DEV Community

#supplychain

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
700 Agents, 25 Actions Each, and Nothing Fired

700 Agents, 25 Actions Each, and Nothing Fired

Comments
3 min read
The Artifact Repository Is a Trust Root: Reading the JFrog Artifactory Authentication Bypass

The Artifact Repository Is a Trust Root: Reading the JFrog Artifactory Authentication Bypass

Comments
4 min read
The Shai-Hulud npm worm showed that opening a folder is enough to run code

The Shai-Hulud npm worm showed that opening a folder is enough to run code

Comments
3 min read
Print Servers and Artifact Repositories: Measuring Two Overlooked Attack Surfaces

Print Servers and Artifact Repositories: Measuring Two Overlooked Attack Surfaces

Comments
3 min read
One Console, Every Customer: What the N-able N-central Pre-Authentication RCE Says About RMM Concentration Risk

One Console, Every Customer: What the N-able N-central Pre-Authentication RCE Says About RMM Concentration Risk

Comments
3 min read
The Default Join Key That Let Attackers Mint Admin Tokens on JFrog Artifactory

The Default Join Key That Let Attackers Mint Admin Tokens on JFrog Artifactory

Comments
4 min read
From Warehouses to Algorithms: How JD Logistics Builds a Technology-Driven Supply Chain

From Warehouses to Algorithms: How JD Logistics Builds a Technology-Driven Supply Chain

Comments
7 min read
Your coding agent installed 23 packages in a minute. Your SBOM saw zero.

Your coding agent installed 23 packages in a minute. Your SBOM saw zero.

Comments
3 min read
Your Coding Agent Reads the Repository Before You Do: Configuration Injection in AI Developer Tooling

Your Coding Agent Reads the Repository Before You Do: Configuration Injection in AI Developer Tooling

Comments
3 min read
Two encrypted emails in twenty years

Two encrypted emails in twenty years

Comments
5 min read
Artifactory on the Internet: Measuring the Exposure Behind CVE-2026-82329

Artifactory on the Internet: Measuring the Exposure Behind CVE-2026-82329

Comments
4 min read
Jenkins Controller Compromise Is a Supply Chain Event: Lessons from 20 Plugin Flaws

Jenkins Controller Compromise Is a Supply Chain Event: Lessons from 20 Plugin Flaws

Comments
4 min read
Self-Hosted CI Runners Are Shared Secrets: Threat Modelling Your Build Infrastructure

Self-Hosted CI Runners Are Shared Secrets: Threat Modelling Your Build Infrastructure

Comments
3 min read
When the Default Configuration Is the Vulnerability: JFrog Artifactory's Empty Join Key and the Supply-Chain Blast Radius

When the Default Configuration Is the Vulnerability: JFrog Artifactory's Empty Join Key and the Supply-Chain Blast Radius

Comments
4 min read
An AI Chained Six Avada Flaws Into a Working Exploit in Two Hours

An AI Chained Six Avada Flaws Into a Working Exploit in Two Hours

Comments
3 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.