{"id":5746,"date":"2026-08-23T12:50:54","date_gmt":"2026-08-23T17:50:54","guid":{"rendered":"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=5746"},"modified":"2026-08-23T12:50:54","modified_gmt":"2026-08-23T17:50:54","slug":"devsecops-weekly-august-23-2026-interactive-topic-map","status":"publish","type":"post","link":"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=5746","title":{"rendered":"DevSecOps Weekly \u2014 August 23, 2026 \u2014 Interactive Topic Map"},"content":{"rendered":"<p><iframe srcdoc=\"&lt;!DOCTYPE html&gt;\n&lt;html lang=&quot;en&quot;&gt;\n&lt;head&gt;\n&lt;meta charset=&quot;utf-8&quot;&gt;\n&lt;title&gt;DevSecOps Weekly \u2014 August 23, 2026 Topic Map&lt;\/title&gt;\n&lt;script src=&quot;https:\/\/cdnjs.cloudflare.com\/ajax\/libs\/d3\/7.9.0\/d3.min.js&quot;&gt;&lt;\/script&gt;\n&lt;style&gt;\n  html, body { margin:0; padding:0; height:100%; background:#ffffff; font-family:-apple-system,BlinkMacSystemFont,&quot;Segoe UI&quot;,Roboto,Helvetica,Arial,sans-serif; }\n  #header { padding:18px 24px 10px; border-bottom:1px solid #e5e7eb; }\n  #header h1 { margin:0; font-size:20px; color:#0f172a; }\n  #header p { margin:6px 0 0; font-size:13px; color:#6b7280; }\n  #canvas-wrap { position:relative; width:100%; height:calc(100vh - 78px); }\n  svg { width:100%; height:100%; display:block; cursor:grab; }\n  svg:active { cursor:grabbing; }\n  .legend { position:absolute; top:14px; left:14px; background:rgba(255,255,255,0.95); border:1px solid #e5e7eb; border-radius:8px; padding:10px 14px; font-size:12px; color:#374151; box-shadow:0 1px 3px rgba(0,0,0,0.08); }\n  .legend-title { font-weight:600; font-size:11px; letter-spacing:.04em; text-transform:uppercase; color:#6b7280; margin-bottom:6px; }\n  .legend-row { display:flex; align-items:center; gap:7px; margin:3px 0; }\n  .legend-dot { width:11px; height:11px; border-radius:50%; flex:0 0 auto; }\n  .controls { position:absolute; top:14px; right:14px; display:flex; flex-direction:column; gap:6px; }\n  .controls button { width:32px; height:32px; border-radius:6px; border:1px solid #d1d5db; background:#ffffff; font-size:16px; cursor:pointer; color:#374151; }\n  .controls button:hover { background:#f3f4f6; }\n  .hint { position:absolute; bottom:12px; right:16px; font-size:11px; color:#9ca3af; }\n  .node-label { font-size:11px; fill:#1f2937; pointer-events:none; paint-order:stroke; stroke:#ffffff; stroke-width:3px; stroke-linejoin:round; }\n  .node-label.bold { font-weight:700; font-size:12px; }\n  .link { stroke:#94a3b8; stroke-opacity:0.55; }\n  .tooltip { position:absolute; pointer-events:auto; background:#0f172a; color:#f9fafb; font-size:12px; padding:8px 12px; border-radius:8px; opacity:0; transition:opacity .12s; max-width:280px; max-height:260px; overflow-y:auto; z-index:20; box-shadow:0 6px 18px rgba(0,0,0,0.28); }\n  .tooltip-head { font-size:12px; }\n  .tooltip-articles { margin-top:7px; padding-top:7px; border-top:1px solid rgba(255,255,255,0.18); }\n  .tooltip-articles-title { font-size:10px; text-transform:uppercase; letter-spacing:.05em; color:#94a3b8; margin-bottom:4px; }\n  .tooltip-articles a { display:block; color:#93c5fd; text-decoration:none; margin:4px 0; line-height:1.35; }\n  .tooltip-articles a:hover { text-decoration:underline; color:#bfdbfe; }\n&lt;\/style&gt;\n&lt;\/head&gt;\n&lt;body&gt;\n&lt;div id=&quot;header&quot;&gt;\n  &lt;h1&gt;DevSecOps Weekly \u2014 August 23, 2026 Topic Map&lt;\/h1&gt;\n  &lt;p&gt;Node size = mentions &amp;middot; edge thickness = co-mention frequency &amp;middot; scroll or pinch to zoom, drag the canvas to pan, drag a node to reposition it, hover a node for related articles.&lt;\/p&gt;\n&lt;\/div&gt;\n&lt;div id=&quot;canvas-wrap&quot;&gt;\n  &lt;svg id=&quot;canvas&quot;&gt;&lt;\/svg&gt;\n  &lt;div class=&quot;legend&quot; id=&quot;legend&quot;&gt;&lt;\/div&gt;\n  &lt;div class=&quot;controls&quot;&gt;\n    &lt;button id=&quot;zoom-in&quot; title=&quot;Zoom in&quot;&gt;+&lt;\/button&gt;\n    &lt;button id=&quot;zoom-out&quot; title=&quot;Zoom out&quot;&gt;&amp;minus;&lt;\/button&gt;\n    &lt;button id=&quot;zoom-reset&quot; title=&quot;Reset view&quot;&gt;&amp;#8634;&lt;\/button&gt;\n  &lt;\/div&gt;\n  &lt;div class=&quot;tooltip&quot; id=&quot;tooltip&quot;&gt;&lt;\/div&gt;\n  &lt;div class=&quot;hint&quot;&gt;Security Radar LLC &amp;middot; Newshunter interactive topic map&lt;\/div&gt;\n&lt;\/div&gt;\n&lt;script&gt;\nconst DATA = {&quot;nodes&quot;: [{&quot;id&quot;: &quot;codingagents&quot;, &quot;type&quot;: &quot;concept&quot;, &quot;label&quot;: &quot;AI coding agents&quot;, &quot;weight&quot;: 12, &quot;articles&quot;: [{&quot;title&quot;: &quot;AI agent suggested installing a malware package. Engineer almost took its advice&quot;, &quot;url&quot;: &quot;https:\/\/www.theregister.com\/security\/2026\/08\/20\/ai-agent-suggested-installing-a-malware-package-engineer-almost-took-its-advice\/5289849&quot;}, {&quot;title&quot;: &quot;How AI Agents Expand the Software Supply Chain Attack Surface&quot;, &quot;url&quot;: &quot;https:\/\/socket.dev\/blog\/ai-agents-supply-chain-attack-surface&quot;}, {&quot;title&quot;: &quot;One pull to wipe them all&quot;, &quot;url&quot;: &quot;https:\/\/thenewstack.io\/ai-coding-agent-security\/&quot;}, {&quot;title&quot;: &quot;Are LLMs Equally Good (or Bad) at Building Secure Software?&quot;, &quot;url&quot;: &quot;https:\/\/devops.com\/are-llms-equally-good-or-bad-at-building-secure-software\/&quot;}, {&quot;title&quot;: &quot;When AI Writes the Code, Specifications Need an Exit Strategy&quot;, &quot;url&quot;: &quot;https:\/\/www.oreilly.com\/radar\/when-ai-writes-the-code-specifications-need-an-exit-strategy\/&quot;}]}, {&quot;id&quot;: &quot;rustsupplychain&quot;, &quot;type&quot;: &quot;campaign&quot;, &quot;label&quot;: &quot;crates.io poisoning&quot;, &quot;weight&quot;: 7, &quot;articles&quot;: [{&quot;title&quot;: &quot;Rust Supply-Chain Attack: arrayref, internment and append-only-vec poisoned by the proc-macro1 build-time dropper&quot;, &quot;url&quot;: &quot;https:\/\/www.stepsecurity.io\/blog\/arrayref-rust-crate-supply-chain-attack&quot;}, {&quot;title&quot;: &quot;Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads&quot;, &quot;url&quot;: &quot;https:\/\/thehackernews.com\/2026\/08\/rust-supply-chain-attack-puts-build.html&quot;}]}, {&quot;id&quot;: &quot;buildrs&quot;, &quot;type&quot;: &quot;concept&quot;, &quot;label&quot;: &quot;build.rs execution&quot;, &quot;weight&quot;: 6, &quot;articles&quot;: [{&quot;title&quot;: &quot;Rust Supply-Chain Attack: arrayref, internment and append-only-vec poisoned by the proc-macro1 build-time dropper&quot;, &quot;url&quot;: &quot;https:\/\/www.stepsecurity.io\/blog\/arrayref-rust-crate-supply-chain-attack&quot;}, {&quot;title&quot;: &quot;Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads&quot;, &quot;url&quot;: &quot;https:\/\/thehackernews.com\/2026\/08\/rust-supply-chain-attack-puts-build.html&quot;}]}, {&quot;id&quot;: &quot;github&quot;, &quot;type&quot;: &quot;vendor&quot;, &quot;label&quot;: &quot;GitHub&quot;, &quot;weight&quot;: 6, &quot;articles&quot;: [{&quot;title&quot;: &quot;How canvases make agentic workflows visible, steerable, and cost-efficient&quot;, &quot;url&quot;: &quot;https:\/\/github.blog\/ai-and-ml\/github-copilot\/how-canvases-make-agentic-workflows-visible-steerable-and-cost-efficient\/&quot;}, {&quot;title&quot;: &quot;GitHub Sharpens CodeQL\\u2019s Eye on Actions Workflows and Modern JavaScript&quot;, &quot;url&quot;: &quot;https:\/\/devops.com\/github-sharpens-codeqls-eye-on-actions-workflows-and-modern-javascript\/&quot;}, {&quot;title&quot;: &quot;Tame Dependabot: Group your updates, slow the cadence, keep security fast&quot;, &quot;url&quot;: &quot;https:\/\/github.blog\/security\/supply-chain-security\/tame-dependabot-group-your-updates-slow-the-cadence-keep-security-fast\/&quot;}, {&quot;title&quot;: &quot;The npm attack that turned provenance attestations into camouflage&quot;, &quot;url&quot;: &quot;https:\/\/thenewstack.io\/npm-supply-chain-worm-attack\/&quot;}]}, {&quot;id&quot;: &quot;cratesio&quot;, &quot;type&quot;: &quot;product&quot;, &quot;label&quot;: &quot;crates.io&quot;, &quot;weight&quot;: 6, &quot;articles&quot;: [{&quot;title&quot;: &quot;Rust Supply-Chain Attack: arrayref, internment and append-only-vec poisoned by the proc-macro1 build-time dropper&quot;, &quot;url&quot;: &quot;https:\/\/www.stepsecurity.io\/blog\/arrayref-rust-crate-supply-chain-attack&quot;}, {&quot;title&quot;: &quot;Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads&quot;, &quot;url&quot;: &quot;https:\/\/thehackernews.com\/2026\/08\/rust-supply-chain-attack-puts-build.html&quot;}, {&quot;title&quot;: &quot;AI-generated Rust compiles perfectly. That\\u2019s the scary part.&quot;, &quot;url&quot;: &quot;https:\/\/thenewstack.io\/canonical-c-rust-apparmor\/&quot;}]}, {&quot;id&quot;: &quot;codereview&quot;, &quot;type&quot;: &quot;concept&quot;, &quot;label&quot;: &quot;Code review load&quot;, &quot;weight&quot;: 6, &quot;articles&quot;: [{&quot;title&quot;: &quot;AI broke code review. What about knowledge sharing?&quot;, &quot;url&quot;: &quot;https:\/\/thenewstack.io\/ai-code-review-cognitive-debt\/&quot;}, {&quot;title&quot;: &quot;When AI Writes the Code, Specifications Need an Exit Strategy&quot;, &quot;url&quot;: &quot;https:\/\/www.oreilly.com\/radar\/when-ai-writes-the-code-specifications-need-an-exit-strategy\/&quot;}, {&quot;title&quot;: &quot;Are LLMs Equally Good (or Bad) at Building Secure Software?&quot;, &quot;url&quot;: &quot;https:\/\/devops.com\/are-llms-equally-good-or-bad-at-building-secure-software\/&quot;}, {&quot;title&quot;: &quot;AI agent suggested installing a malware package. Engineer almost took its advice&quot;, &quot;url&quot;: &quot;https:\/\/www.theregister.com\/security\/2026\/08\/20\/ai-agent-suggested-installing-a-malware-package-engineer-almost-took-its-advice\/5289849&quot;}, {&quot;title&quot;: &quot;The Pulse: We need to talk about migrations with AI&quot;, &quot;url&quot;: &quot;https:\/\/newsletter.pragmaticengineer.com\/p\/the-pulse-we-need-to-talk-about-migrations&quot;}]}, {&quot;id&quot;: &quot;arrayref&quot;, &quot;type&quot;: &quot;product&quot;, &quot;label&quot;: &quot;arrayref&quot;, &quot;weight&quot;: 5, &quot;articles&quot;: [{&quot;title&quot;: &quot;Rust Supply-Chain Attack: arrayref, internment and append-only-vec poisoned by the proc-macro1 build-time dropper&quot;, &quot;url&quot;: &quot;https:\/\/www.stepsecurity.io\/blog\/arrayref-rust-crate-supply-chain-attack&quot;}, {&quot;title&quot;: &quot;Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads&quot;, &quot;url&quot;: &quot;https:\/\/thehackernews.com\/2026\/08\/rust-supply-chain-attack-puts-build.html&quot;}]}, {&quot;id&quot;: &quot;procmacro1&quot;, &quot;type&quot;: &quot;malware&quot;, &quot;label&quot;: &quot;proc-macro1&quot;, &quot;weight&quot;: 5, &quot;articles&quot;: [{&quot;title&quot;: &quot;Rust Supply-Chain Attack: arrayref, internment and append-only-vec poisoned by the proc-macro1 build-time dropper&quot;, &quot;url&quot;: &quot;https:\/\/www.stepsecurity.io\/blog\/arrayref-rust-crate-supply-chain-attack&quot;}, {&quot;title&quot;: &quot;Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads&quot;, &quot;url&quot;: &quot;https:\/\/thehackernews.com\/2026\/08\/rust-supply-chain-attack-puts-build.html&quot;}]}, {&quot;id&quot;: &quot;gitlab&quot;, &quot;type&quot;: &quot;product&quot;, &quot;label&quot;: &quot;GitLab&quot;, &quot;weight&quot;: 5, &quot;articles&quot;: [{&quot;title&quot;: &quot;Critical GitLab flaw allows attackers to delete and modify public repos&quot;, &quot;url&quot;: &quot;https:\/\/www.csoonline.com\/article\/4211140\/critical-gitlab-flaw-allows-attackers-to-delete-and-modify-public-repos.html&quot;}, {&quot;title&quot;: &quot;Critical GitLab Flaw Exploited Shortly After Disclosure&quot;, &quot;url&quot;: &quot;https:\/\/www.securityweek.com\/critical-gitlab-flaw-exploited-shortly-after-disclosure\/&quot;}]}, {&quot;id&quot;: &quot;cve19478&quot;, &quot;type&quot;: &quot;cve&quot;, &quot;label&quot;: &quot;CVE-2026-19478&quot;, &quot;weight&quot;: 5, &quot;articles&quot;: [{&quot;title&quot;: &quot;Critical GitLab flaw allows attackers to delete and modify public repos&quot;, &quot;url&quot;: &quot;https:\/\/www.csoonline.com\/article\/4211140\/critical-gitlab-flaw-allows-attackers-to-delete-and-modify-public-repos.html&quot;}, {&quot;title&quot;: &quot;Critical GitLab Flaw Exploited Shortly After Disclosure&quot;, &quot;url&quot;: &quot;https:\/\/www.securityweek.com\/critical-gitlab-flaw-exploited-shortly-after-disclosure\/&quot;}]}, {&quot;id&quot;: &quot;agentidentity&quot;, &quot;type&quot;: &quot;concept&quot;, &quot;label&quot;: &quot;Agent identity&quot;, &quot;weight&quot;: 5, &quot;articles&quot;: [{&quot;title&quot;: &quot;Six identity capabilities for securing autonomous AI agents&quot;, &quot;url&quot;: &quot;https:\/\/thenewstack.io\/securing-autonomous-ai-agents\/&quot;}, {&quot;title&quot;: &quot;Securing sandboxes: What happens when AI agents escape containment?&quot;, &quot;url&quot;: &quot;https:\/\/thenewstack.io\/securing-ai-agent-sandboxes\/&quot;}, {&quot;title&quot;: &quot;AWS deprecated this EKS auth method. 81% of clusters still run it.