Skip to content
Navigation menu
Search
Powered by Algolia
Search
Log in
Create account
DEV Community
Close
#
supplychain
Follow
Hide
Posts
Left menu
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
Right menu
Print Servers and Artifact Repositories: Measuring Two Overlooked Attack Surfaces
kozhevniko
kozhevniko
kozhevniko
Follow
Sep 20
Print Servers and Artifact Repositories: Measuring Two Overlooked Attack Surfaces
#
security
#
zoomeye
#
exposure
#
supplychain
Comments
Add Comment
3 min read
One Console, Every Customer: What the N-able N-central Pre-Authentication RCE Says About RMM Concentration Risk
jeffrey
jeffrey
jeffrey
Follow
Sep 20
One Console, Every Customer: What the N-able N-central Pre-Authentication RCE Says About RMM Concentration Risk
#
vulnerabilitymanagement
#
msp
#
rmm
#
supplychain
Comments
Add Comment
3 min read
The Default Join Key That Let Attackers Mint Admin Tokens on JFrog Artifactory
yutianle
yutianle
yutianle
Follow
Sep 20
The Default Join Key That Let Attackers Mint Admin Tokens on JFrog Artifactory
#
supplychain
#
authenticationbypass
#
artifactory
#
cve202682329
Comments
Add Comment
4 min read
From Warehouses to Algorithms: How JD Logistics Builds a Technology-Driven Supply Chain
lyee blair
lyee blair
lyee blair
Follow
Sep 20
From Warehouses to Algorithms: How JD Logistics Builds a Technology-Driven Supply Chain
#
jdlogistics
#
jingdong
#
supplychain
#
ai
Comments
Add Comment
7 min read
Your coding agent installed 23 packages in a minute. Your SBOM saw zero.
Jason Miller
Jason Miller
Jason Miller
Follow
Sep 19
Your coding agent installed 23 packages in a minute. Your SBOM saw zero.
#
supplychain
#
aiagents
Comments
Add Comment
3 min read
Your Coding Agent Reads the Repository Before You Do: Configuration Injection in AI Developer Tooling
jeffrey
jeffrey
jeffrey
Follow
Sep 17
Your Coding Agent Reads the Repository Before You Do: Configuration Injection in AI Developer Tooling
#
aisecurity
#
supplychain
#
developertooling
#
appsec
Comments
Add Comment
3 min read
Two encrypted emails in twenty years
Matt Cockayne
Matt Cockayne
Matt Cockayne
Follow
Sep 18
Two encrypted emails in twenty years
#
opensource
#
security
#
signing
#
supplychain
Comments
Add Comment
5 min read
Field report: 1246 real pull requests scanned, 0 hallucinated packages confirmed
Mag Solutions
Mag Solutions
Mag Solutions
Follow
Sep 18
Field report: 1246 real pull requests scanned, 0 hallucinated packages confirmed
#
security
#
supplychain
#
opensource
#
devops
Comments
Add Comment
2 min read
Artifactory on the Internet: Measuring the Exposure Behind CVE-2026-82329
jeffrey
jeffrey
jeffrey
Follow
Sep 17
Artifactory on the Internet: Measuring the Exposure Behind CVE-2026-82329
#
zoomeye
#
exposuremanagement
#
supplychain
#
artifactory
Comments
Add Comment
4 min read
Jenkins Controller Compromise Is a Supply Chain Event: Lessons from 20 Plugin Flaws
kozhevniko
kozhevniko
kozhevniko
Follow
Sep 17
Jenkins Controller Compromise Is a Supply Chain Event: Lessons from 20 Plugin Flaws
#
security
#
jenkins
#
supplychain
#
cicd
Comments
Add Comment
4 min read
Self-Hosted CI Runners Are Shared Secrets: Threat Modelling Your Build Infrastructure
kozhevniko
kozhevniko
kozhevniko
Follow
Sep 17
Self-Hosted CI Runners Are Shared Secrets: Threat Modelling Your Build Infrastructure
#
cicd
#
supplychain
#
devops
#
runnersecurity
Comments
Add Comment
3 min read
When the Default Configuration Is the Vulnerability: JFrog Artifactory's Empty Join Key and the Supply-Chain Blast Radius
yutianle
yutianle
yutianle
Follow
Sep 16
When the Default Configuration Is the Vulnerability: JFrog Artifactory's Empty Join Key and the Supply-Chain Blast Radius
#
security
#
supplychain
#
artifactory
#
authentication
Comments
Add Comment
4 min read
An AI Chained Six Avada Flaws Into a Working Exploit in Two Hours
Jason Miller
Jason Miller
Jason Miller
Follow
Sep 15
An AI Chained Six Avada Flaws Into a Working Exploit in Two Hours
#
apiauth
#
idor
#
supplychain
#
aiagents
Comments
Add Comment
3 min read
The fastest trigger produces no CVE
Developer at Fortitude Omnis Group
Developer at Fortitude Omnis Group
Developer at Fortitude Omnis Group
Follow
Sep 14
The fastest trigger produces no CVE
#
security
#
opensource
#
devops
#
supplychain
Comments
Add Comment
3 min read
Inside the LiteLLM hack: 153GB, 433,909 Files, 2,488 Organizations
Dwayne McDaniel
Dwayne McDaniel
Dwayne McDaniel
Follow
for
GitGuardian
Sep 14
Inside the LiteLLM hack: 153GB, 433,909 Files, 2,488 Organizations
#
security
#
supplychain
#
devops
#
appsec
1
 reaction
Comments
Add Comment
4 min read
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
We're a place where coders share, stay up-to-date and grow their careers.
Log in
Create account