Announcements, technical notes, and occasional commentary from our team.

Continuous Adversarial Security

The annual penetration test has a quiet problem: it's a snapshot of an environment that never stops moving. By the time the report is bound and delivered, a …

Published
CommentaryCompany news

Cordyceps Flaw Leads to Supply Chain Attack

It's been almost a week since this dropped, but it's too good an example to skip: another reminder that the automation we trust to build and ship our …

Published
CommentarySupply chain

node-ipc Backdoor Targets Developer and Cloud Credentials

Three versions of the widely used npm package node-ipc were confirmed malicious this week by researchers at Socket and StepSecurity.

Published
Supply chain

RubyGems Registry Attack: 500+ Malicious Packages Pulled

RubyGems temporarily suspended new account registrations on May 12 after a coordinated spam-publishing campaign pushed over 500 malicious packages through newly registered accounts.

Published
CommentarySupply chain

AI Deletes PocketOS Database

Cursor, running Anthropic's Claude Opus 4.6, autonomously decided to resolve a credential mismatch by deleting PocketOS's production database and all volume-level backups via a single Railway API call.

Published
Commentary

PAN-OS Vulnerability Exploited in the Wild

The flaw allows an unauthenticated remote attacker to trigger an out-of-bounds write via specially crafted network packets, leading to arbitrary code execution with root privileges on the affected …

Published
Vulnerability

Copy Fail Linux Kernel Vulnerability

Cybersecurity researchers at Xint.io and Theori have disclosed a high-severity Linux local privilege escalation (LPE) vulnerability.

Published
Vulnerability

NIST NVD Changes

NIST has announced an update to how the National Vulnerability Database (NVD) handles CVE enrichment. The driver is scale: vulnerability submissions grew by 263% between 2020 and 2025, …

Published
CommentaryVulnerability

LMDeploy Flaw Rapidly Exploited

A high-severity security flaw (CVE-2026-33626, CVSS score: 7.5) has been found in LMDeploy, an open-source toolkit for compressing, deploying, and serving large language models.

Published
Vulnerability

Bitwarden CLI Compromise

Security researchers at JFrog and Socket have uncovered a supply chain attack targeting the Bitwarden command-line interface. If you use the Bitwarden CLI via npm, here's what happened, …

Published
Supply chain