Blog/Codebase Security

Codebase Security

Exposed secrets, vulnerable dependencies, and the supply-chain attacks that reach you through packages you did not write. Incident analysis and practical remediation, in business terms.

10 articles

Security
July 13, 20268 min read

Jscrambler npm Attack: What the July 2026 Supply-Chain Hit Means for Founders

A poisoned release of jscrambler, itself a security vendor, ran an infostealer on install. Here's the founder's lesson on what npm packages do to your machine.

Read more →
Security
July 6, 20269 min read

Dependency Confusion: How 33 Fake npm Packages Quietly Mapped Companies' Internal Tools

In late May 2026, attackers used 33 malicious npm packages not to steal — but to map which companies use which internal tools. Here's the founder's risk.

Read more →
Security
July 6, 20268 min read

Klue Breach: What the Salesforce Supply-Chain Attack Means for Founders

A breach at vendor Klue exposed Salesforce data at nine-plus companies via stolen OAuth tokens. Here's the founder's lesson on third-party integration risk.

Read more →
Security
June 29, 20269 min read

The Mastra npm Attack: Why One Dependency Can Drain Your Secrets

On June 17, 2026, attackers backdoored 140+ Mastra AI-framework npm packages in 88 minutes. Here's the business lesson for founders shipping on AI tooling.

Read more →
Security
June 29, 202610 min read

The Vercel OAuth Breach: Why Your Third-Party Integrations Are a Supply Chain Risk

A compromised OAuth app at one vendor cascaded into Vercel and exposed customer environment variables. Here's what founders should learn from the 2026 breach.

Read more →
The 2026 Supply Chain Worm Wave: 500M+ Downloads Compromised. Is Your Product Exposed?
Security
June 22, 20267 min read

The 2026 Supply Chain Worm Wave: 500M+ Downloads Compromised. Is Your Product Exposed?

Worms hit TanStack, Mistral AI, Red Hat and 170+ npm/PyPI packages in May-June 2026. Here's the business risk and a founder's response checklist.

Read more →
Security
June 22, 20269 min read

ServiceNow's Data Exposure: When One Unauthenticated Endpoint Leaks Everything

A single endpoint that didn't check credentials let anyone pull ServiceNow customer data. Here's what founders should learn from the June 2026 exposure.

Read more →
The AI Governance Gap: Why AI Tools Are Now the #1 Audit Risk
Security
April 1, 20267 min read

The AI Governance Gap: Why AI Tools Are Now the #1 Audit Risk

69% of security leaders say AI adoption is outpacing their compliance controls. New research reveals AI has become the top audit risk for 2026—here's what that means for your organization.

Read more →
LiteLLM Supply Chain Attack: 95 Million Downloads, 40 Minutes of Malware
Security
March 25, 20267 min read

LiteLLM Supply Chain Attack: 95 Million Downloads, 40 Minutes of Malware

A Python package used by AI tools everywhere was poisoned for two hours. Here's what happened, how attackers chained compromises together, and what you should do now.

Read more →
Find Exposed Secrets in GitHub: Free Scan + Remediation Guide
Security
March 20, 20268 min read

Find Exposed Secrets in GitHub: Free Scan + Remediation Guide

API keys, database credentials, and tokens hiding in your codebase are ticking time bombs. Learn how to scan for exposed secrets before attackers find them first.

Read more →