Dependency Surface Area 최소화를 통한 AI Supply Chain 리스크 제거
The Hidden Supply Chain Risk in Your `pip install`
The Hidden Supply Chain Risk in Your `pip install`
Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub
The 20-Minute Compromise: CI/CD Audit Guide for the TanStack Supply Chain Attack
Win11 Zero-Days, npm Supply Chain, & AI Agent Security Threats
Mini Shai-Hulud: un gusano de cadena de suministro que explotó TanStack y el ecosistema npm.
How a fake npm package made Cursor backdoor a Next.js admin route
6분 내 10개 패키지 감염시킨 CI/CD 기반 자가 전파형 공급망 공격
Cache-poisoning caper turns TanStack npm packages toxic
What now? explaining the TanStack Supply Chain Attack
pull_request_target 권한 허점을 이용한 Cache Poisoning 공격 및 공급망 침해
Checkmarx tackles another TeamPCP intrusion as Jenkins plugin sabotaged
Checkmarx tackles another TeamPCP intrusion as Jenkins plugin sabotaged
Debian의 Reproducible Builds를 통한 공급망 보안 강화 및 97% 빌드 재현성 달성
Incident CVE-2024-Yikes
Is Your Claude Code Safe From Base64? Inside 2026 AI Agent Attacks
Worm rubs out competitor's malware, then takes control
공급망 공격 방어를 위한 권한 기반 보안 모델 및 의존성 격리 전략
Supply chain npm vs PyPI: I compared both simulations and the most dangerous vector isn't what everyone thinks
Supply chain en npm vs PyPI: comparé mis dos simulaciones y el vector más peligroso no es el que todos creen
Hackers breach JDownloader website to serve malware-laced downloads