[{"id":"pages:about","section":"pages","title":"Empowering developers to ship more secure products","summary":"Our mission is to empower every developer to ship the most secure products where security and speed are not at odds with each other. Developers should be able to write code freely with the right safeguards and assistance to move fast safely.","url":"/about","tags":[],"body":""},{"id":"pages:contact","section":"pages","title":"Contact","summary":"Get in touch with the Corgea team.","url":"/contact","tags":[],"body":""},{"id":"pages:demo","section":"pages","title":"Book a demo","summary":"Get a personalized walkthrough with the Corgea team.","url":"/demo","tags":[],"body":""},{"id":"pages:events/black-hat-las-vegas-2026","section":"pages","title":"Black Hat, BSides Las Vegas & DEF CON 2026","summary":"Meet Corgea at Black Hat, BSides Las Vegas, and DEF CON 2026. Visit our BSides booth, join the F1 Happy Hour, or book a meeting with Ahmad and Allen.","url":"/events/black-hat-las-vegas-2026","tags":[],"body":""},{"id":"pages:rsa-bsides-2026","section":"pages","title":"RSA Week & BSides SF 2026","summary":"Join Corgea during RSA week and BSides SF for the SPIN SF social, 1:1 meetings, and on-site booth conversations.","url":"/rsa-bsides-2026","tags":[],"body":""},{"id":"pages:security-research-program","section":"pages","title":"Security Research Program","summary":"Partner with Corgea to discover material vulnerabilities and get rewarded for impactful research.","url":"/security-research-program","tags":[],"body":""},{"id":"pages:trust-center","section":"pages","title":"Trust Center","summary":"Corgea is SOC 2 Type II compliant. Explore our security posture, compliance reports, subprocessors, and policies, and request our SOC 2 report.","url":"/trust-center","tags":[],"body":""},{"id":"blog:ai-application-security-how-ai-is-transforming-appsec-in-2026","section":"blog","title":"AI Application Security: How AI Is Transforming AppSec in 2026","summary":"Codebases are growing faster than security headcount, scanner output is a firehose of noise, and developers treat security findings like spam. AI application security is the fir...","url":"/blog/ai-application-security-how-ai-is-transforming-appsec-in-2026","tags":["Product"],"body":"Codebases are growing faster than security headcount, scanner output is a firehose of noise, and developers treat security findings like spam. AI application security is the fir..."},{"id":"blog:ai-powered-policy-creation-optimization-and-testing-all-in-one-place","section":"blog","title":"AI-Powered Policy Creation, Optimization, and Testing — All in One Place","summary":"Corgea’s Policy Playground & Optimizer empower security teams to craft AI-enhanced policies that catch real issues and cut noise, all in one seamless environment.","url":"/blog/ai-powered-policy-creation-optimization-and-testing-all-in-one-place","tags":["Product"],"body":"Corgea’s Policy Playground & Optimizer empower security teams to craft AI-enhanced policies that catch real issues and cut noise, all in one seamless environment."},{"id":"blog:announcing-beagle-the-next-generation-of-appsec-llms","section":"blog","title":"Announcing Beagle: The Next Generation of AppSec LLMs","summary":"We are proud to introduce Beagle, the latest version of Corgea's fine-tuned AppSec LLM. Beagle represents a groundbreaking leap in automated vulnerability management, combining...","url":"/blog/announcing-beagle-the-next-generation-of-appsec-llms","tags":["Product"],"body":"We are proud to introduce Beagle, the latest version of Corgea's fine-tuned AppSec LLM. Beagle represents a groundbreaking leap in automated vulnerability management, combining..."},{"id":"blog:announcing-corgea-s-github-app","section":"blog","title":"Announcing Corgea's GitHub App for automated PR fixes","summary":"Corgea’s GitHub app brings enterprise-level security to small teams by detecting vulnerabilities and suggesting fixes—like your own in-house security engineer","url":"/blog/announcing-corgea-s-github-app","tags":["Product"],"body":"Corgea’s GitHub app brings enterprise-level security to small teams by detecting vulnerabilities and suggesting fixes—like your own in-house security engineer"},{"id":"blog:announcing-new-language-support-c-and-net-for-automated-vulnerability-fixes","section":"blog","title":"Announcing New Language Support: C# and .Net for Automated Vulnerability Fixes","summary":"Corgea now supports automated code fixes for C# and .NET apps, extending our commitment to secure development across popular languages and frameworks.","url":"/blog/announcing-new-language-support-c-and-net-for-automated-vulnerability-fixes","tags":["Product"],"body":"Corgea now supports automated code fixes for C# and .NET apps, extending our commitment to secure development across popular languages and frameworks."