Definition
Security practices protecting software supply chains from dependency tampering, malicious packages, and CI/CD compromise. Related to supply-chain-attacks.
Recent Developments
-
2026-08-04: Active shai-hulud-worm incident reinforces install-script hygiene, lockfile audit, credential rotation; runtime defenses (runtime-exploit-blocking) rise in parallel (2026-08-04-npm-shai-hulud-keyv-supply-chain-attack)
-
2026-07-14: untrusted-search-path RCE in Cursor via planted
git.exe -
2026-06-30: guardfall — adversa-ai structural shell guard bypass in 10/11 open-source coding-agents; decades-old Bash tricks defeat regex denylists after guard approval (2026-06-30-adversa-ai-bash-tricks-coding-agents)
-
2026-06-30: oracle CVE-2026-46817 — CVSS 9.8 active exploitation in EBS Payments;
/OA_HTML/ibytransmitendpoint (defused-cyber, 2026-06-30-oracle-ebs-cve-2026-46817-active-exploitation) -
2026-06-24: gemini-cli CVE-2026-12537 — CVSS 10.0 RCE via malicious
.gemini/.envon headless CI; ai-agent-ci-security (2026-06-29-google-gemini-cli-cve-2026-12537, novee-security research) -
2026-06-25: akrites — linux-foundation industry SIRT for coordinated OSS vulnerability disclosure as AI accelerates discovery (2026-06-25-linux-foundation-akrites-open-source-security)
-
2026-06-25: mozilla-0din PoC — clean GitHub repos trick coding-agents into reverse shells via DNS TXT payloads (2026-06-27-mozilla-0din-claude-code-github-malware)
-
2026-06-27: dirtyclone (CVE-2026-43503) — Linux kernel LPE bypassing dirtyfrag mitigations (jfrog)
-
2026-06-26: amazon-q-developer CVE-2026-12957 — MCP workspace config auto-execution; AWS credential theft
-
2026-06-25: langflow CVE-2026-33017 — unauthenticated RCE on self-hosted AI pipelines
-
2026-06-23: cordyceps — systemic github-actions CI/CD vulnerability class; 300+ exploitable chains at major OSS projects (2026-06-25-novee-cordyceps-github-actions-supply-chain)
-
2026-06-22: patch-the-planet — openai + trail-of-bits AI-assisted OSS patching with human review; Python, Go, cURL, PyPI, Linux kernel in scope; 64 PRs week one (2026-06-22-openai-patch-the-planet-oss-security)
-
2026-06-23: apple acquired swift-package-index — package signing roadmap addresses Swift supply chain trust