Categories

Subscribe to Feed

Latest Posts

Showing 0 Items

Runtime Security for AWS CodeBuild-Hosted GitHub Actions Runners

Harden-Runner now secures GitHub Actions jobs running on AWS CodeBuild-hosted runners, on EC2 compute, with managed or custom images.

Introducing deny list egress policies for Harden-Runner

A new denied-endpoints input blocks the destinations you name and leaves everything else reachable. Here is why that matters, and how to use it to stop CI from bypassing your package proxy

openapi-react-query-codegen compromised through an exposed npm publishing workflow

@7nohe/openapi-react-query-codegen Compromised Through an Exposed npm Publishing Workflow

An external GitHub user exploited an exposed npm publishing workflow for @7nohe/openapi-react-query-codegen and shipped ten malicious versions that run attacker code during installation.

Dev Machine Guard Now Inventories Browser Extensions on Developer Machines

Dev Machine Guard now inventories browser extensions across your developer fleet. See every extension installed in Chrome, Edge, and Firefox, what each one is currently permitted to do, whether it came from a marketplace or was installed some other way, and which devices are running it.

Dev Machine Guard Now Inventories Where Developer Credentials Live

Dev Machine Guard now inventories where developer tools keep credentials. See which credential sources are in use across your fleet, how many devices each one affects, and how much of that material is sitting in plaintext. Credential values, fragments, hashes, and fingerprints are never stored, displayed, or sent off the device.

The State of Open Source Supply Chain Attacks

56 supply chain attacks in 12 months, each with a StepSecurity Threat Center alert. The data, the worms, the Team PCP numbers, and how to defend.

Rust Supply-Chain Attack: arrayref, internment, and append-only-vec Poisoned by the proc-macro1 Build-Time Dropper

A compromised maintainer account and a same-day impersonator of one of Rust's best-known authors turned a routine cargo update into silent remote code execution. Three crates from the same owner were poisoned in 23 minutes (arrayref, internment, and append-only-vec), alongside six attacker-owned crates now deleted from crates.io. The malicious releases are gone, but the 07:11–09:25 UTC exposure window leaves an open question: who built during it? Verified timeline, IOCs, runtime detection, and remediation inside.

Team PCP CI/CD secrets heist: 78,330 secrets exfiltrated from the CI/CD pipelines of 2,186 organizations in five days, per the CloudSEK disclosure

Team PCP Stole 78,330 Secrets From 2,186 Organizations. CloudSEK Just Published the List.

CloudSEK has published the victim list from Team PCP's supply chain campaign: 78,330 secrets exfiltrated from the CI/CD pipelines of 2,186 organizations over five days in March 2026. StepSecurity's research team has tracked this threat actor across the Trivy, telnyx, and LiteLLM compromises. Here is how the campaign works, why CI/CD pipelines are the target, and the layered controls that stop it.

There are no blog posts matching your criteria at this time.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.