&quot;, &quot;url&quot;: &quot;https:\/\/thenewstack.io\/kubernetes-fleet-security-management\/&quot;}, {&quot;title&quot;: &quot;Claude Breached 3 Companies and Uploaded Malware to PyPI During Anthropic\\u2019s Security Tests&quot;, &quot;url&quot;: &quot;https:\/\/socket.dev\/blog\/anthropic-claude-pypi-malware&quot;}, {&quot;title&quot;: &quot;LangChain\\u2019s dcode Isn\\u2019t New. Its Governance Play for Sensitive Code Is&quot;, &quot;url&quot;: &quot;https:\/\/devops.com\/langchains-dcode-isnt-new-its-governance-play-for-sensitive-code-is\/&quot;}]}, {&quot;id&quot;: &quot;agentsandbox&quot;, &quot;type&quot;: &quot;concept&quot;, &quot;label&quot;: &quot;Agent sandboxing&quot;, &quot;weight&quot;: 5, &quot;articles&quot;: [{&quot;title&quot;: &quot;Securing sandboxes: What happens when AI agents escape containment?&quot;, &quot;url&quot;: &quot;https:\/\/thenewstack.io\/securing-ai-agent-sandboxes\/&quot;}, {&quot;title&quot;: &quot;Six identity capabilities for securing autonomous AI agents&quot;, &quot;url&quot;: &quot;https:\/\/thenewstack.io\/securing-autonomous-ai-agents\/&quot;}, {&quot;title&quot;: &quot;One pull to wipe them all&quot;, &quot;url&quot;: &quot;https:\/\/thenewstack.io\/ai-coding-agent-security\/&quot;}, {&quot;title&quot;: &quot;Claude Breached 3 Companies and Uploaded Malware to PyPI During Anthropic\\u2019s Security Tests&quot;, &quot;url&quot;: &quot;https:\/\/socket.dev\/blog\/anthropic-claude-pypi-malware&quot;}]}, {&quot;id&quot;: &quot;secureaicode&quot;, &quot;type&quot;: &quot;concept&quot;, &quot;label&quot;: &quot;LLM code security&quot;, &quot;weight&quot;: 5, &quot;articles&quot;: [{&quot;title&quot;: &quot;Are LLMs Equally Good (or Bad) at Building Secure Software?&quot;, &quot;url&quot;: &quot;https:\/\/devops.com\/are-llms-equally-good-or-bad-at-building-secure-software\/&quot;}, {&quot;title&quot;: &quot;AI-generated Rust compiles perfectly. That\\u2019s the scary part.&quot;, &quot;url&quot;: &quot;https:\/\/thenewstack.io\/canonical-c-rust-apparmor\/&quot;}, {&quot;title&quot;: &quot;Anthropic brings Mythos 5 to its Claude Security vulnerability scanner&quot;, &quot;url&quot;: &quot;https:\/\/thenewstack.io\/anthropic-mythos-claude-security\/&quot;}, {&quot;title&quot;: &quot;When AI Writes the Code, Specifications Need an Exit Strategy&quot;, &quot;url&quot;: &quot;https:\/\/www.oreilly.com\/radar\/when-ai-writes-the-code-specifications-need-an-exit-strategy\/&quot;}, {&quot;title&quot;: &quot;AI broke code review. What about knowledge sharing?&quot;, &quot;url&quot;: &quot;https:\/\/thenewstack.io\/ai-code-review-cognitive-debt\/&quot;}]}, {&quot;id&quot;: &quot;socket&quot;, &quot;type&quot;: &quot;vendor&quot;, &quot;label&quot;: &quot;Socket&quot;, &quot;weight&quot;: 5, &quot;articles&quot;: [{&quot;title&quot;: &quot;How AI Agents Expand the Software Supply Chain Attack Surface&quot;, &quot;url&quot;: &quot;https:\/\/socket.dev\/blog\/ai-agents-supply-chain-attack-surface&quot;}, {&quot;title&quot;: &quot;NIST Proposes AI-Enabled NVD Overhaul After Cutting Routine CVE Enrichment&quot;, &quot;url&quot;: &quot;https:\/\/socket.dev\/blog\/nist-nvd-ai-automation&quot;}, {&quot;title&quot;: &quot;PHP and Composer Support Is Now in Beta&quot;, &quot;url&quot;: &quot;https:\/\/socket.dev\/blog\/php-and-composer-support-now-in-beta&quot;}, {&quot;title&quot;: &quot;Claude Breached 3 Companies and Uploaded Malware to PyPI During Anthropic\\u2019s Security Tests&quot;, &quot;url&quot;: &quot;https:\/\/socket.dev\/blog\/anthropic-claude-pypi-malware&quot;}]}, {&quot;id&quot;: &quot;supplychainsurface&quot;, &quot;type&quot;: &quot;concept&quot;, &quot;label&quot;: &quot;Agent attack surface&quot;, &quot;weight&quot;: 5, &quot;articles&quot;: [{&quot;title&quot;: &quot;How AI Agents Expand the Software Supply Chain Attack Surface&quot;, &quot;url&quot;: &quot;https:\/\/socket.dev\/blog\/ai-agents-supply-chain-attack-surface&quot;}, {&quot;title&quot;: &quot;AI agent suggested installing a malware package. Engineer almost took its advice&quot;, &quot;url&quot;: &quot;https:\/\/www.theregister.com\/security\/2026\/08\/20\/ai-agent-suggested-installing-a-malware-package-engineer-almost-took-its-advice\/5289849&quot;}, {&quot;title&quot;: &quot;One pull to wipe them all&quot;, &quot;url&quot;: &quot;https:\/\/thenewstack.io\/ai-coding-agent-security\/&quot;}, {&quot;title&quot;: &quot;Claude Breached 3 Companies and Uploaded Malware to PyPI During Anthropic\\u2019s Security Tests&quot;, &quot;url&quot;: &quot;https:\/\/socket.dev\/blog\/anthropic-claude-pypi-malware&quot;}, {&quot;title&quot;: &quot;The npm attack that turned provenance attestations into camouflage&quot;, &quot;url&quot;: &quot;https:\/\/thenewstack.io\/npm-supply-chain-worm-attack\/&quot;}]}, {&quot;id&quot;: &quot;provenance&quot;, &quot;type&quot;: &quot;standard&quot;, &quot;label&quot;: &quot;Provenance&quot;, &quot;weight&quot;: 4, &quot;articles&quot;: [{&quot;title&quot;: &quot;Proven, not promised: Chainguard Containers achieves SLSA Build Level 3&quot;, &quot;url&quot;: &quot;https:\/\/www.chainguard.dev\/unchained\/proven-not-promised-chainguard-containers-achieves-slsa-build-level-3&quot;}, {&quot;title&quot;: &quot;The npm attack that turned provenance attestations into camouflage&quot;, &quot;url&quot;: &quot;https:\/\/thenewstack.io\/npm-supply-chain-worm-attack\/&quot;}, {&quot;title&quot;: &quot;This Shit is Hard: Patching a vulnerability that has no fix&quot;, &quot;url&quot;: &quot;https:\/\/www.chainguard.dev\/unchained\/this-shit-is-hard-patching-a-vulnerability-that-has-no-fix&quot;}]}, {&quot;id&quot;: &quot;npm&quot;, &quot;type&quot;: &quot;product&quot;, &quot;label&quot;: &quot;npm&quot;, &quot;weight&quot;: 4, &quot;articles&quot;: [{&quot;title&quot;: &quot;The npm attack that turned provenance attestations into camouflage&quot;, &quot;url&quot;: &quot;https:\/\/thenewstack.io\/npm-supply-chain-worm-attack\/&quot;}, {&quot;title&quot;: &quot;PHP and Composer Support Is Now in Beta&quot;, &quot;url&quot;: &quot;https:\/\/socket.dev\/blog\/php-and-composer-support-now-in-beta&quot;}, {&quot;title&quot;: &quot;Tame Dependabot: Group your updates, slow the cadence, keep security fast&quot;, &quot;url&quot;: &quot;https:\/\/github.blog\/security\/supply-chain-security\/tame-dependabot-group-your-updates-slow-the-cadence-keep-security-fast\/&quot;}, {&quot;title&quot;: &quot;How AI Agents Expand the Software Supply Chain Attack Surface&quot;, &quot;url&quot;: &quot;https:\/\/socket.dev\/blog\/ai-agents-supply-chain-attack-surface&quot;}]}, {&quot;id&quot;: &quot;graphql&quot;, &quot;type&quot;: &quot;concept&quot;, &quot;label&quot;: &quot;GraphQL injection&quot;, &quot;weight&quot;: 4, &quot;articles&quot;: [{&quot;title&quot;: &quot;Critical GitLab flaw allows attackers to delete and modify public repos&quot;, &quot;url&quot;: &quot;https:\/\/www.csoonline.com\/article\/4211140\/critical-gitlab-flaw-allows-attackers-to-delete-and-modify-public-repos.html&quot;}, {&quot;title&quot;: &quot;Critical GitLab Flaw Exploited Shortly After Disclosure&quot;, &quot;url&quot;: &quot;https:\/\/www.securityweek.com\/critical-gitlab-flaw-exploited-shortly-after-disclosure\/&quot;}]}, {&quot;id&quot;: &quot;slopsquat&quot;, &quot;type&quot;: &quot;concept&quot;, &quot;label&quot;: &quot;Slopsquatting&quot;, &quot;weight&quot;: 4, &quot;articles&quot;: [{&quot;title&quot;: &quot;AI agent suggested installing a malware package. Engineer almost took its advice&quot;, &quot;url&quot;: &quot;https:\/\/www.theregister.com\/security\/2026\/08\/20\/ai-agent-suggested-installing-a-malware-package-engineer-almost-took-its-advice\/5289849&quot;}, {&quot;title&quot;: &quot;How AI Agents Expand the Software Supply Chain Attack Surface&quot;, &quot;url&quot;: &quot;https:\/\/socket.dev\/blog\/ai-agents-supply-chain-attack-surface&quot;}]}, {&quot;id&quot;: &quot;specs&quot;, &quot;type&quot;: &quot;concept&quot;, &quot;label&quot;: &quot;Executable specs&quot;, &quot;weight&quot;: 4, &quot;articles&quot;: [{&quot;title&quot;: &quot;When AI Writes the Code, Specifications Need an Exit Strategy&quot;, &quot;url&quot;: &quot;https:\/\/www.oreilly.com\/radar\/when-ai-writes-the-code-specifications-need-an-exit-strategy\/&quot;}, {&quot;title&quot;: &quot;The Pulse: We need to talk about migrations with AI&quot;, &quot;url&quot;: &quot;https:\/\/newsletter.pragmaticengineer.com\/p\/the-pulse-we-need-to-talk-about-migrations&quot;}, {&quot;title&quot;: &quot;AI broke code review. What about knowledge sharing?&quot;, &quot;url&quot;: &quot;https:\/\/thenewstack.io\/ai-code-review-cognitive-debt\/&quot;}]}, {&quot;id&quot;: &quot;secretscanning&quot;, &quot;type&quot;: &quot;concept&quot;, &quot;label&quot;: &quot;Secret scanning&quot;, &quot;weight&quot;: 4, &quot;articles&quot;: [{&quot;title&quot;: &quot;50,000 Stripe Secrets Leaked in Public Code&quot;, &quot;url&quot;: &quot;https:\/\/securityaffairs.com\/197504\/cyber-crime\/50000-stripe-secrets-leaked-in-public-code.html&quot;}, {&quot;title&quot;: &quot;Claude Breached 3 Companies and Uploaded Malware to PyPI During Anthropic\\u2019s Security Tests&quot;, &quot;url&quot;: &quot;https:\/\/socket.dev\/blog\/anthropic-claude-pypi-malware&quot;}]}, {&quot;id&quot;: &quot;toolsprawl&quot;, &quot;type&quot;: &quot;concept&quot;, &quot;label&quot;: &quot;DevSecOps tool sprawl&quot;, &quot;weight&quot;: 4, &quot;articles&quot;: [{&quot;title&quot;: &quot;Is Your New DevSecOps Tooling Reducing Work Or Just Adding to It?&quot;, &quot;url&quot;: &quot;https:\/\/devops.com\/is-your-new-devsecops-tooling-reducing-work-or-just-adding-to-it\/&quot;}, {&quot;title&quot;: &quot;Harness Adds AI Agents to Automate DevSecOps Workflows at Machine Speed&quot;, &quot;url&quot;: &quot;https:\/\/devops.com\/harness-adds-ai-agents-to-automate-devsecops-workflows-at-machine-speed\/&quot;}, {&quot;title&quot;: &quot;How to Avoid Repeating the \\u2018Automate Everything\\u2019 Mistake Due to AI FOMO&quot;, &quot;url&quot;: &quot;https:\/\/devops.com\/how-to-avoid-repeating-the-automate-everything-mistake-due-to-ai-fomo\/&quot;}, {&quot;title&quot;: &quot;Dynatrace Acquires Arize as AI Agents Deepen the Observability Challenge&quot;, &quot;url&quot;: &quot;https:\/\/devops.com\/dynatrace-acquires-arize-as-ai-agents-deepen-the-observability-challenge\/&quot;}, {&quot;title&quot;: &quot;Why Self-Healing Tests Need a Deployment Gate&quot;, &quot;url&quot;: &quot;https:\/\/devops.com\/why-self-healing-tests-need-a-deployment-gate\/&quot;}]}, {&quot;id&quot;: &quot;anthropic&quot;, &quot;type&quot;: &quot;vendor&quot;, &quot;label&quot;: &quot;Anthropic&quot;, &quot;weight&quot;: 4, &quot;articles&quot;: [{&quot;title&quot;: &quot;Anthropic brings Mythos 5 to its Claude Security vulnerability scanner&quot;, &quot;url&quot;: &quot;https:\/\/thenewstack.io\/anthropic-mythos-claude-security\/&quot;}, {&quot;title&quot;: &quot;Claude Breached 3 Companies and Uploaded Malware to PyPI During Anthropic\\u2019s Security Tests&quot;, &quot;url&quot;: &quot;https:\/\/socket.dev\/blog\/anthropic-claude-pypi-malware&quot;}]}, {&quot;id&quot;: &quot;githubactions&quot;, &quot;type&quot;: &quot;product&quot;, &quot;label&quot;: &quot;GitHub Actions&quot;, &quot;weight&quot;: 4, &quot;articles&quot;: [{&quot;title&quot;: &quot;GitHub Sharpens CodeQL\\u2019s Eye on Actions Workflows and Modern JavaScript&quot;, &quot;url&quot;: &quot;https:\/\/devops.com\/github-sharpens-codeqls-eye-on-actions-workflows-and-modern-javascript\/&quot;}, {&quot;title&quot;: &quot;How canvases make agentic workflows visible, steerable, and cost-efficient&quot;, &quot;url&quot;: &quot;https:\/\/github.blog\/ai-and-ml\/github-copilot\/how-canvases-make-agentic-workflows-visible-steerable-and-cost-efficient\/&quot;}, {&quot;title&quot;: &quot;Tame Dependabot: Group your updates, slow the cadence, keep security fast&quot;, &quot;url&quot;: &quot;https:\/\/github.blog\/security\/supply-chain-security\/tame-dependabot-group-your-updates-slow-the-cadence-keep-security-fast\/&quot;}]}, {&quot;id&quot;: &quot;stepsecurity&quot;, &quot;type&quot;: &quot;vendor&quot;, &quot;label&quot;: &quot;StepSecurity&quot;, &quot;weight&quot;: 3, &quot;articles&quot;: [{&quot;title&quot;: &quot;Rust Supply-Chain Attack: arrayref, internment and append-only-vec poisoned by the proc-macro1 build-time dropper&quot;, &quot;url&quot;: &quot;https:\/\/www.stepsecurity.io\/blog\/arrayref-rust-crate-supply-chain-attack&quot;}]}, {&quot;id&quot;: &quot;rustsec&quot;, &quot;type&quot;: &quot;vendor&quot;, &quot;label&quot;: &quot;Rust Security WG&quot;, &quot;weight&quot;: 3, &quot;articles&quot;: [{&quot;title&quot;: &quot;Rust Supply-Chain Attack: arrayref, internment and append-only-vec poisoned by the proc-macro1 build-time dropper&quot;, &quot;url&quot;: &quot;https:\/\/www.stepsecurity.io\/blog\/arrayref-rust-crate-supply-chain-attack&quot;}, {&quot;title&quot;: &quot;Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads&quot;, &quot;url&quot;: &quot;https:\/\/thehackernews.com\/2026\/08\/rust-supply-chain-attack-puts-build.html&quot;}]}, {&quot;id&quot;: &quot;dprk&quot;, &quot;type&quot;: &quot;actor&quot;, &quot;label&quot;: &quot;DPRK infra overlap (Wiz)&quot;, &quot;weight&quot;: 3, &quot;articles&quot;: [{&quot;title&quot;: &quot;Rust Supply-Chain Attack: arrayref, internment and append-only-vec poisoned by the proc-macro1 build-time dropper&quot;, &quot;url&quot;: &quot;https:\/\/www.stepsecurity.io\/blog\/arrayref-rust-crate-supply-chain-attack&quot;}, {&quot;title&quot;: &quot;Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads&quot;, &quot;url&quot;: &quot;https:\/\/thehackernews.com\/2026\/08\/rust-supply-chain-attack-puts-build.html&quot;}]}, {&quot;id&quot;: &quot;codeql&quot;, &quot;type&quot;: &quot;product&quot;, &quot;label&quot;: &quot;CodeQL&quot;, &quot;weight&quot;: 3, &quot;articles&quot;: [{&quot;title&quot;: &quot;GitHub Sharpens CodeQL\\u2019s