},{"id":"blog:announcing-reachability-analysis-endpoint-aware-sast-in-corgea","section":"blog","title":"Announcing Reachability Analysis: Endpoint-Aware SAST in Corgea","summary":"Corgea’s new Reachability Analysis connects SAST findings to real web endpoints, showing which vulnerabilities are actually reachable from your API surface. Automatically maps e...","url":"/blog/announcing-reachability-analysis-endpoint-aware-sast-in-corgea","tags":["Product"],"body":"Corgea’s new Reachability Analysis connects SAST findings to real web endpoints, showing which vulnerabilities are actually reachable from your API surface. Automatically maps e..."},{"id":"blog:automate-your-security-introducing-corgea-s-scheduled-scans","section":"blog","title":"Automate Your Security: Introducing Corgea's Scheduled Scans","summary":"Automate your security workflows with Corgea's new Scheduled Scans feature. Set up recurring SAST, SCA, secrets, and PII scans across projects with flexible scheduling, intellig...","url":"/blog/automate-your-security-introducing-corgea-s-scheduled-scans","tags":["Product"],"body":"Automate your security workflows with Corgea's new Scheduled Scans feature. Set up recurring SAST, SCA, secrets, and PII scans across projects with flexible scheduling, intellig..."},{"id":"blog:best-java-static-code-analyzer-top-tools-ranked","section":"blog","title":"13 Best Java Static Code Analysis Tools in 2026 (Ranked)","summary":"The best Java static code analysis tools for security, code quality and CI/CD in 2026, with a comparison table, framework awareness, auto-fix and pricing.","url":"/blog/best-java-static-code-analyzer-top-tools-ranked","tags":["java","static-analysis","sast","code-quality","Product"],"body":"The best Java static code analysis tools for security, code quality and CI/CD in 2026, with a comparison table, framework awareness, auto-fix and pricing."},{"id":"blog:changelog-august-13-2026","section":"blog","title":"Changelog - August 13, 2026","summary":"This week's Corgea changelog highlights the new Vulnerability Workbench, bulk triage ingestion with approval workflows, and stronger sign-in resilience with email one-time passwords.","url":"/blog/changelog-august-13-2026","tags":["Changelog","Product","Product"],"body":"This week's Corgea changelog highlights the new Vulnerability Workbench, bulk triage ingestion with approval workflows, and stronger sign-in resilience with email one-time passwords."},{"id":"blog:changelog-august-20-2026","section":"blog","title":"Changelog - August 20, 2026","summary":"This week's Corgea changelog highlights private package registry support, Rust scanning coverage, and controlled bulk triage actions for agent workflows.","url":"/blog/changelog-august-20-2026","tags":["Changelog","Product","Product"],"body":"This week's Corgea changelog highlights private package registry support, Rust scanning coverage, and controlled bulk triage actions for agent workflows."},{"id":"blog:changelog-august-27-2026","section":"blog","title":"Changelog - August 27, 2026","summary":"This week's Corgea changelog post focuses on broader webhook coverage, richer SARIF exports for SCA findings, and private package registry support from the latest public releases in Corgea Docs.","url":"/blog/changelog-august-27-2026","tags":["Changelog","Product","Product"],"body":"This week's Corgea changelog post focuses on broader webhook coverage, richer SARIF exports for SCA findings, and private package registry support from the latest public releases in Corgea Docs."},{"id":"blog:changelog-august-6-2026","section":"blog","title":"Changelog - August 6, 2026","summary":"This week's Corgea changelog highlights dynamic team access, scheduled IaC and container scans, and clearer failure diagnostics in scan API responses.","url":"/blog/changelog-august-6-2026","tags":["Changelog","Product","Product"],"body":"This week's Corgea changelog highlights dynamic team access, scheduled IaC and container scans, and clearer failure diagnostics in scan API responses."