Structured data rendered for: CollectionPage
Back to Blog
8 posts in this category

supply chain attack

8 posts
Mastra npm compromise turns AI agent builds into credential-theft risk

Mastra npm compromise turns AI agent builds into credential-theft risk

Mastra npm compromise turns AI agent builds into credential-theft risk The Mastra npm incident is a sharp warning for teams building AI agents: dependency compr...

Last updated on 17/08/2026 at 12:56 PM
8 min read
Red Hat npm compromise proves provenance alone is not enough

Red Hat npm compromise proves provenance alone is not enough

Red Hat npm compromise proves provenance alone is not enough Red Hat has confirmed that multiple packages published under the @redhat-cloud-services npm namespa...

Last updated on 17/08/2026 at 12:56 PM
6 min read
GitHub breach forces GHES signing-key rotation

GitHub breach forces GHES signing-key rotation

GitHub breach forces GHES signing-key rotation | 2026 GitHub's May 2026 incident is a useful reminder that developer tooling is now part of the production trust...

Last updated on 17/08/2026 at 12:56 PM
6 min read
GitHub Action tag hijack turns CI/CD runs into credential theft

GitHub Action tag hijack turns CI/CD runs into credential theft

GitHub Action tag hijack turns CI/CD runs into credential theft A fresh GitHub Actions supply chain incident is a good reminder that "pinned" does not mean safe...

Last updated on 17/08/2026 at 12:56 PM
6 min read
Poisoned Trivy scanner led to malicious LiteLLM releases on PyPI

Poisoned Trivy scanner led to malicious LiteLLM releases on PyPI

Poisoned Trivy scanner led to malicious LiteLLM releases on PyPI | 2026 The LiteLLM incident is what modern software supply-chain compromise looks like when one...

Last updated on 25/03/2026 at 1:03 AM
5 min read
Trivy GitHub Action compromise exposed CI/CD secrets in a stealth supply-chain attack

Trivy GitHub Action compromise exposed CI/CD secrets in a stealth supply-chain attack

Trivy GitHub Action compromise exposed CI/CD secrets in a stealth supply-chain attack A supply-chain compromise in Aqua Security’s aquasecurity/trivy-action sho...

Last updated on 22/03/2026 at 7:29 AM
4 min read
Chrome Extension Supply-Chain Attack: ShotBird and QuickLens

Chrome Extension Supply-Chain Attack: ShotBird and QuickLens

Chrome Extension Supply-Chain Attack: ShotBird and QuickLens | 2026 Executive Summary ShotBird and QuickLens, two Chrome extensions that were previously legitim...

Last updated on 17/08/2026 at 12:55 PM
8 min read

Lotus Panda Chrysalis: Notepad++ Supply Chain Attack | 2026

Executive Summary Since June 2025, the Chinese state-sponsored [threat actor](https://invaders.ie/resources/glossary/advanced-persistent-threat) Lotus Panda (al...

Last updated on 17/08/2026 at 12:55 PM
7 min read