We're excited to announce the launch of our security AI agent, "Takumi"!
It's already making waves in the security world, having reported over 10 vulnerabilities in OSS projects like Vim.
Check it out!
🚨 We posted a initial response guidance blog for the software supply chain attack on the tensorlake npm package, which occurred today at 10/8.
We are still researching the details of the campaign and sample, and will update the blog post as new details emerge.
We have published a new blog post covering a recent software supply chain attack on the @subql/common npm package.
It covers technical details of the compromised package, as well as guidance on response if affected, as well as recommendations for users to protect against supply
We've published a new blog post by RyotaK @ryotkak.
He discovered a vulnerability in Claude Code GitHub Actions that allows external attackers to bypass its permission controls via a GitHub issue and abuse the workflow's permissions, along with related misconfigurations.
The
We've published a new blog post by RyotaK @ryotkak !
He exploited a directory deletion race condition in Google Cloud's Looker, leading to full RCE and K8s privilege escalation.
Read the technical details here: