Articles

Secure your Software Development and Delivery

OWASP SPVS

OWASP SPVS: Lessons from Securing the Software Pipeline

Verify the Whole Software Pipeline: The Friction, the Wins, and the Lessons from Adopting OWASP SPVS The OWASP Secure Pipeline Verification Standard (SPVS) reached version 1.0 in October 2025. We decided to use the standard across our organization for the reasons explained below. This post

Read More »
Threats in Open Source - worm attack

New Threats in Open Source: Worms, AI-Driven Malware, and Trust Abuse

TL;DR The open source supply chain threat landscape has fundamentally shifted. Three converging trends are redefining risk: Self-Propagating Worms Have Arrived Shai-Hulud (Sept 2025): First npm worm attack—stole credentials via postinstall hooks, then autonomously republished itself across ~700 package versions using compromised maintainer tokens. GlassWorm

Read More »