Skip to content
Navigation menu
Search
Powered by Algolia
Search
Log in
Create account
Forem
Close
#
supplychain
Follow
Hide
Posts
Left menu
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
Right menu
MCPwn Is Live. We Scanned the Supply Chains of 14 MCP Servers. Here's What We Found.
Pico
Pico
Pico
Follow
May 5
MCPwn Is Live. We Scanned the Supply Chains of 14 MCP Servers. Here's What We Found.
#
security
#
mcp
#
supplychain
#
javascript
Comments
Add Comment
5 min read
One Year of Liberation Day: What the Tariff Rollout Actually Revealed About AI Infrastructure
David Aronchick
David Aronchick
David Aronchick
Follow
May 5
One Year of Liberation Day: What the Tariff Rollout Actually Revealed About AI Infrastructure
#
ai
#
infrastructure
#
supplychain
#
distributedcomputing
Comments
Add Comment
8 min read
161 verified AI package hallucinations across 8.5M indexed — open dataset
Vincenzo Rubino
Vincenzo Rubino
Vincenzo Rubino
Follow
May 4
161 verified AI package hallucinations across 8.5M indexed — open dataset
#
ai
#
security
#
supplychain
#
mcp
Comments
Add Comment
4 min read
Two Independent Attack Surfaces: Why npm Provenance Doesn't Make a Package Safe
Pico
Pico
Pico
Follow
May 4
Two Independent Attack Surfaces: Why npm Provenance Doesn't Make a Package Safe
#
npm
#
security
#
javascript
#
supplychain
Comments
Add Comment
3 min read
Two Types of npm Supply Chain Attack: What Catches Each
Pico
Pico
Pico
Follow
May 4
Two Types of npm Supply Chain Attack: What Catches Each
#
npm
#
security
#
supplychain
#
javascript
Comments
Add Comment
5 min read
certifi has 350M weekly downloads and one publisher. It handles your SSL certificates.
Pico
Pico
Pico
Follow
May 4
certifi has 350M weekly downloads and one publisher. It handles your SSL certificates.
#
python
#
security
#
supplychain
#
npm
Comments
Add Comment
4 min read
Four MCP packages, four ways the supply chain shifted in two weeks of npm monitoring
Michael Kayode Onyekwere
Michael Kayode Onyekwere
Michael Kayode Onyekwere
Follow
May 1
Four MCP packages, four ways the supply chain shifted in two weeks of npm monitoring
#
security
#
supplychain
#
mcp
#
npm
Comments
Add Comment
7 min read
Slopsquatting in Python: What 205,474 Hallucinated Package Names Mean for Your Supply Chain
Sour durian
Sour durian
Sour durian
Follow
Apr 30
Slopsquatting in Python: What 205,474 Hallucinated Package Names Mean for Your Supply Chain
#
python
#
security
#
ai
#
supplychain
Comments
Add Comment
8 min read
Hacking GitHub: From Tag Rewrites to Dangling Commits, Where the Git Protocol Trusts You Without Checking
kt
kt
kt
Follow
Apr 30
Hacking GitHub: From Tag Rewrites to Dangling Commits, Where the Git Protocol Trusts You Without Checking
#
security
#
github
#
git
#
supplychain
Comments
Add Comment
19 min read
I built chainscope: reading supply chain attacks across 6 surfaces, one slide at a time
kt
kt
kt
Follow
Apr 29
I built chainscope: reading supply chain attacks across 6 surfaces, one slide at a time
#
showdev
#
security
#
supplychain
Comments
Add Comment
7 min read
SLSA Provenance Hands-on: Generate with GitHub Actions, Verify with slsa-verifier
kt
kt
kt
Follow
Apr 29
SLSA Provenance Hands-on: Generate with GitHub Actions, Verify with slsa-verifier
#
security
#
supplychain
#
slsa
#
sigstore
Comments
Add Comment
11 min read
Why Did Docker Abandon TUF?: A Turbulent History of Container Signing
kt
kt
kt
Follow
Apr 28
Why Did Docker Abandon TUF?: A Turbulent History of Container Signing
#
security
#
docker
#
supplychain
#
sigstore
2
 reactions
Comments
Add Comment
10 min read
The power adapter was the attack
RC
RC
RC
Follow
Apr 27
The power adapter was the attack
#
hardwareimplant
#
supplychain
#
physicalsecurity
#
redteam
Comments
Add Comment
7 min read
The Anthropic SDK Looks Safe. Two of Its Transitive Dependencies Are Not.
Pico
Pico
Pico
Follow
Apr 26
The Anthropic SDK Looks Safe. Two of Its Transitive Dependencies Are Not.
#
security
#
npm
#
javascript
#
supplychain
Comments
Add Comment
3 min read
A postcard breached a warship
RC
RC
RC
Follow
Apr 27
A postcard breached a warship
#
physicalsecurity
#
iotthreats
#
redteam
#
supplychain
Comments
Add Comment
5 min read
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
We're a blogging-forward open source social network where we learn from one another
Log in
Create account