Eye on Actions Workflows and Modern JavaScript&quot;, &quot;url&quot;: &quot;https:\/\/devops.com\/github-sharpens-codeqls-eye-on-actions-workflows-and-modern-javascript\/&quot;}]}, {&quot;id&quot;: &quot;claudesecurity&quot;, &quot;type&quot;: &quot;product&quot;, &quot;label&quot;: &quot;Claude Security&quot;, &quot;weight&quot;: 3, &quot;articles&quot;: [{&quot;title&quot;: &quot;Anthropic brings Mythos 5 to its Claude Security vulnerability scanner&quot;, &quot;url&quot;: &quot;https:\/\/thenewstack.io\/anthropic-mythos-claude-security\/&quot;}]}, {&quot;id&quot;: &quot;nvd&quot;, &quot;type&quot;: &quot;standard&quot;, &quot;label&quot;: &quot;NIST NVD&quot;, &quot;weight&quot;: 3, &quot;articles&quot;: [{&quot;title&quot;: &quot;NIST Proposes AI-Enabled NVD Overhaul After Cutting Routine CVE Enrichment&quot;, &quot;url&quot;: &quot;https:\/\/socket.dev\/blog\/nist-nvd-ai-automation&quot;}]}, {&quot;id&quot;: &quot;nist&quot;, &quot;type&quot;: &quot;law&quot;, &quot;label&quot;: &quot;NIST&quot;, &quot;weight&quot;: 3, &quot;articles&quot;: [{&quot;title&quot;: &quot;NIST Proposes AI-Enabled NVD Overhaul After Cutting Routine CVE Enrichment&quot;, &quot;url&quot;: &quot;https:\/\/socket.dev\/blog\/nist-nvd-ai-automation&quot;}]}, {&quot;id&quot;: &quot;chainguard&quot;, &quot;type&quot;: &quot;vendor&quot;, &quot;label&quot;: &quot;Chainguard&quot;, &quot;weight&quot;: 3, &quot;articles&quot;: [{&quot;title&quot;: &quot;Proven, not promised: Chainguard Containers achieves SLSA Build Level 3&quot;, &quot;url&quot;: &quot;https:\/\/www.chainguard.dev\/unchained\/proven-not-promised-chainguard-containers-achieves-slsa-build-level-3&quot;}, {&quot;title&quot;: &quot;This Shit is Hard: Patching a vulnerability that has no fix&quot;, &quot;url&quot;: &quot;https:\/\/www.chainguard.dev\/unchained\/this-shit-is-hard-patching-a-vulnerability-that-has-no-fix&quot;}]}, {&quot;id&quot;: &quot;slsa&quot;, &quot;type&quot;: &quot;standard&quot;, &quot;label&quot;: &quot;SLSA Build Level 3&quot;, &quot;weight&quot;: 3, &quot;articles&quot;: [{&quot;title&quot;: &quot;Proven, not promised: Chainguard Containers achieves SLSA Build Level 3&quot;, &quot;url&quot;: &quot;https:\/\/www.chainguard.dev\/unchained\/proven-not-promised-chainguard-containers-achieves-slsa-build-level-3&quot;}, {&quot;title&quot;: &quot;The npm attack that turned provenance attestations into camouflage&quot;, &quot;url&quot;: &quot;https:\/\/thenewstack.io\/npm-supply-chain-worm-attack\/&quot;}]}, {&quot;id&quot;: &quot;stripesecrets&quot;, &quot;type&quot;: &quot;concept&quot;, &quot;label&quot;: &quot;50,000 Stripe secrets&quot;, &quot;weight&quot;: 3, &quot;articles&quot;: [{&quot;title&quot;: &quot;50,000 Stripe Secrets Leaked in Public Code&quot;, &quot;url&quot;: &quot;https:\/\/securityaffairs.com\/197504\/cyber-crime\/50000-stripe-secrets-leaked-in-public-code.html&quot;}]}, {&quot;id&quot;: &quot;eks&quot;, &quot;type&quot;: &quot;product&quot;, &quot;label&quot;: &quot;Amazon EKS&quot;, &quot;weight&quot;: 3, &quot;articles&quot;: [{&quot;title&quot;: &quot;AWS deprecated this EKS auth method. 81% of clusters still run it.&quot;, &quot;url&quot;: &quot;https:\/\/thenewstack.io\/kubernetes-fleet-security-management\/&quot;}]}, {&quot;id&quot;: &quot;awsauth&quot;, &quot;type&quot;: &quot;concept&quot;, &quot;label&quot;: &quot;aws-auth ConfigMap&quot;, &quot;weight&quot;: 3, &quot;articles&quot;: [{&quot;title&quot;: &quot;AWS deprecated this EKS auth method. 81% of clusters still run it.&quot;, &quot;url&quot;: &quot;https:\/\/thenewstack.io\/kubernetes-fleet-security-management\/&quot;}]}, {&quot;id&quot;: &quot;kubernetes&quot;, &quot;type&quot;: &quot;product&quot;, &quot;label&quot;: &quot;Kubernetes&quot;, &quot;weight&quot;: 3, &quot;articles&quot;: [{&quot;title&quot;: &quot;AWS deprecated this EKS auth method. 81% of clusters still run it.&quot;, &quot;url&quot;: &quot;https:\/\/thenewstack.io\/kubernetes-fleet-security-management\/&quot;}, {&quot;title&quot;: &quot;Securing sandboxes: What happens when AI agents escape containment?&quot;, &quot;url&quot;: &quot;https:\/\/thenewstack.io\/securing-ai-agent-sandboxes\/&quot;}, {&quot;title&quot;: &quot;Proven, not promised: Chainguard Containers achieves SLSA Build Level 3&quot;, &quot;url&quot;: &quot;https:\/\/www.chainguard.dev\/unchained\/proven-not-promised-chainguard-containers-achieves-slsa-build-level-3&quot;}]}, {&quot;id&quot;: &quot;mcp&quot;, &quot;type&quot;: &quot;standard&quot;, &quot;label&quot;: &quot;MCP&quot;, &quot;weight&quot;: 3, &quot;articles&quot;: [{&quot;title&quot;: &quot;How AI Agents Expand the Software Supply Chain Attack Surface&quot;, &quot;url&quot;: &quot;https:\/\/socket.dev\/blog\/ai-agents-supply-chain-attack-surface&quot;}, {&quot;title&quot;: &quot;One pull to wipe them all&quot;, &quot;url&quot;: &quot;https:\/\/thenewstack.io\/ai-coding-agent-security\/&quot;}, {&quot;title&quot;: &quot;Securing sandboxes: What happens when AI agents escape containment?&quot;, &quot;url&quot;: &quot;https:\/\/thenewstack.io\/securing-ai-agent-sandboxes\/&quot;}]}, {&quot;id&quot;: &quot;rustai&quot;, &quot;type&quot;: &quot;concept&quot;, &quot;label&quot;: &quot;AI-generated Rust&quot;, &quot;weight&quot;: 3, &quot;articles&quot;: [{&quot;title&quot;: &quot;AI-generated Rust compiles perfectly. That\\u2019s the scary part.&quot;, &quot;url&quot;: &quot;https:\/\/thenewstack.io\/canonical-c-rust-apparmor\/&quot;}, {&quot;title&quot;: &quot;Are LLMs Equally Good (or Bad) at Building Secure Software?&quot;, &quot;url&quot;: &quot;https:\/\/devops.com\/are-llms-equally-good-or-bad-at-building-secure-software\/&quot;}, {&quot;title&quot;: &quot;The Pulse: We need to talk about migrations with AI&quot;, &quot;url&quot;: &quot;https:\/\/newsletter.pragmaticengineer.com\/p\/the-pulse-we-need-to-talk-about-migrations&quot;}]}, {&quot;id&quot;: &quot;watchtowr&quot;, &quot;type&quot;: &quot;researcher&quot;, &quot;label&quot;: &quot;watchTowr&quot;, &quot;weight&quot;: 2, &quot;articles&quot;: [{&quot;title&quot;: &quot;Critical GitLab Flaw Exploited Shortly After Disclosure&quot;, &quot;url&quot;: &quot;https:\/\/www.securityweek.com\/critical-gitlab-flaw-exploited-shortly-after-disclosure\/&quot;}, {&quot;title&quot;: &quot;Critical GitLab flaw allows attackers to delete and modify public repos&quot;, &quot;url&quot;: &quot;https:\/\/www.csoonline.com\/article\/4211140\/critical-gitlab-flaw-allows-attackers-to-delete-and-modify-public-repos.html&quot;}]}, {&quot;id&quot;: &quot;harness&quot;, &quot;type&quot;: &quot;vendor&quot;, &quot;label&quot;: &quot;Harness&quot;, &quot;weight&quot;: 2, &quot;articles&quot;: [{&quot;title&quot;: &quot;Harness Adds AI Agents to Automate DevSecOps Workflows at Machine Speed&quot;, &quot;url&quot;: &quot;https:\/\/devops.com\/harness-adds-ai-agents-to-automate-devsecops-workflows-at-machine-speed\/&quot;}, {&quot;title&quot;: &quot;Is Your New DevSecOps Tooling Reducing Work Or Just Adding to It?