},{"id":"blog:changelog-july-16-2026","section":"blog","title":"Changelog - July 16, 2026","summary":"This week's Corgea changelog post highlights the latest public release notes, including new reporting visibility into generated fixes and duplicate cleanup, plus more reliable GitHub pull request check updates.","url":"/blog/changelog-july-16-2026","tags":["Changelog","Product","Product"],"body":"This week's Corgea changelog post highlights the latest public release notes, including new reporting visibility into generated fixes and duplicate cleanup, plus more reliable GitHub pull request check updates."},{"id":"blog:changelog-july-2-2026","section":"blog","title":"Changelog - July 2, 2026","summary":"This week's Corgea changelog highlights AI Penetration Testing, new dependency inventory workflows in the Corgea Agent, and better documentation for project-level scan exclusions.","url":"/blog/changelog-july-2-2026","tags":["Changelog","Product","Product"],"body":"This week's Corgea changelog highlights AI Penetration Testing, new dependency inventory workflows in the Corgea Agent, and better documentation for project-level scan exclusions."},{"id":"blog:changelog-july-23-2026","section":"blog","title":"Changelog - July 23, 2026","summary":"This week's Corgea changelog highlights better scan coverage visibility, malicious dependency blocking, and broader search and export workflows for SCA and IaC findings.","url":"/blog/changelog-july-23-2026","tags":["Changelog","Product","Product"],"body":"This week's Corgea changelog highlights better scan coverage visibility, malicious dependency blocking, and broader search and export workflows for SCA and IaC findings."},{"id":"blog:changelog-july-30-2026","section":"blog","title":"Changelog - July 30, 2026","summary":"This week's Corgea changelog highlights new Linear ticketing from findings, branded PDF exports for scan reports, and simpler self-service SSO group mapping.","url":"/blog/changelog-july-30-2026","tags":["Changelog","Product","Product"],"body":"This week's Corgea changelog highlights new Linear ticketing from findings, branded PDF exports for scan reports, and simpler self-service SSO group mapping."},{"id":"blog:changelog-july-9-2026","section":"blog","title":"Changelog - July 9, 2026","summary":"This week's Corgea changelog highlights new reporting visibility into fixes generated, cleaner duplicate triage reporting, and more reliable GitHub pull request check updates.","url":"/blog/changelog-july-9-2026","tags":["Changelog","Product","Product"],"body":"This week's Corgea changelog highlights new reporting visibility into fixes generated, cleaner duplicate triage reporting, and more reliable GitHub pull request check updates."},{"id":"blog:changelog-june-11-2026","section":"blog","title":"Changelog - June 11, 2026","summary":"This week's Corgea changelog highlights on-demand fix generation, branch-level reporting filters, and richer SCA advisory details.","url":"/blog/changelog-june-11-2026","tags":["Changelog","Product","Product"],"body":"This week's Corgea changelog highlights on-demand fix generation, branch-level reporting filters, and richer SCA advisory details."},{"id":"blog:changelog-june-18-2026","section":"blog","title":"Changelog - June 18, 2026","summary":"This week's Corgea changelog highlights the new Skills Registry, policy API access, and SLA-aware vulnerability search.","url":"/blog/changelog-june-18-2026","tags":["Changelog","Product","Product"],"body":"This week's Corgea changelog highlights the new Skills Registry, policy API access, and SLA-aware vulnerability search."},{"id":"blog:changelog-june-25-2026","section":"blog","title":"Changelog - June 25, 2026","summary":"This week's Corgea changelog post highlights the latest public release notes, including the Skills Registry, policy API access, and bulk Content Access Management workflows.","url":"/blog/changelog-june-25-2026","tags":["Changelog","Product","Product"],"body":"This week's Corgea changelog post highlights the latest public release notes, including the Skills Registry, policy API access, and bulk Content Access Management workflows."},{"id":"blog:changelog-june-4-2026","section":"blog","title":"Changelog - June 4, 2026","summary":"This week's Corgea changelog highlights faster project tag management, more resilient large scan uploads, and more reliable GitHub App pull request scanning.","url":"/blog/changelog-june-4-2026","tags":["Changelog","Product","Product"],"body":"This week's Corgea changelog highlights faster project tag management, more resilient large scan uploads, and more reliable GitHub App pull request scanning."