
.avif)
News

The CVE spike across major software companies is a remediation problem
CVE volume is climbing across major software companies, and a federal audit shows even NIST couldn't keep up. Here's why remediation speed, not disclosure count, is the number that actually matters.
Cyber Resilience Act is here! Myth busting and first impressions
The Cyber Resilience Act's first deadline just came up on September 11, 2026. What the new Single Reporting Platform looks like, and four common CRA myths debunked.
The CVE spike across major software companies is a remediation problem
CVE volume is climbing across major software companies, and a federal audit shows even NIST couldn't keep up. Here's why remediation speed, not disclosure count, is the number that actually matters.
The dark figure of supply chain detection
String-based rules only catch malware that's already been seen. Behavioral detection is how you find the supply chain attacks.
Good riddance, TeamPCP. Now for the hard part.
The AFP, FBI, and WA Police charged two men allegedly behind TeamPCP. Charlie Eriksen on why the arrest doesn't close the gap TeamPCP exposed.
Software supply chain security requires decisions rather than defaults
Most software runs on decisions nobody made. We talk about why gating, pinning, backporting, and SBOM upkeep only work if someone actually owns them.
Shai-Hulud was the best thing to happen to supply chain security
npm Trusted Publishing sat near-idle after it was released. Then Shai-Hulud and 14 more supply chain attacks pushed adoption 3.4x. Charlie looks at the data behind it.
From Hugging Face to Fable: this summer shows AI control matters more than trust
An autonomous AI breach at Hugging Face and Anthropic's Fable suspension show the same thing: trusting a vendor isn't the same as being in control
What is AI harness engineering?
Harness engineering is the code around an AI model that turns it into an agent. What a harness does, why it beats picking a model, and how to build one.
Who was behind the attack? Possibly nobody
Three summer disclosures documented AI agents attacking real organizations with no human intent in the chain. Incident response has no box for this yet.
Four incident-response decisions from the Hugging Face breach
Recon, stolen credentials, hidden C2, and rebuild-or-patch. Four Hugging Face breach decisions that show whether you can catch an attack in progress.
Get secure now
Secure your code, cloud, and runtime in one central system.
Find and fix vulnerabilities fast automatically.



.png)