&quot;, &quot;url&quot;: &quot;https:\/\/devops.com\/is-your-new-devsecops-tooling-reducing-work-or-just-adding-to-it\/&quot;}]}, {&quot;id&quot;: &quot;dynatrace&quot;, &quot;type&quot;: &quot;vendor&quot;, &quot;label&quot;: &quot;Dynatrace \/ Arize&quot;, &quot;weight&quot;: 2, &quot;articles&quot;: [{&quot;title&quot;: &quot;Dynatrace Acquires Arize as AI Agents Deepen the Observability Challenge&quot;, &quot;url&quot;: &quot;https:\/\/devops.com\/dynatrace-acquires-arize-as-ai-agents-deepen-the-observability-challenge\/&quot;}, {&quot;title&quot;: &quot;Is Your New DevSecOps Tooling Reducing Work Or Just Adding to It?&quot;, &quot;url&quot;: &quot;https:\/\/devops.com\/is-your-new-devsecops-tooling-reducing-work-or-just-adding-to-it\/&quot;}]}], &quot;links&quot;: [{&quot;source&quot;: &quot;rustsupplychain&quot;, &quot;target&quot;: &quot;cratesio&quot;, &quot;weight&quot;: 4}, {&quot;source&quot;: &quot;rustsupplychain&quot;, &quot;target&quot;: &quot;arrayref&quot;, &quot;weight&quot;: 4}, {&quot;source&quot;: &quot;rustsupplychain&quot;, &quot;target&quot;: &quot;procmacro1&quot;, &quot;weight&quot;: 4}, {&quot;source&quot;: &quot;rustsupplychain&quot;, &quot;target&quot;: &quot;buildrs&quot;, &quot;weight&quot;: 4}, {&quot;source&quot;: &quot;rustsupplychain&quot;, &quot;target&quot;: &quot;stepsecurity&quot;, &quot;weight&quot;: 3}, {&quot;source&quot;: &quot;rustsupplychain&quot;, &quot;target&quot;: &quot;rustsec&quot;, &quot;weight&quot;: 2}, {&quot;source&quot;: &quot;rustsupplychain&quot;, &quot;target&quot;: &quot;dprk&quot;, &quot;weight&quot;: 2}, {&quot;source&quot;: &quot;rustsupplychain&quot;, &quot;target&quot;: &quot;npm&quot;, &quot;weight&quot;: 2}, {&quot;source&quot;: &quot;cratesio&quot;, &quot;target&quot;: &quot;arrayref&quot;, &quot;weight&quot;: 3}, {&quot;source&quot;: &quot;cratesio&quot;, &quot;target&quot;: &quot;buildrs&quot;, &quot;weight&quot;: 3}, {&quot;source&quot;: &quot;cratesio&quot;, &quot;target&quot;: &quot;rustsec&quot;, &quot;weight&quot;: 2}, {&quot;source&quot;: &quot;cratesio&quot;, &quot;target&quot;: &quot;procmacro1&quot;, &quot;weight&quot;: 2}, {&quot;source&quot;: &quot;arrayref&quot;, &quot;target&quot;: &quot;procmacro1&quot;, &quot;weight&quot;: 3}, {&quot;source&quot;: &quot;procmacro1&quot;, &quot;target&quot;: &quot;buildrs&quot;, &quot;weight&quot;: 3}, {&quot;source&quot;: &quot;procmacro1&quot;, &quot;target&quot;: &quot;dprk&quot;, &quot;weight&quot;: 2}, {&quot;source&quot;: &quot;buildrs&quot;, &quot;target&quot;: &quot;stepsecurity&quot;, &quot;weight&quot;: 2}, {&quot;source&quot;: &quot;gitlab&quot;, &quot;target&quot;: &quot;cve19478&quot;, &quot;weight&quot;: 4}, {&quot;source&quot;: &quot;gitlab&quot;, &quot;target&quot;: &quot;graphql&quot;, &quot;weight&quot;: 3}, {&quot;source&quot;: &quot;cve19478&quot;, &quot;target&quot;: &quot;graphql&quot;, &quot;weight&quot;: 3}, {&quot;source&quot;: &quot;cve19478&quot;, &quot;target&quot;: &quot;watchtowr&quot;, &quot;weight&quot;: 2}, {&quot;source&quot;: &quot;gitlab&quot;, &quot;target&quot;: &quot;watchtowr&quot;, &quot;weight&quot;: 2}, {&quot;source&quot;: &quot;cve19478&quot;, &quot;target&quot;: &quot;nvd&quot;, &quot;weight&quot;: 2}, {&quot;source&quot;: &quot;codingagents&quot;, &quot;target&quot;: &quot;slopsquat&quot;, &quot;weight&quot;: 4}, {&quot;source&quot;: &quot;codingagents&quot;, &quot;target&quot;: &quot;supplychainsurface&quot;, &quot;weight&quot;: 5}, {&quot;source&quot;: &quot;codingagents&quot;, &quot;target&quot;: &quot;agentsandbox&quot;, &quot;weight&quot;: 5}, {&quot;source&quot;: &quot;codingagents&quot;, &quot;target&quot;: &quot;agentidentity&quot;, &quot;weight&quot;: 4}, {&quot;source&quot;: &quot;codingagents&quot;, &quot;target&quot;: &quot;secureaicode&quot;, &quot;weight&quot;: 5}, {&quot;source&quot;: &quot;codingagents&quot;, &quot;target&quot;: &quot;codereview&quot;, &quot;weight&quot;: 5}, {&quot;source&quot;: &quot;codingagents&quot;, &quot;target&quot;: &quot;specs&quot;, &quot;weight&quot;: 4}, {&quot;source&quot;: &quot;codingagents&quot;, &quot;target&quot;: &quot;mcp&quot;, &quot;weight&quot;: 3}, {&quot;source&quot;: &quot;codingagents&quot;, &quot;target&quot;: &quot;rustai&quot;, &quot;weight&quot;: 3}, {&quot;source&quot;: &quot;codingagents&quot;, &quot;target&quot;: &quot;socket&quot;, &quot;weight&quot;: 3}, {&quot;source&quot;: &quot;codingagents&quot;, &quot;target&quot;: &quot;anthropic&quot;, &quot;weight&quot;: 3}, {&quot;source&quot;: &quot;codingagents&quot;, &quot;target&quot;: &quot;github&quot;, &quot;weight&quot;: 3}, {&quot;source&quot;: &quot;slopsquat&quot;, &quot;target&quot;: &quot;supplychainsurface&quot;, &quot;weight&quot;: 4}, {&quot;source&quot;: &quot;slopsquat&quot;, &quot;target&quot;: &quot;npm&quot;, &quot;weight&quot;: 3}, {&quot;source&quot;: &quot;slopsquat&quot;, &quot;target&quot;: &quot;socket&quot;, &quot;weight&quot;: 3}, {&quot;source&quot;: &quot;supplychainsurface&quot;, &quot;target&quot;: &quot;socket&quot;, &quot;weight&quot;: 4}, {&quot;source&quot;: &quot;supplychainsurface&quot;, &quot;target&quot;: &quot;mcp&quot;, &quot;weight&quot;: 3}, {&quot;source&quot;: &quot;supplychainsurface&quot;, &quot;target&quot;: &quot;agentidentity&quot;, &quot;weight&quot;: 3}, {&quot;source&quot;: &quot;supplychainsurface&quot;, &quot;target&quot;: &quot;npm&quot;, &quot;weight&quot;: 3}, {&quot;source&quot;: &quot;agentsandbox&quot;, &quot;target&quot;: &quot;agentidentity&quot;, &quot;weight&quot;: 4}, {&quot;source&quot;: &quot;agentsandbox&quot;, &quot;target&quot;: &quot;kubernetes&quot;, &quot;weight&quot;: 3}, {&quot;source&quot;: &quot;agentidentity&quot;, &quot;target&quot;: &quot;kubernetes&quot;, &quot;weight&quot;: 3}, {&quot;source&quot;: &quot;agentidentity&quot;, &quot;target&quot;: &quot;eks&quot;, &quot;weight&quot;: 2}, {&quot;source&quot;: &quot;agentidentity&quot;, &quot;target&quot;: &quot;secretscanning&quot;, &quot;weight&quot;: 2}, {&quot;source&quot;: &quot;awsauth&quot;, &quot;target&quot;: &quot;agentidentity&quot;, &quot;weight&quot;: 2}, {&quot;source&quot;: &quot;eks&quot;, &quot;target&quot;: &quot;awsauth&quot;, &quot;weight&quot;: 5}, {&quot;source&quot;: &quot;eks&quot;, &quot;target&quot;: &quot;kubernetes&quot;, &quot;weight&quot;: 5}, {&quot;source&quot;: &quot;awsauth&quot;, &quot;target&quot;: &quot;kubernetes&quot;, &quot;weight&quot;: 3}, {&quot;source&quot;: &quot;secureaicode&quot;, &quot;target&quot;: &quot;codereview&quot;, &quot;weight&quot;: 4}, {&quot;source&quot;: &quot;secureaicode&quot;, &quot;target&quot;: &quot;rustai&quot;, &quot;weight&quot;: 3}, {&quot;source&quot;: &quot;secureaicode&quot;, &quot;target&quot;: &quot;specs&quot;, &quot;weight&quot;: 3}, {&quot;source&quot;: &quot;secureaicode&quot;, &quot;target&quot;: &quot;codeql&quot;, &quot;weight&quot;: 2}, {&quot;source&quot;: &quot;codereview&quot;, &quot;target&quot;: &quot;specs&quot;, &quot;weight&quot;: 4}, {&quot;source&quot;: &quot;codereview&quot;, &quot;target&quot;: &quot;github&quot;, &quot;weight&quot;: 3}, {&quot;source&quot;: &quot;rustai&quot;, &quot;target&quot;: &quot;cratesio&quot;, &quot;weight&quot;: 2}, {&quot;source&quot;: &quot;github&quot;, &quot;target&quot;: &quot;codeql&quot;, &quot;weight&quot;: 5}, {&quot;source&quot;: &quot;github&quot;, &quot;target&quot;: &quot;githubactions&quot;, &quot;weight&quot;: 5}, {&quot;source&quot;: &quot;codeql&quot;, &quot;target&quot;: &quot;githubactions&quot;, &quot;weight&quot;: 4}, {&quot;source&quot;: &quot;anthropic&quot;, &quot;target&quot;: &quot;claudesecurity&quot;, &quot;weight&quot;: 5}, {&quot;source&quot;: &quot;claudesecurity&quot;, &quot;target&quot;: &quot;secureaicode&quot;, &quot;weight&quot;: 3}, {&quot;source&quot;: &quot;claudesecurity&quot;, &quot;target&quot;: &quot;codereview&quot;, &quot;weight&quot;: 2}, {&quot;source&quot;: &quot;socket&quot;, &quot;target&quot;: &quot;npm&quot;, &quot;weight&quot;: 3}, {&quot;source&quot;: &quot;socket&quot;, &quot;target&quot;: &quot;nvd&quot;, &quot;weight&quot;: 3}, {&quot;source&quot;: &quot;nvd&quot;, &quot;target&quot;: &quot;nist&quot;, &quot;weight&quot;: 5}, {&quot;source&quot;: &quot;chainguard&quot;, &quot;target&quot;: &quot;slsa&quot;, &quot;weight&quot;: 5}, {&quot;source&quot;: &quot;chainguard&quot;, &quot;target&quot;: &quot;provenance&quot;, &quot;weight&quot;: 4}, {&quot;source&quot;: &quot;slsa&quot;, &quot;target&quot;: &quot;provenance&quot;, &quot;weight&quot;: 4}, {&quot;source&quot;: &quot;provenance&quot;, &quot;target&quot;: &quot;npm&quot;, &quot;weight&quot;: 4}, {&quot;source&quot;: &quot;provenance&quot;, &quot;target&quot;: &quot;github&quot;, &quot;weight&quot;: 3}, {&quot;source&quot;: &quot;chainguard&quot;, &quot;target&quot;: &quot;kubernetes&quot;, &quot;weight&quot;: 2}, {&quot;source&quot;: &quot;stripesecrets&quot;, &quot;target&quot;: &quot;secretscanning&quot;, &quot;weight&quot;: 5}, {&quot;source&quot;: &quot;secretscanning&quot;, &quot;target&quot;: &quot;github&quot;, &quot;weight&quot;: 3}, {&quot;source&quot;: &quot;toolsprawl&quot;, &quot;target&quot;: &quot;harness&quot;, &quot;weight&quot;: 4}, {&quot;source&quot;: &quot;toolsprawl&quot;, &quot;target&quot;: &quot;dynatrace&quot;, &quot;weight&quot;: 3}, {&quot;source&quot;: &quot;harness&quot;, &quot;target&quot;: &quot;codingagents&quot;, &quot;weight&quot;: 3}]};\nconst TYPE_COLORS = {&quot;actor&quot;: &quot;#dc2626&quot;, &quot;malware&quot;: &quot;#991b1b&quot;, &quot;cve&quot;: &quot;#ea580c&quot;, &quot;product&quot;: &quot;#2563eb&quot;, &quot;vendor&quot;: &quot;#16a34a&quot;, &quot;researcher&quot;: &quot;#0d9488&quot;, &quot;person&quot;: &quot;#475569&quot;, &quot;location&quot;: &quot;#7c3aed&quot;, &quot;law&quot;: &quot;#ca8a04&quot;, &quot;campaign&quot;: &quot;#be185d&quot;, &quot;concept&quot;: &quot;#0891b2&quot;, &quot;standard&quot;: &quot;#64748b&quot;};\nconst TYPE_LABELS = {&quot;actor&quot;: &quot;Threat actor \/ APT&quot;, &quot;malware&quot;: &quot;Malware \/ worm&quot;, &quot;cve&quot;: &quot;CVE \/ vulnerability&quot;, &quot;product&quot;: &quot;Product \/ platform&quot;, &quot;vendor&quot;: &quot;Vendor \/ company&quot;, &quot;researcher&quot;: &quot;Researcher \/ source&quot;, &quot;person&quot;: &quot;Person&quot;, &quot;location&quot;: &quot;Country \/ region&quot;, &quot;law&quot;: &quot;Regulator \/ law enforcement&quot;, &quot;campaign&quot;: &quot;Campaign \/ event&quot;, &quot;concept&quot;: &quot;Theme \/ stat&quot;, &quot;standard&quot;: &quot;Standard \/ framework&quot;};\n\nconst wrap = document.getElementById(&#x27;canvas-wrap&#x27;);\nconst svg = d3.select(&#x27;#canvas&#x27;);\nlet width = wrap.clientWidth, height = wrap.clientHeight;\n\nconst g = svg.append(&#x27;g&#x27;);\n\nconst zoom = d3.zoom()\n  .scaleExtent([0.2, 6])\n  .on(&#x27;zoom&#x27;, (event) =&gt; g.attr(&#x27;transform&#x27;, event.transform));\nsvg.call(zoom);\n\ndocument.getElementById(&#x27;zoom-in&#x27;).onclick = () =&gt; svg.transition().duration(200).call(zoom.scaleBy, 1.3);\ndocument.getElementById(&#x27;zoom-out&#x27;).onclick = () =&gt; svg.transition().duration(200).call(zoom.scaleBy, 1\/1.3);\ndocument.getElementById(&#x27;zoom-reset&#x27;).onclick = () =&gt; svg.transition().duration(300).call(zoom.transform, d3.zoomIdentity);\n\nconst maxW = d3.max(DATA.nodes, d =&gt; d.weight) || 1;\nconst rScale = d3.scaleSqrt().domain([1, maxW]).range([8, 34]);\nconst maxEdgeW = d3.max(DATA.links, l =&gt; l.weight) || 1;\nconst edgeScale = d3.scaleLinear().domain([1, maxEdgeW]).range([1, 7]);\n\nconst simulation = d3.forceSimulation(DATA.nodes)\n  .force(&#x27;link&#x27;, d3.forceLink(DATA.links).id(d =&gt; d.id).distance(l =&gt; 90 + 10 * (5 - Math.min(l.weight,5))).strength(0.35))\n  .force(&#x27;charge&#x27;, d3.forceManyBody().strength(-420))\n  .force(&#x27;center&#x27;, d3.forceCenter(width \/ 2, height \/ 2))\n  .force(&#x27;collide&#x27;, d3.forceCollide(d =&gt; rScale(d.weight) + 18));\n\nconst link = g.append(&#x27;g&#x27;).attr(&#x27;class&#x27;, &#x27;links&#x27;)\n  .selectAll(&#x27;line&#x27;).data(DATA.links).join(&#x27;line&#x27;)\n  .attr(&#x27;class&#x27;, &#x27;link&#x27;)\n  .attr(&#x27;stroke-width&#x27;, d =&gt; edgeScale(d.weight));\n\nconst node = g.append(&#x27;g&#x27;).attr(&#x27;class&#x27;, &#x27;nodes&#x27;)\n  .selectAll(&#x27;circle&#x27;).data(DATA.nodes).join(&#x27;circle&#x27;)\n  .attr(&#x27;r&#x27;, d =&gt; rScale(d.weight))\n  .attr(&#x27;fill&#x27;, d =&gt; TYPE_COLORS[d.type] || &#x27;#64748b&#x27;)\n  .attr(&#x27;stroke&#x27;, &#x27;#ffffff&#x27;).attr(&#x27;stroke-width&#x27;, 1.5)\n  .style(&#x27;cursor&#x27;, &#x27;grab&#x27;)\n  .call(d3.drag()\n    .on(&#x27;start&#x27;, (event, d) =&gt; { if (!event.active) simulation.alphaTarget(0.2).restart(); d.fx = d.x; d.fy = d.y; })\n    .on(&#x27;drag&#x27;, (event, d) =&gt; { d.fx = event.x; d.fy = event.y; })\n    .on(&#x27;end&#x27;, (event, d) =&gt; { if (!event.active) simulation.alphaTarget(0); d.fx = null; d.fy = null; }));\n\nconst label = g.append(&#x27;g&#x27;).attr(&#x27;class&#x27;, &#x27;labels&#x27;)\n  .selectAll(&#x27;text&#x27;).data(DATA.nodes).join(&#x27;text&#x27;)\n  .attr(&#x27;class&#x27;, d =&gt; &#x27;node-label&#x27; + (d.weight &gt;= maxW * 0.7 ? &#x27; bold&#x27; : &#x27;&#x27;))\n  .attr(&#x27;dy&#x27;, d =&gt; -(rScale(d.weight) + 6))\n  .attr(&#x27;text-anchor&#x27;, &#x27;middle&#x27;)\n  .text(d =&gt; d.label);\n\nconst tooltip = d3.select(&#x27;#tooltip&#x27;);\nconst