Attackers didn't need a fake package this time. They hijacked #AsyncAPI's own CI/CD pipeline and shipped the malware through the real one – 2.9 million weekly downloads before anyone caught it. Full attack breakdown:
Ship trusted software, fast. Cloud-native artifact management for the AI era — security enforced before packages reach your build environment.
- Every container inherits its base image. If that image carries unpatched CVEs, your app does too, before you've written a line of code. Here's how to make @wiz_io WizOS hardened images the frictionless default across your org.
- Cloudsmith is now a @github secret scanning partner. If your API key ends up in a public repo, GitHub catches it and tells us. One more layer of control over your software supply chain 🛡️
- The logic is rather simple: if you can compromise the framework itself, you have the ability to compromise highly sensitive infrastructure. Today, it's happened again - this time #Mastra was the target. Full attack breakdown:
- Automate now > explain to regulators later. 87 days until the CRA's 24-hour reporting rule kicks in. We broke down what engineering teams should be working towards for compliance.