},{"id":"blog:changelog-may-13-2026","section":"blog","title":"Changelog - May 13, 2026","summary":"This week's Corgea changelog highlights Harness Code integration, sharper secret scanning, and stronger endpoint discovery in the scanning engine.","url":"/blog/changelog-may-13-2026","tags":["Changelog","Product","Product"],"body":"This week's Corgea changelog highlights Harness Code integration, sharper secret scanning, and stronger endpoint discovery in the scanning engine."},{"id":"blog:changelog-may-21-2026","section":"blog","title":"Changelog - May 21, 2026","summary":"This week's Corgea changelog highlights scheduled scan webhook filters, project-tag scoped PR rules, and broader, cleaner scan analysis.","url":"/blog/changelog-may-21-2026","tags":["Changelog","Product","Product"],"body":"This week's Corgea changelog highlights scheduled scan webhook filters, project-tag scoped PR rules, and broader, cleaner scan analysis."},{"id":"blog:changelog-may-28-2026","section":"blog","title":"Changelog - May 28, 2026","summary":"This week's Corgea changelog highlights SCA support in SLA Management, Security Design Review beta, and broader API and MCP access to security data.","url":"/blog/changelog-may-28-2026","tags":["Changelog","Product","Product"],"body":"This week's Corgea changelog highlights SCA support in SLA Management, Security Design Review beta, and broader API and MCP access to security data."},{"id":"blog:changelog-september-10-2026","section":"blog","title":"Changelog - September 10, 2026","summary":"This week's Corgea changelog adds API finding groups, a synchronous option for Generate Fix, and clearer reasons for false-positive and accepted-risk decisions.","url":"/blog/changelog-september-10-2026","tags":["Changelog","Product","Product"],"body":"This week's Corgea changelog adds API finding groups, a synchronous option for Generate Fix, and clearer reasons for false-positive and accepted-risk decisions."},{"id":"blog:changelog-september-5-2026","section":"blog","title":"Changelog - September 5, 2026","summary":"This week's Corgea changelog covers approval workflows for triage decisions, Bitbucket scan support, and a simpler way to connect AI agents to Corgea through MCP.","url":"/blog/changelog-september-5-2026","tags":["Changelog","Product","Product"],"body":"This week's Corgea changelog covers approval workflows for triage decisions, Bitbucket scan support, and a simpler way to connect AI agents to Corgea through MCP."},{"id":"blog:compare/checkmarx-vs-veracode","section":"blog","title":"Checkmarx vs Veracode: Full Comparison + Why Teams Are Choosing Corgea","summary":"Compare Checkmarx and Veracode side by side on enterprise SAST, governance, developer workflow, remediation, and buying fit. See how Corgea stacks up.","url":"/blog/compare/checkmarx-vs-veracode","tags":["Checkmarx","Veracode","Corgea","AppSec","DevSecOps","Comparison"],"body":"Compare Checkmarx and Veracode side by side on enterprise SAST, governance, developer workflow, remediation, and buying fit. See how Corgea stacks up."},{"id":"blog:compare/snyk-vs-checkmarx","section":"blog","title":"Snyk vs Checkmarx: Full Comparison + Why Teams Are Choosing Corgea","summary":"Compare Snyk and Checkmarx side by side on security coverage, developer experience, accuracy, pricing, and auto-remediation. See how Corgea stacks up.","url":"/blog/compare/snyk-vs-checkmarx","tags":["Snyk","Checkmarx","Corgea","AppSec","DevSecOps","Comparison"],"body":"Compare Snyk and Checkmarx side by side on security coverage, developer experience, accuracy, pricing, and auto-remediation. See how Corgea stacks up."},{"id":"blog:compare/snyk-vs-semgrep","section":"blog","title":"Snyk vs Semgrep: Full Comparison + Why Teams Are Choosing Corgea","summary":"Compare Snyk and Semgrep side by side on security coverage, developer experience, accuracy, pricing, and auto-remediation. See how Corgea stacks up.","url":"/blog/compare/snyk-vs-semgrep","tags":["Snyk","Semgrep","Corgea","AppSec","DevSecOps","Comparison"],"body":"Compare Snyk and Semgrep side by side on security coverage, developer experience, accuracy, pricing, and auto-remediation. See how Corgea stacks up."},{"id":"blog:compare/snyk-vs-veracode","section":"blog","title":"Snyk vs Veracode: Full Comparison + Why Teams Are Choosing Corgea","summary":"Compare Snyk and Veracode side by side on security coverage, developer experience, governance, remediation workflow, and buying fit. See how Corgea stacks up.","url":"/blog/compare/snyk-vs-veracode","tags":["Snyk","Veracode","Corgea","AppSec","DevSecOps","Comparison"],"body":"Compare Snyk and Veracode side by side on security coverage, developer experience, governance, remediation workflow, and buying fit. See how Corgea stacks up."},{"id":"blog:compare/sonarqube-vs-checkmarx","section":"blog","title":"SonarQube vs Checkmarx: Full Comparison + Why Teams Are Choosing Corgea","summary":"Compare SonarQube and Checkmarx side by side on security coverage, developer experience, accuracy, pricing, and auto-remediation. See how Corgea stacks up.","url":"/blog/compare/sonarqube-vs-checkmarx","tags":["SonarQube","Checkmarx","Corgea","AppSec","DevSecOps","Comparison"],"body":"Compare SonarQube and Checkmarx side by side on security coverage, developer experience, accuracy, pricing, and auto-remediation. See how Corgea stacks up."},{"id":"blog:compare/sonarqube-vs-snyk","section":"blog","title":"SonarQube vs Snyk: Full Comparison + Why Teams Are Choosing Corgea","summary":"Compare SonarQube and Snyk side by side on security coverage, developer experience, accuracy, pricing, and auto-remediation. See how Corgea stacks up.","url":"/blog/compare/sonarqube-vs-snyk","tags":["SonarQube","Snyk","Corgea","AppSec","DevSecOps","Comparison"],"body":"Compare SonarQube and Snyk side by side on security coverage, developer experience, accuracy, pricing, and auto-remediation. See how Corgea stacks up."},{"id":"blog:compare/sonarqube-vs-veracode","section":"blog","title":"SonarQube vs Veracode: Full Comparison + Why Teams Are Choosing Corgea","summary":"Compare SonarQube and Veracode side by side on security coverage, developer experience, accuracy, pricing, and auto-remediation. See how Corgea stacks up.","url":"/blog/compare/sonarqube-vs-veracode","tags":["SonarQube","Veracode","Corgea","AppSec","DevSecOps","Comparison"],"body":"Compare SonarQube and Veracode side by side on security coverage, developer experience, accuracy, pricing, and auto-remediation. See how Corgea stacks up."},{"id":"blog:corgea-announces-gitlab-integration","section":"blog","title":"Corgea Announces GitLab Integration","summary":"Corgea, the leading automated code security platform, is excited to announce its integration with GitLab, the popular web-based DevOps lifecycle tool. This integration allows de...","url":"/blog/corgea-announces-gitlab-integration","tags":["Product"],"body":"Corgea, the leading automated code security platform, is excited to announce its integration with GitLab, the popular web-based DevOps lifecycle tool. This integration allows de..."},{"id":"blog:corgea-announces-integration-with-fortify-to-enhance-application-security-for-enterprises","section":"blog","title":"Corgea Announces Integration with Fortify to Enhance Application Security for Enterprises","summary":"Corgea partners with Fortify to bring AI-driven triage and remediation to enterprise SAST, helping complex organizations strengthen app security at scale.","url":"/blog/corgea-announces-integration-with-fortify-to-enhance-application-security-for-enterprises","tags":["Product"],"body":"Corgea partners with Fortify to bring AI-driven triage and remediation to enterprise SAST, helping complex organizations strengthen app security at scale."},{"id":"blog:corgea-announces-new-integration-with-codeql-reports-to-streamline-security-fixes","section":"blog","title":"Corgea Announces New Integration with CodeQL Reports to Streamline Security Fixes","summary":"Corgea now supports fixing CodeQL-detected vulnerabilities with seamless, automated remediation integrated directly into your workflow.","url":"/blog/corgea-announces-new-integration-with-codeql-reports-to-streamline-security-fixes","tags":["Product"],"body":"Corgea now supports fixing CodeQL-detected vulnerabilities with seamless, automated remediation integrated directly into your workflow."},{"id":"blog:corgea-expands-language-support-c-c-kotlin-and-php-for-enhanced-code-security","section":"blog","title":"Corgea Expands Language Support: C, C++, Kotlin, and PHP for Enhanced Code Security","summary":"Corgea is excited to announce the expansion of its language support to include C, C++, Kotlin, and PHP. We know how critical comprehensive language and framework support is for...","url":"/blog/corgea-expands-language-support-c-c-kotlin-and-php-for-enhanced-code-security","tags":["Product"],"body":"Corgea is excited to announce the expansion of its language support to include C, C++, Kotlin, and PHP. We know how critical comprehensive language and framework support is for..."