#OpenSourceRisk
February 27, 2026 at 7:00 PM
AI coding tools speed delivery, but they also add open-source packages and remediation debt. Security teams must track vulnerabilities, licensing, ownership, and maintenance as AI-generated code scales. #AICoding #OpenSourceRisk #RemediationDebt
Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt
AI coding tools can speed up development, but they also increase open-source dependencies and create growing remediation debt for security teams. The webinar shares findings from 300 enterprise leaders on how organizations like ActiveState are handling AI-driven open-source risk, governance, and downstream business impact. #ActiveState #RebeccaBanks #MorisChen...
www.hendryadrian.com
August 25, 2026 at 2:45 AM
Claude code leaked via malicious npm packaging - the supply chain remains a soft target for high-impact breaches. Trust in dependencies must be continuously verified. 📦⚠️ #SupplyChainSecurity #OpenSourceRisk
Claude Code Source Leaked via npm Packaging Error, Anthropic Confirms
Claude Code 2.1.88 leak exposed 512,000 lines via npm error, fueling supply chain risks and typosquatting attacks.
buff.ly
April 1, 2026 at 10:05 AM
December 13, 2025 at 2:51 AM
Millions of end-of-life open source packages remain unflagged in CVE feeds, leaving blind spots in vulnerability scans. AI tools like Project Glasswing may help reveal hidden risks in unmaintained code. #OpenSourceRisk #VulnerabilityScan #USA
The EOL Blind Spot in Your CVE Feed: What SCA Tools Miss
Open source end-of-life (EOL) packages are frequently omitted from CVE investigations and vulnerability feeds, leaving millions of versions unflagged and enterprises exposed. Industry research from HeroDevs and Sonatype shows 5.4M EOL package versions across major registries and finds that AI-driven discovery like Project Glasswing may increase uncovered vulnerabilities in unmaintained code. #SpringSecurity #ProjectGlasswing
www.hendryadrian.com
May 5, 2026 at 9:45 PM
North Korean-linked group UNC1069 used social engineering to steal Axios maintainer credentials via fake Slack and Teams setups, releasing trojanized packages with the WAVESHAPER.V2 remote access implant. #NorthKorea #SupplyChain #OpenSourceRisk
UNC1069 Social Engineering of Axios Maintainer Led to npm Supply Chain Attack
North Korean-linked threat actors tracked as UNC1069 used a highly targeted social engineering campaign to steal the Axios maintainer's credentials and publish trojanized versions of the package. The compromise deployed a remote access implant called WAVESHAPER.V2 and underscores the massive supply-chain risk posed by attacks on popular open-source maintainers. #UNC1069 #WAVESHAPERV2...
www.hendryadrian.com
April 5, 2026 at 2:40 PM
March 5, 2026 at 4:00 PM
March 3, 2026 at 7:00 PM
February 26, 2026 at 6:00 PM
February 2, 2026 at 5:06 PM
January 30, 2026 at 5:00 PM
GitHub links a repo breach to the TanStack npm supply-chain attack - one compromised dependency can ripple across thousands of developers. Trust in code must be continuously verified. 📦⚠️ #SupplyChainSecurity #OpenSourceRisk
GitHub links repo breach to TanStack npm supply-chain attack
GitHub says the hackers who breached 3,800 internal repositories gained access via a malicious version of the Nx Console VS Code extension, compromised in last week's TanStack npm supply-chain attack.
buff.ly
May 22, 2026 at 10:05 AM