Vm2 sandbox escapes: what it means for Node.js isolation controls
First post and replies | Last post by Mr NHI, 3 weeks ago
JetBrains IDE plugins stealing AI keys: what should teams do now?
First post and replies | Last post by Mr NHI, 3 weeks ago
Application risk management and identity gaps: what teams need now
First post and replies | Last post by Mr NHI, 3 weeks ago
Shai-Hulud npm malware variant: what IAM teams need to act on
First post and replies | Last post by Mr NHI, 3 weeks ago
Rocket.Chat file access and MongoDB ObjectId predictability: what failed?
First post and replies | Last post by Mr NHI, 3 weeks ago
Injective SDK supply chain attack: what wallet teams need to know
First post and replies | Last post by Mr NHI, 3 weeks ago
npm dependency poisoning: what it means for IAM and secrets teams
First post and replies | Last post by Mr NHI, 3 weeks ago
Polymarket-kit malware: what npm supply chain teams should watch now
First post and replies | Last post by Mr NHI, 3 weeks ago
AsyncAPI package backdoor: what GitHub Actions secret theft enabled
First post and replies | Last post by Mr NHI, 3 weeks ago
Shai-Hulud’s GitHub pivot: what does it mean for NHI governance?
First post and replies | Last post by Mr NHI, 3 weeks ago
Node-ipc malware in npm packages: what identity teams should watch
First post and replies | Last post by Mr NHI, 3 weeks ago
OpenClaw security risks: are your agent identity controls keeping up?
First post and replies | Last post by Mr NHI, 3 weeks ago
WordPress core RCE via SQL injection: are your controls keeping up?
First post and replies | Last post by Mr NHI, 3 weeks ago
Node-tar decompression bombs: are your archive controls keeping up?
First post and replies | Last post by Mr NHI, 3 weeks ago
Malicious Axios supply chain attack: what it means for IAM teams
First post and replies | Last post by Mr NHI, 3 weeks ago
LMDeploy SSRF and metadata exposure: what IAM teams need to know
First post and replies | Last post by Mr NHI, 3 weeks ago
OpenClaw-style agents and the identity gap teams are missing
First post and replies | Last post by Mr NHI, 3 weeks ago
Log4Shell and Java runtime RCE: what security teams missed
First post and replies | Last post by Mr NHI, 3 weeks ago
React2Shell and server components: are your controls keeping up?
First post and replies | Last post by Mr NHI, 3 weeks ago
AI capability supply chain abuse: are your MCP controls ready?
First post and replies | Last post by Mr NHI, 3 weeks ago