Supply Chain

Supply Chain

Software supply chain security covering npm vulnerabilities, dependency risks, SBOM implementation, package security, and protecting against supply chain attacks.
04
Feb
Notepad++ update server compromise

Notepad++ Compromised for 6 Months: Check Your Version Now

Notepad++ update servers were compromised from June through December 2025 by a Chinese state-sponsored threat group. The attackers hijacked the
6 min read
15
Dec
npm Security: The Complete Guide to Package Vulnerabilities

npm Security: The Complete Guide to Package Vulnerabilities

npm processes 4.5 trillion package requests annually, representing 70% year-over-year growth (Sonatype, 2024). This scale makes the JavaScript ecosystem
12 min read
04
Dec
React2Shell vulnerability concept showing React Server Components leaking into a remote shell execution (CVE-2025-55182)

CVE-2025-55182: React2Shell Detection and Fix Guide

UPDATE (Jan 1, 2026): RondoDox botnet now weaponizing React2Shell. Shadowserver reports 90,300 instances still vulnerable. Multiple nation-state actors actively
19 min read
02
Dec
Why npm audit fix Isn't Working

Why npm audit fix Isn't Working

You ran npm audit fix, and nothing changed. The same warnings stare back at you. If this sounds familiar, you&
4 min read
01
Dec
Shai-Hulud npm Attack: What You Need to Know

Shai-Hulud npm Attack: What You Need to Know

Over 796 npm packages have been compromised by a self-replicating worm called Shai-Hulud, affecting more than 20 million weekly downloads
5 min read
31
Oct
How the threat landscape will look in 2026

Four Threat Shifts That Will Define the 2026 Security Landscape

How the threat landscape shifted in 2025 and what to expect in 2026
6 min read
31
Oct
Gartner's 2025 Supply Chain Prediction: A Retrospective Look at What Actually Happened

Gartner's 2025 Supply Chain Prediction: A Retrospective Look at What Actually Happened

In 2021, Gartner made a bold prediction: by 2025, 45% of organizations worldwide would experience attacks on their software supply
6 min read
18
Sep
Poisoned Packages: Auditing the NPM Supply Chain

Poisoned Packages: Auditing the NPM Supply Chain

Navigating the rise of self-replicating worms and credential theft in the open-source world
2 min read