Articles

Secure your Software Development and Delivery

OWASP SPVS

OWASP SPVS: Lessons from Securing the Software Pipeline

For years, attackers went after applications one at a time. They have changed tactics: why compromise one app when you can compromise the pipeline that builds many? Xygeni’s Malware Early Warning (MEW) detected 4,452 malicious packages in 2025 and 1,281 more in 2026 so far.

Read More »
Threats in Open Source - worm attack

New Threats in Open Source: Worms, AI-Driven Malware, and Trust Abuse

TL;DR The open source supply chain threat landscape has fundamentally shifted. Three converging trends are redefining risk: Self-Propagating Worms Have Arrived Shai-Hulud (Sept 2025): First npm worm attack—stole credentials via postinstall hooks, then autonomously republished itself across ~700 package versions using compromised maintainer tokens. GlassWorm

Read More »