Codecov Breach: The CI Script That Leaked Build Secrets for Months

A tampered Codecov Bash Uploader quietly shipped CI environment variables — cloud keys, tokens, signing material — to attackers for two months. The curl-pipe-bash trust model dissected, and how build supply-chain security was rewritten after.

Continue ReadingCodecov Breach: The CI Script That Leaked Build Secrets for Months

Dependency Confusion: How a Researcher Hacked Apple and Microsoft

No exploits, no stolen credentials — Alex Birsan’s February 2021 research got code executed inside 35+ major companies by registering their internal package names on public registries and letting version arithmetic do the rest. The incident file on the cheapest supply-chain attack ever demonstrated.

Continue ReadingDependency Confusion: How a Researcher Hacked Apple and Microsoft

SolarWinds SUNBURST: Inside the Supply-Chain Attack That Rewrote Security

The full incident file on the SolarWinds SUNBURST supply-chain attack: how SVR-linked actors compromised the Orion build pipeline, trojanized signed updates reaching 18,000 customers, hand-picked under 100 targets including nine US federal agencies, and forged SAML tokens to persist. Includes the technical anatomy, timeline, impact numbers, and the build-pipeline hardening lessons that still define defender programs in 2026.

Continue ReadingSolarWinds SUNBURST: Inside the Supply-Chain Attack That Rewrote Security
Read more about the article AST07 & AST08: Update Drift and Weak Scanning
OWASP Agentic Skills Top 10 series cover (cover_p7.png)

AST07 & AST08: Update Drift and Weak Scanning

The two post-deployment risks in the OWASP Agentic Skills Top 10: AST07 malicious updates riding channels with no signatures, pinning or freeze mode (40,000 exposed instances in 24 hours), and AST08 scanners that structurally lag base64, zero-width, pure-natural-language and .pyc evasion. Digest pinning, PASS/FAIL/INCOMPLETE pipelines, and Unicode strip ranges — dissected.

Continue ReadingAST07 & AST08: Update Drift and Weak Scanning
Read more about the article The Pipeline Is the Attack: AST02 Skill Supply Chain Compromise, Explained
OWASP Agentic Skills Top 10 series cover (cover_p3.png)

The Pipeline Is the Attack: AST02 Skill Supply Chain Compromise, Explained

AST02 of the OWASP Agentic Skills Top 10 maps attacks on the skill distribution layer: registry flooding, dependency confusion, config files that execute on clone (CVE-2025-59536, CVE-2026-21852), and maintainer takeover. With Trail of Bits' evidence that every marketplace scanner can be bypassed.

Continue ReadingThe Pipeline Is the Attack: AST02 Skill Supply Chain Compromise, Explained
Read more about the article Agent Skills Are the New npm: OWASP Agentic Skills Top 10 Explained
OWASP Agentic Skills Top 10 series cover (cover_p1.png)

Agent Skills Are the New npm: OWASP Agentic Skills Top 10 Explained

The OWASP Agentic Skills Top 10 maps the 10 risks of the AI-agent skill ecosystem - malicious skills, supply chain compromise, over-privileged manifests, metadata attacks, weak isolation, update drift, scanning gaps, governance failures and cross-platform reuse - with real 2026 evidence.

Continue ReadingAgent Skills Are the New npm: OWASP Agentic Skills Top 10 Explained