},{"id":"blog:corgea-integration-with-azure-devops-enhancing-code-security-through-ai","section":"blog","title":"Corgea Integration with Azure DevOps: Enhancing Code Security Through AI","summary":"Corgea now integrates with Azure DevOps, enabling seamless, AI-powered code correction and security directly in your DevOps workflows.","url":"/blog/corgea-integration-with-azure-devops-enhancing-code-security-through-ai","tags":["Product"],"body":"Corgea now integrates with Azure DevOps, enabling seamless, AI-powered code correction and security directly in your DevOps workflows."},{"id":"blog:corgea-named-best-sast-auto-fixing-solution-in-recent-analyst-report","section":"blog","title":"Corgea Named Best SAST Auto-Fixing Solution in Recent Analyst Report","summary":"We’re excited to share that Corgea has been recognized as the best SAST auto-fixing solution in the latest Actually Useful Product Guide report for Q1 2025. This recognition val...","url":"/blog/corgea-named-best-sast-auto-fixing-solution-in-recent-analyst-report","tags":["Product"],"body":"We’re excited to share that Corgea has been recognized as the best SAST auto-fixing solution in the latest Actually Useful Product Guide report for Q1 2025. This recognition val..."},{"id":"blog:corgea-now-supports-vulnerability-fixes-in-java-go-and-ruby","section":"blog","title":"Corgea Now Supports Vulnerability Fixes in Java, Go, and Ruby","summary":"Corgea expands automated code fixes to Java, Go, and Ruby, ensuring comprehensive security coverage for widely-used programming languages.","url":"/blog/corgea-now-supports-vulnerability-fixes-in-java-go-and-ruby","tags":["Product"],"body":"Corgea expands automated code fixes to Java, Go, and Ruby, ensuring comprehensive security coverage for widely-used programming languages."},{"id":"blog:corgea-recognized-as-an-idc-innovator-for-devsecops-automated-remediation","section":"blog","title":"Corgea Recognized as an IDC Innovator for DevSecOps Automated Remediation","summary":"Corgea named an IDC Innovator for DevSecOps Automated Remediation, recognized for pioneering AI-driven secure code automation and innovation.","url":"/blog/corgea-recognized-as-an-idc-innovator-for-devsecops-automated-remediation","tags":["Product"],"body":"Corgea named an IDC Innovator for DevSecOps Automated Remediation, recognized for pioneering AI-driven secure code automation and innovation."},{"id":"blog:corgea-reporting-security-and-developer-insights-in-one-view","section":"blog","title":"Corgea Reporting: Security and Developer Insights in One View","summary":"Track code, dependency, code quality, IaC, scan activity, aging, and developer insights in one place. Filter reporting by project, tags, and time to see trends clearly.","url":"/blog/corgea-reporting-security-and-developer-insights-in-one-view","tags":["Product"],"body":"Track code, dependency, code quality, IaC, scan activity, aging, and developer insights in one place. Filter reporting by project, tags, and time to see trends clearly."},{"id":"blog:corgea-s-new-github-action","section":"blog","title":"Corgea's New GitHub Action","summary":"Corgea now integrates with GitHub Actions, empowering developers to detect and fix vulnerable code seamlessly within their CI/CD workflow.","url":"/blog/corgea-s-new-github-action","tags":["Product"],"body":"Corgea now integrates with GitHub Actions, empowering developers to detect and fix vulnerable code seamlessly within their CI/CD workflow."},{"id":"blog:corgea-vs-aikido-security-benchmark","section":"blog","title":"Corgea vs. Aikido: We benchmarked SAST on a deliberately vulnerable repo","summary":"Aikido was slightly more precise in this benchmark, but missed 34 of 47 confirmed issues. Corgea found 42, reached 89.36% recall, and delivered the stronger F1 score.","url":"/blog/corgea-vs-aikido-security-benchmark","tags":["benchmark","sast","aikido","appsec","ai-security","Research"],"body":"Aikido was slightly more precise in this benchmark, but missed 34 of 47 confirmed issues. Corgea found 42, reached 89.36% recall, and delivered the stronger F1 score."