The Docket: ShinyHunters Shows SaaS Trust Is an Attack Path Microsoft's ShinyHunters research shows why OAuth grants, vendor integrations, and guest access now define SaaS breach risk.
The Docket: Gitea Docker Turned Proxy Trust Into Identity Bypass Gitea's Docker image shows why identity headers need a verified trust boundary, not just a reverse proxy in front.
Exhibit A(I): Claude Code Leak Turns Curiosity Into a Malware Trap A Claude Code source leak became bait for GitHub malware, exposing the legal and operational gap between leaked code and trusted software.
Explain This: CrewAI Vulnerability Chain and AI Agent Attack Surface Four unpatched CVEs in CrewAI expose how AI agent frameworks become attack vectors through prompt injection and code execution chains.
Breach Autopsy: NPM Typosquatting Attack Compromises 200+ Developer Environments Attackers registered 'requst' instead of 'request' and waited for typos to deliver malware to developer machines running npm install.
Exhibit A(I): CISA sounds alarm on Langflow RCE, Trivy supply chain compromise after rapid exploitation CISA has recently added two significant vulnerabilities - Langflow RCE and Trivy supply chain compromise - to its list of Known Exploited Vulnerabilities.
Policy Roast: LangChain's File Exposure Problem Is a Governance Failure, Not Just a Bug LangChain and LangGraph vulnerabilities expose files, secrets, and databases. The real problem? No security framework for AI development libraries.