tooltipEl = document.getElementById(&#x27;tooltip&#x27;);\nlet hideTimer = null;\n\nfunction escapeHtml(s) {\n  return String(s).replace(\/&amp;\/g, &#x27;&amp;amp;&#x27;).replace(\/&lt;\/g, &#x27;&amp;lt;&#x27;).replace(\/&gt;\/g, &#x27;&amp;gt;&#x27;).replace(\/&quot;\/g, &#x27;&amp;quot;&#x27;);\n}\n\nfunction showTooltip(d) {\n  clearTimeout(hideTimer);\n  let html = &#x27;&lt;div class=&quot;tooltip-head&quot;&gt;&lt;strong&gt;&#x27; + escapeHtml(d.label) + &#x27;&lt;\/strong&gt;&lt;br&gt;&#x27; +\n    escapeHtml(TYPE_LABELS[d.type] || d.type) + &#x27; &amp;middot; &#x27; + d.weight + &#x27; mentions&lt;\/div&gt;&#x27;;\n  const articles = d.articles || [];\n  if (articles.length) {\n    html += &#x27;&lt;div class=&quot;tooltip-articles&quot;&gt;&lt;div class=&quot;tooltip-articles-title&quot;&gt;Related articles&lt;\/div&gt;&#x27; +\n      articles.map(a =&gt; &#x27;&lt;a href=&quot;&#x27; + escapeHtml(a.url) + &#x27;&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;&#x27; + escapeHtml(a.title) + &#x27;&lt;\/a&gt;&#x27;).join(&#x27;&#x27;) +\n      &#x27;&lt;\/div&gt;&#x27;;\n  }\n  tooltip.style(&#x27;opacity&#x27;, 1).html(html);\n}\n\nfunction hideTooltipNow() {\n  tooltip.style(&#x27;opacity&#x27;, 0);\n}\n\n\/\/ Hide only when the cursor leaves the WHOLE graph area (canvas + tooltip),\n\/\/ not when it leaves a node&#x27;s small circular hit-area. A per-node mouseout with a\n\/\/ short timer is a race: if the cursor takes even slightly longer than the timer to\n\/\/ travel from the node&#x27;s edge to the tooltip (which can be tall, with a scrollable\n\/\/ article list), it disappears before a click can land. Binding to the wrap&#x27;s\n\/\/ mouseleave instead means the tooltip only closes when you actually leave the graph,\n\/\/ or immediately when you click empty canvas space, or updates in place when you move\n\/\/ to a different node -- all far more forgiving.\nwrap.addEventListener(&#x27;mouseleave&#x27;, hideTooltipNow);\n\nsvg.on(&#x27;click&#x27;, (event) =&gt; {\n  if (event.target === svg.node()) hideTooltipNow();\n});\n\nnode.on(&#x27;mouseover&#x27;, (event, d) =&gt; showTooltip(d))\n  .on(&#x27;mousemove&#x27;, (event) =&gt; {\n    const [mx, my] = d3.pointer(event, wrap);\n    let left = mx + 16, top = my + 8;\n    const maxLeft = wrap.clientWidth - 296, maxTop = wrap.clientHeight - 40;\n    if (left &gt; maxLeft) left = Math.max(8, mx - 296);\n    if (top &gt; maxTop) top = Math.max(8, maxTop);\n    tooltip.style(&#x27;left&#x27;, left + &#x27;px&#x27;).style(&#x27;top&#x27;, top + &#x27;px&#x27;);\n  });\n\nfunction renderPositions() {\n  link.attr(&#x27;x1&#x27;, d =&gt; d.source.x).attr(&#x27;y1&#x27;, d =&gt; d.source.y)\n      .attr(&#x27;x2&#x27;, d =&gt; d.target.x).attr(&#x27;y2&#x27;, d =&gt; d.target.y);\n  node.attr(&#x27;cx&#x27;, d =&gt; d.x).attr(&#x27;cy&#x27;, d =&gt; d.y);\n  label.attr(&#x27;x&#x27;, d =&gt; d.x).attr(&#x27;y&#x27;, d =&gt; d.y);\n}\n\n\/\/ Fit the whole graph inside the visible canvas (accounting for node radius and the\n\/\/ label sitting just above each node) by computing the bounding box of all node\n\/\/ positions and applying a translate+scale transform through the existing zoom\n\/\/ behavior. duration=0 applies it instantly (used on first paint); a duration applies\n\/\/ a smooth transition (used after a resize).\nfunction zoomToFit(duration) {\n  if (!DATA.nodes.length) return;\n  let minX = Infinity, maxX = -Infinity, minY = Infinity, maxY = -Infinity;\n  DATA.nodes.forEach(d =&gt; {\n    const r = rScale(d.weight);\n    minX = Math.min(minX, d.x - r);\n    maxX = Math.max(maxX, d.x + r);\n    minY = Math.min(minY, d.y - r - 24); \/\/ extra headroom for the label above the node\n    maxY = Math.max(maxY, d.y + r);\n  });\n  const graphW = maxX - minX, graphH = maxY - minY;\n  if (graphW &lt;= 0 || graphH &lt;= 0) return;\n  const fitFraction = 0.9; \/\/ leave a small margin so edge nodes\/labels aren&#x27;t flush against the frame\n  const scale = Math.max(0.2, Math.min(2, fitFraction \/ Math.max(graphW \/ width, graphH \/ height)));\n  const tx = width \/ 2 - scale * (minX + maxX) \/ 2;\n  const ty = height \/ 2 - scale * (minY + maxY) \/ 2;\n  const transform = d3.zoomIdentity.translate(tx, ty).scale(scale);\n  if (duration &gt; 0) {\n    svg.transition().duration(duration).call(zoom.transform, transform);\n  } else {\n    svg.call(zoom.transform, transform);\n  }\n}\n\n\/\/ Pre-settle the force layout synchronously (no on-screen animation) so the very\n\/\/ first paint already shows a converged graph that&#x27;s fully framed by zoomToFit,\n\/\/ instead of nodes flying in from D3&#x27;s random initial scatter with the view\n\/\/ potentially clipping some of them before things settle.\nconst PRESETTLE_TICKS = 300;\nsimulation.stop();\nfor (let i = 0; i &lt; PRESETTLE_TICKS; i++) simulation.tick();\nrenderPositions();\nzoomToFit(0);\n\nsimulation.on(&#x27;tick&#x27;, renderPositions);\n\n\/\/ Legend: only show entity types actually present in this map.\nconst typesPresent = Array.from(new Set(DATA.nodes.map(d =&gt; d.type)));\nconst legend = document.getElementById(&#x27;legend&#x27;);\nlegend.innerHTML = &#x27;&lt;div class=&quot;legend-title&quot;&gt;Entity types&lt;\/div&gt;&#x27; + typesPresent.map(t =&gt;\n  &#x27;&lt;div class=&quot;legend-row&quot;&gt;&lt;span class=&quot;legend-dot&quot; style=&quot;background:&#x27; + (TYPE_COLORS[t] || &#x27;#64748b&#x27;) + &#x27;&quot;&gt;&lt;\/span&gt;&#x27; + (TYPE_LABELS[t] || t) + &#x27;&lt;\/div&gt;&#x27;\n).join(&#x27;&#x27;);\n\nwindow.addEventListener(&#x27;resize&#x27;, () =&gt; {\n  width = wrap.clientWidth; height = wrap.clientHeight;\n  simulation.force(&#x27;center&#x27;, d3.forceCenter(width \/ 2, height \/ 2));\n  simulation.alpha(0.3).restart();\n  zoomToFit(400);\n});\n&lt;\/script&gt;\n&lt;\/body&gt;\n&lt;\/html&gt;\n\" style=\"width:100%;height:82vh;min-height:600px;border:1px solid #e2e8f0;border-radius:8px;\" title=\"Interactive topic map\"><\/iframe><\/p>\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[34,11],"tags":[],"class_list":["post-5746","post","type-post","status-publish","format-standard","hentry","category-secure","category-trends"],"_links":{"self":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/5746","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=5746"}],"version-history":[{"count":1,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/5746\/revisions"}],"predecessor-version":[{"id":5764,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/5746\/revisions\/5764"}],"wp:attachment":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=5746"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=5746"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=5746"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}