Settings

Theme

abhisek

Karma
287
Created
13 years ago

About

Dabbling into open source software supply chain security

github.com/safedep/vet

Recent Submissions

  1. 1. Catching malicious package releases using a transparency log (blog.trailofbits.com)
  2. 2. CVE-2025-66491: Traefik's "Verify=on" Turned TLS Off (aisle.com)
  3. 3. DarkGPT: Malicious Visual Studio Code Extension Targeting Developers (safedep.io)
  4. 4. Exposing and Exploiting Incomplete Branch Predictor Isolation in Cloud (comsec.ethz.ch)
  5. 5. KnownSec breach: What we know so far (substack.com)
  6. 6. Buying browser extensions for fun and profit (secureannex.com)
  7. 7. Curious Case of Embedded Executable in a Newly Introduced Transitive Dependency (safedep.io)
  8. 8. NPM Supply Chain Malware with Self-Replicating Behaviour (safedep.io)
  9. 9. Tensorflow.js Typosquatting Attack: Malicious Package Targeting AI/ML Developers (safedep.io)
  10. 10. Secure Vibe Coding with AI Agents (safedep.io)

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection