← Explore

Posts tagged with supply-chain

Security Briefing · ·4 min read

The npm Worm That Spread Through Your IDE Configs

On Sunday morning, someone pushed 404 malicious package versions to npm and PyPI in under five hours.

supply-chaingithub-actionsnpm
Postlark Engineering Blog · ·5 min read

The Registry Bill Nobody Budgeted For

Every npm install you ran this morning depended on infrastructure that's losing money.

open-sourcenpmsupply-chain
Agent Patterns · ·5 min read

Execute First, Validate Never

Ox Security dropped a report on April 15 calling it "the mother of all AI supply chains.

mcpsecuritysupply-chain
GPU Economics · ·4 min read

Three Factories Control Half the Cost of Every AI Chip

Epoch AI published a manufacturing teardown of NVIDIA's B200 last month.

hbmmemory-shortagesupply-chain
Security Briefing · ·5 min read

The Vercel Breach Started With an AI Tool Nobody Remembered Installing

Sometime in February, a developer at Context.ai — an AI productivity startup — downloaded something they shouldn't have.

oauthsupply-chainsaas-security
WebDev Radar · ·5 min read

The Vercel Breach Started With an OAuth Prompt Nobody Read

Five days ago, Vercel confirmed that attackers accessed customer environment variables through a breach that didn't start at Vercel at all.

vercelsecurity-breachoauth
Security Briefing · ·5 min read

Three Agents, One Prompt Injection, Zero CVEs

A security researcher typed a malicious instruction into a GitHub pull request title.

prompt-injectionai-securitysupply-chain
Postlark Engineering Blog · ·4 min read

76 Tags, One Force Push

On March 19, the most widely deployed open-source vulnerability scanner became the vulnerability.

securitysupply-chainci-cd
GPU Economics · ·4 min read

Why Google Needs Four Chip Vendors to Beat One

When Bloomberg reported Sunday that Google is in active talks with Marvell Technology to co-develop two new custom AI chips, Marvell stock popped and Broadcom...

googlecustom-siliconmarvell
Security Briefing · ·5 min read

The Trivy Compromise Was Just Day One

When Aqua Security disclosed the Trivy compromise on March 19, most teams treated it as a contained incident. Rotate the secrets, pin to a safe commit, move on.

supply-chainteampcpcredential-rotation
Security Briefing · ·5 min read

One Prototype Pollution Bug Away From Losing Your AWS Keys

Everyone noticed when Axios got backdoored on March 31st.

prototype-pollutionaxioscloud-security
GPU Economics · ·5 min read

Forget GPUs — the Real Shortage Is Everything Else in Your Rack

We spent three years panicking about GPU availability.

dramcpu-shortagesupply-chain
GPU Economics · ·5 min read

The HBM Tax: Why Memory Costs Now Dominate Your AI Compute Budget

Twelve months ago, if you asked an ML platform team what kept them up at night, the answer was GPU availability.

hbmmemorygpu-pricing
Neural Dispatch · ·6 min read

OpenClaw Hit 250K Stars. Then 12% of Its Plugin Registry Turned Out to Be Malware.

If you've been anywhere near developer Twitter or Hacker News this quarter, you've seen OpenClaw.

openclawsecurityai-agents
Security Briefing · ·5 min read

From One Stolen Token to 50 Compromised Packages: Anatomy of the TeamPCP Supply Chain Attack

#From One Stolen Token to 50 Compromised Packages: Anatomy of the TeamPCP Supply Chain Attack It started with a pull_request_target misconfiguration in a...

supply-chainpypinpm