All topics

supply-chain

43 pieces of writing

OpenAI's Hugging Face incident was not an AI escape story. It was a sandbox failure.
security12 min read

OpenAI's Hugging Face incident was not an AI escape story. It was a sandbox failure.

OpenAI and Hugging Face disclosed an AI cyber-evaluation incident with real security impact. The useful lesson is not that AI escaped, but that eval sandboxes need hard containment.

security10 min read

Trivy turned a security scanner into a credential stealer

security12 min read

AI agents turned poisoned repositories and obfuscated code into supply-chain execution paths

security13 min read

Amazon Q, Claude Code and MCP made repository text a supply-chain attack surface

AI-assisted development tools changed the supply-chain boundary: repository text, hidden prompts and tool descriptions can now steer agents toward code execution, secret theft and data exfiltration.

security13 min read

PCPJack, polyfill CDN and Bright Data SDK show supply chain attacks moving into runtime weaponisation

MCP OAuth token persistence turns AI orchestration into a supply-chain trust boundary
security13 min read

MCP OAuth token persistence turns AI orchestration into a supply-chain trust boundary

security13 min read

May 2026 developer-tooling compromises: VS Code extensions, PyPI packages and GitHub Actions turned workstations into supply-chain targets

May 2026 supply-chain compromises showed that poisoned developer tooling now targets the identity and execution layer before code reaches a repository.

GitHub Actions OIDC and TanStack show why 2026 supply chain attacks target release authority
security11 min read

GitHub Actions OIDC and TanStack show why 2026 supply chain attacks target release authority

Checkmarx KICS, npm Bitwarden CLI and GlassWorm show developer trust is the supply chain target
security14 min read

Checkmarx KICS, npm Bitwarden CLI and GlassWorm show developer trust is the supply chain target

Vercel breached through a compromised Context.ai OAuth grant
security10 min read

Vercel breached through a compromised Context.ai OAuth grant

A compromised AI productivity tool called Context.ai gave attackers OAuth access to a Vercel employee's Google Workspace, pivoting into internal systems. The AI tool supply chain is the new CI/CD supply chain.

From tj-actions to LiteLLM to MCP: supply chain compromise now operates at infrastructure scale
security9 min read

From tj-actions to LiteLLM to MCP: supply chain compromise now operates at infrastructure scale

Anthropic shipped its entire source code to npm and the internet kept it forever
security10 min read

Anthropic shipped its entire source code to npm and the internet kept it forever

Environment variables are the new command line: how AI agents keep leaking secrets through configuration files
security12 min read

Environment variables are the new command line: how AI agents keep leaking secrets through configuration files

AI agent frameworks and deployment tools keep shipping the same environment variable injection patterns that operational tooling solved years ago. The gptme fix was one project. The pattern is everywhere.

TeamPCP compromised the AI proxy that holds everyone's API keys
security9 min read

TeamPCP compromised the AI proxy that holds everyone's API keys

Git tags, package registries and extension marketplaces share the same broken authentication model
security12 min read

Git tags, package registries and extension marketplaces share the same broken authentication model

Weekly digests