},{"id":"blog:corgea-vs-snyk-security-benchmark","section":"blog","title":"Corgea vs. Snyk: We benchmarked SAST on a deliberately vulnerable repo","summary":"On the same fixed benchmark basis as our Aikido comparison, Corgea found 42 of 47 confirmed issues and led on precision, recall, and F1. Snyk found 26, missing 21 of the confirmed set.","url":"/blog/corgea-vs-snyk-security-benchmark","tags":["benchmark","sast","snyk","appsec","ai-security","Research"],"body":"On the same fixed benchmark basis as our Aikido comparison, Corgea found 42 of 47 confirmed issues and led on precision, recall, and F1. Snyk found 26, missing 21 of the confirmed set."},{"id":"blog:fine-tuning-for-precision-and-privacy-how-corgea-s-llm-enhances-enterprise-application-security","section":"blog","title":"Fine-Tuning for Precision and Privacy: How Corgea's LLM Enhances Enterprise Application Security","summary":"Corgea: AI-powered AppSec engineer for enterprises, cutting false positives by 30% and speeding remediation by 80% with secure, private fine-tuned models.","url":"/blog/fine-tuning-for-precision-and-privacy-how-corgea-s-llm-enhances-enterprise-application-security","tags":["Product"],"body":"Corgea: AI-powered AppSec engineer for enterprises, cutting false positives by 30% and speeding remediation by 80% with secure, private fine-tuned models."},{"id":"blog:given-enough-inference-all-bugs-all-shallow","section":"blog","title":"Mythos: Given Enough Inference, All Bugs Are Shallow","summary":"Anthropic's Mythos showed that given enough inference, all bugs are shallow. But who pays for the inference? We benchmarked Claude Opus 4.6 against Corgea v1 and v2 to show why purpose-built scanner architecture beats raw model capability on precision, recall, cost, and speed.","url":"/blog/given-enough-inference-all-bugs-all-shallow","tags":["Product"],"body":"Anthropic's Mythos showed that given enough inference, all bugs are shallow. But who pays for the inference? We benchmarked Claude Opus 4.6 against Corgea v1 and v2 to show why purpose-built scanner architecture beats raw model capability on precision, recall, cost, and speed."},{"id":"blog:here-s-what-happening-the-last-72-hours-700-packages-compromised-in-major-supply-chain-breach-november-25-2025","section":"blog","title":"Here's what happening the last 72-hours: 700+ Packages Compromised from Shai-Hulud 2.0 Worm (November 25, 2025)","summary":"Critical npm worm compromises 700+ packages including Zapier, PostHog, and Postman. 25,000+ GitHub repos infected, exposing 775+ tokens. Immediate mitigation steps inside.","url":"/blog/here-s-what-happening-the-last-72-hours-700-packages-compromised-in-major-supply-chain-breach-november-25-2025","tags":["Product"],"body":"Critical npm worm compromises 700+ packages including Zapier, PostHog, and Postman. 25,000+ GitHub repos infected, exposing 775+ tokens. Immediate mitigation steps inside."},{"id":"blog:how-corgea-improve-fix-accuracy-and-coverage","section":"blog","title":"How Corgea Improves Fix Accuracy and Coverage?","summary":"Corgea explains how its AI-driven platform improves SAST fix accuracy and coverage, delivering precise code fixes and reducing false positives for developers.","url":"/blog/how-corgea-improve-fix-accuracy-and-coverage","tags":["Product"],"body":"Corgea explains how its AI-driven platform improves SAST fix accuracy and coverage, delivering precise code fixes and reducing false positives for developers."},{"id":"blog:how-does-corgea-work","section":"blog","title":"How does Corgea work?","summary":"Corgea connects to SAST tools like Snyk & Semgrep, writes AI-powered fixes with explanations, saving security teams 80% effort & speeding up patching.","url":"/blog/how-does-corgea-work","tags":["Product"],"body":"Corgea connects to SAST tools like Snyk & Semgrep, writes AI-powered fixes with explanations, saving security teams 80% effort & speeding up patching."},{"id":"blog:improved-multi-file-analysis-and-false-positive-reduction","section":"blog","title":"Improved Multi-File Analysis and False Positive Reduction","summary":"Corgea’s upgraded multi-file analysis engine redefines static analysis by mapping your codebase context, analyzing file relationships, and understanding true system behavior.","url":"/blog/improved-multi-file-analysis-and-false-positive-reduction","tags":["Product"],"body":"Corgea’s upgraded multi-file analysis engine redefines static analysis by mapping your codebase context, analyzing file relationships, and understanding true system behavior."