Settings

Theme

abhisek

Karma
297
Created
13 years ago

About

Dabbling into open source software supply chain security

github.com/safedep/pmg

Recent Submissions

  1. 1. Step by Step Analysis of Malicious NPM Package (safedep.io)
  2. 2. OpenClaw bot calls out maintainer when its PR got rejected (crabby-rathbun.github.io)
  3. 3. Show HN: Gryph – Audit Trail for AI Coding Agents (Claude Code, Cursor, Gemini) (github.com)
  4. 4. Agent Skills Threat Model (safedep.io)
  5. 5. Catching malicious package releases using a transparency log (blog.trailofbits.com)
  6. 6. CVE-2025-66491: Traefik's "Verify=on" Turned TLS Off (aisle.com)
  7. 7. DarkGPT: Malicious Visual Studio Code Extension Targeting Developers (safedep.io)
  8. 8. Exposing and Exploiting Incomplete Branch Predictor Isolation in Cloud (comsec.ethz.ch)
  9. 9. KnownSec breach: What we know so far (substack.com)
  10. 10. Buying browser extensions for fun and profit (secureannex.com)

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection