWASP/www-pr...

4 months ago 42 14 0 1
Preview
GitHub - lirantal/npm-security-best-practices: Collection of npm package manager Security Best Practices Collection of npm package manager Security Best Practices - lirantal/npm-security-best-practices

Given Shai-Hulud comeback (hello SHA1-HULUD πŸ‘‹)

It is quite timely to share my up-to-date repository for modern npm security best practices against supply chain malware attacks:

4 months ago 9 4 2 0
Advertisement

Shai-Hulud Returns: Over 300 NPM packages infected via fake Bun runtime within hours

helixguard.ai/blog/malicio...

4 months ago 11 2 1 1
Post image

Troy Parrott's 96th-minute winner keeps Ireland's World Cup hopes alive!

The 23-year-old's hat-trick earns his country victory and a spot in the play-offs, breaking Hungarian hearts in the process.

Remarkable scenes in Budapest.

5 months ago 167 21 0 14
Towards a secure by default GitHub Actions Β· community Β· Discussion #179107 Why are you starting this discussion? Product Feedback What GitHub Actions topic or product is this about? Workflow Configuration Discussion Details Today, GitHub announced upcoming changes to the ...

πŸš€ GitHub is making Actions more secure by default

We recently announced upcoming changes to the pull_request_target event and environment protection rules to make GitHub Actions more secure by default.

We’ve opened a discussion to gather feedback πŸ‘‡

πŸ”— github.com/orgs/communi...

5 months ago 6 4 0 0
Introduction - OWASP Top 10:2025 RC1 OWASP Top 10:2025 RC1

The release candidate of the OWASP Top 10 2025 has been released

owasp.org/Top10/2025/0...

The definitive release should be out on November 20th

5 months ago 8 11 0 0

There's some really big caveats to this. A thread.

5 months ago 156 74 6 2
Preview
Security-Focused Prompts | Vibe Coding Framework

Just prompt it they way you like. E.g with something like this: docs.vibe-coding-framework.com/document-tem...

5 months ago 4 1 1 1
Post image

🚨 Open source supply chain attacks are exploding.

Starting today, that ends.

We’re releasing Socket Firewall β€” FREE, zero-config, CLI that blocks malware before it lands on your laptop or CI.

Just run:

npm i -g sfw
sfw npm install lodash

Works for: npm, yarn, pnpm, pip, uv, and cargo.

6 months ago 45 12 7 3

The press release is here: www.secretservice.gov/newsroom/rel...

Some images are below:

6 months ago 14 5 2 3
Advertisement
Preview
Ongoing Supply Chain Attack Targets CrowdStrike npm Packages... Socket detected multiple compromised CrowdStrike npm packages, continuing the "Shai-Halud" supply chain attack that previously hit Tinycolor and dozen...

🚨 Update: The "Shai-Hulud" supply chain attack has expanded to nearly 500 trojanized npm packages, including several from CrowdStrike, all using the same malware first seen in Tinycolor.

Full details and package list: socket.dev/blog/ongoing... #NodeJS #JavaScript

7 months ago 31 15 1 5
Preview
ctrl/tinycolor and 40+ NPM Packages Compromised - StepSecurity The popular @ctrl/tinycolor package with over 2 million weekly downloads has been compromised alongside 40+ other NPM packages in a sophisticated supply chain attack. The malware self-propagates across maintainer packages, harvests AWS/GCP/Azure credentials using TruffleHog, and establishes persistence through GitHub Actions backdoors - representing a major escalation in NPM ecosystem threats.

#NPM:The popular @ctrl/tinycolor package with over 2mln weekly downloads has been compromised alongside 40+ other NPM packages (including Crowdstirke packages!) in a sophisticated supply chain attack:
#SoftwareSupplyChainSecurity
πŸ‘‡

7 months ago 0 1 0 0

Hi everyone. The 'next day' busy-ness has fully set in.

Since I still haven't gotten any followup from npm regarding account actions taken, and given that I have now been approached by authorities, I will need to hold off on the post-mortem for a day or two.

Sincerest apologies for the delay.

7 months ago 29 3 3 0

🚨URGENT: A series of popular packages maintained by qix have just been compromised.

Compromised packages include:
β€’ has-ansi - 12 million weekly downloads - V6.0.1
β€’ supports-hyperlinks - 19m weekly downloads - v4.1.1
β€’ chalk-template - 3.9m weekly downlaods - V1.1.1

7 months ago 5 4 1 1