Category: Secure
DevSecOps Weekly — July 19, 2026
Security Radar · Issue 8 DevSecOps Weekly July 19, 2026 · Weekly Edition A backdoor rode into ~2 million weekly npm installs the moment developers imported AsyncAPI — and 148 more packages quietly conscripted student browsers into a DDoS botnet. At a glance This week’s marquee story is a textbook…
DevSecOps Weekly — July 12, 2026 — Interactive Topic Map
DevSecOps Weekly — July 12, 2026
Security Radar · Issue 7 DevSecOps Weekly July 12, 2026 · Weekly Edition Six npm and PyPI packages compromised this week — and four separate attacks built specifically to fool the AI agents reviewing your code, not the developers running it. At a glance Package registries took another beating this…
DevSecOps Weekly — July 5, 2026
Security Radar · Issue 6 DevSecOps Weekly July 5, 2026 · Weekly Edition Registries under siege, an unpatched pipeline flaw with no fix in sight, and JFrog’s governance play takes center stage. At a glance Package-registry supply-chain attacks dominated the week, and JFrog’s own research desk was in the middle…
DevSecOps Weekly — June 28, 2026
Security Radar · Issue 5 DevSecOps Weekly June 28, 2026 · Weekly Edition Pipeline, registry, and platform security — what shipped, what broke, what to do about it. At a glance CI/CD pipeline attacks dominated the week. The Cordyceps research exposed critical flaws in GitHub Actions workflows across more than…