AISnyk Finds Prompt Injection in 36%, 1467 Malicious Payloads in a ToxicSkills Study of Agent Skills Supply Chain CompromiseFebruary 5, 2026
AIServiceNow's Virtual Agent Vulnerability Shows Why AI Security Needs Traditional AppSec FoundationsJanuary 14, 2026
AIBeyond Detection: Building a Resilient Software Supply Chain (Lessons from the Shai-Hulud Post-Mortem)January 8, 2026
Vulnerability InsightsSecurity Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)December 3, 2025
Application SecurityMaintainers of ESLint Prettier Plugin Attacked via npm Supply Chain MalwareJuly 22, 2025
Vulnerability InsightsReconstructing the TJ Actions Changed Files GitHub Actions CompromiseMarch 17, 2025
Application SecurityVulnerability vs Weakness: Understanding Key Differences in AppSecNovember 17, 2023
Vulnerability InsightsWeak Hash vulnerability discovered in crypto-js and crypto-es (CVE-2023-46233 & CVE-2023-46133)October 25, 2023
Vulnerability InsightsFind and fix HTTP/2 rapid reset zero-day vulnerability CVE-2023-44487October 11, 2023
Vulnerability InsightsHow to find and fix Critical WebP zero-day vulnerability CVE-2023-4863October 5, 2023
Vulnerability InsightsHigh severity vulnerability found in libcurl and curl (CVE-2023-38545)October 4, 2023
Supply Chain SecurityCritical WebP 0-day security CVE-2023-4863 impacts wider software ecosystemSeptember 28, 2023