DevSecOps
3 AI tools 4 articles
Advertisement
AI tools3
Aikido Security
All-in-one AppSec platform: SAST, SCA, IaC, secrets, DAST, and runtime protection — zero CI config required.
AI Directory
→
DryRun Security
AI-native contextual security for every pull request — catch exploitable risks before they merge, not after.
AI Directory
→
ZeroPath
AI-native AppSec that verifies findings before flagging them.
AI Directory
→
Articles4
Miasma Returns With 'Phantom Gyp': npm Worm Sidesteps the Install-Script Defences Teams Just Deployed
On 3 June, two days after the Red Hat npm compromise, the Miasma worm returned with a new delivery trick: a 15...
CY
11 Jun
Miasma: How a Hijacked CI Pipeline Shipped Malicious npm Packages With Valid Provenance
The Miasma supply-chain attack didn't typosquat or steal an npm token — it hijacked a maintainer's CI pipeline...
KE
8 Jun
Megalodon Campaign Backdoors 5,561 GitHub Repos in Six Hours — Inside the Largest GitHub Actions Supply-Chain Attack on Record
An automated campaign called Megalodon pushed 5,718 malicious commits to 5,561 GitHub repos between 18-21 May...
CY
21 May
Supply Chain Attacks Hit Record 454,600 Malicious Packages in 2025 — And AI Is to Blame
Malicious packages in public software repositories hit 454,600 in 2025, up from 55,000 in 2022. AI-assisted cr...
CY
28 Apr
Advertisement