Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
Securing the Developer Supply Chain: Verifying the Claude Code Rust-Bun Migration
Introduction On June 17th, 2026, a significant infrastructure shift occurred in a widely used developer toolchain component. Claude Code v2....
GoldenEyeDog Code-Signing Abuse: Detecting Stolen Certificates from DigiCert Breach
GoldenEyeDog Code-Signing Abuse: Detecting Stolen Certificates from DigiCert Breach Introduction The July 2026 breach of DigiCert represents...
Third-Party Support System Breach: Analyzing the EY Incident and Defensive Strategies
Introduction Ernst & Young (EY) recently disclosed a significant security incident stemming from the compromise of a third-party support tic...
Defending Trust: Microsoft's 2026 Black Hat Research on AI and Supply Chain Security
Introduction At Black Hat USA 2026, Microsoft Security doubled down on the theme of "Defending Trust" in an era where the attack surface has...
GoSerpent APT & GlassWASM Supply Chain: OTX Pulse Analysis — Enterprise Detection Pack
Threat Summary Recent OTX pulses indicate a surge in sophisticated, multi-vector campaigns targeting government, technology, and cryptocurre...
Defending Against Chrome Sync Stalking and Game Cheat Supply Chain Attacks
Introduction This week’s ThreatsDay roundup is a stark reminder that the most dangerous attacks often hide in plain sight. We are seeing a s...
AsyncAPI npm Supply Chain Attack: Detection and Remediation for Credential-Stealing RAT
AsyncAPI npm Supply Chain Attack: Detection and Remediation for Credential-Stealing RAT Introduction A critical supply-chain compromise has ...
AsyncAPI npm Supply Chain Compromise: Mitigating Import-Time Malware Delivery
Introduction The open-source ecosystem is the lifeblood of modern development, but it remains a prime target for adversaries seeking scale a...
OkoBot, LummaC2 & O-UNC-038: Credential Harvesting & Infostealer Surge — OTX Analysis
Threat Summary Recent OTX pulses indicate a converged threat landscape focused on credential theft and initial access via diverse vectors. A...