},{"id":"blog:introducing-ai-pentesting","section":"blog","title":"Introducing Corgea AI Pentesting","summary":"Autonomous penetration testing that thinks like a pentesting team. Multi-agent architecture. Code-aware, not black-box. 4-8 hours instead of 2 weeks.","url":"/blog/introducing-ai-pentesting","tags":["Launch Week","AI Pentesting","Product","Product"],"body":"Autonomous penetration testing that thinks like a pentesting team. Multi-agent architecture. Code-aware, not black-box. 4-8 hours instead of 2 weeks."},{"id":"blog:introducing-auto-discovery-and-learning","section":"blog","title":"Corgea Auto-Discovery and Learning","summary":"Corgea now studies your codebase before scanning it, and learns from every developer feedback action. No more generic scanners. No more repeating the same false positives.","url":"/blog/introducing-auto-discovery-and-learning","tags":["Launch Week","Auto-Discovery","Learning","Product","Product"],"body":"Corgea now studies your codebase before scanning it, and learns from every developer feedback action. No more generic scanners. No more repeating the same false positives."},{"id":"blog:introducing-blast-the-future-of-security-testing-is-here","section":"blog","title":"Introducing BLAST: The Future of Security Testing is Here","summary":"Corgea launches BLAST: an AI-powered platform to uncover and fix hidden business logic vulnerabilities, protecting enterprises from advanced cyber threats.","url":"/blog/introducing-blast-the-future-of-security-testing-is-here","tags":["Product"],"body":"Corgea launches BLAST: an AI-powered platform to uncover and fix hidden business logic vulnerabilities, protecting enterprises from advanced cyber threats."},{"id":"blog:introducing-corgea","section":"blog","title":"Introducing Corgea","summary":"Corgea launches! Automatically secure vulnerable source code with AI-powered fixes, reducing effort by 80% and accelerating secure development.","url":"/blog/introducing-corgea","tags":["Product"],"body":"Corgea launches! Automatically secure vulnerable source code with AI-powered fixes, reducing effort by 80% and accelerating secure development."},{"id":"blog:introducing-corgea-codeiq-smarter-detection-triaging-and-fixing-of-insecure-code","section":"blog","title":"Introducing Corgea CodeIQ: Smarter Detection, Triaging, and Fixing of Insecure Code","summary":"Introducing Corgea CodeIQ: Understand your codebase deeply, map code to the broader system, and revolutionize secure code analysis for developers and security teams.","url":"/blog/introducing-corgea-codeiq-smarter-detection-triaging-and-fixing-of-insecure-code","tags":["Product"],"body":"Introducing Corgea CodeIQ: Understand your codebase deeply, map code to the broader system, and revolutionize secure code analysis for developers and security teams."},{"id":"blog:introducing-corgea-dependency-scanning","section":"blog","title":"Introducing Corgea Dependency Scanning","summary":"Stay ahead of open-source risks with Corgea’s new Dependency Scanning. Automatically detect vulnerabilities, enforce licenses, and apply grouped fix versions across multiple eco...","url":"/blog/introducing-corgea-dependency-scanning","tags":["Product"],"body":"Stay ahead of open-source risks with Corgea’s new Dependency Scanning. Automatically detect vulnerabilities, enforce licenses, and apply grouped fix versions across multiple eco..."},{"id":"blog:introducing-corgea-reporting","section":"blog","title":"Introducing Corgea Reporting","summary":"Corgea launches a powerful reporting feature for AppSec and software engineers to track security posture, spot patterns, and drive measurable savings.","url":"/blog/introducing-corgea-reporting","tags":["Product"],"body":"Corgea launches a powerful reporting feature for AppSec and software engineers to track security posture, spot patterns, and drive measurable savings."},{"id":"blog:introducing-corgea-s-appsec-llm-precision-privacy-and-performance-for-enterprise-security","section":"blog","title":"Introducing Corgea's AppSec LLM: Precision, Privacy, and Performance for Enterprise Security","summary":"Introducing Corgea’s AppSec LLM: a private, enterprise-grade language model delivering precise vulnerability detection and secure, privacy-focused remediation.","url":"/blog/introducing-corgea-s-appsec-llm-precision-privacy-and-performance-for-enterprise-security","tags":["Product"],"body":"Introducing Corgea’s AppSec LLM: a private, enterprise-grade language model delivering precise vulnerability detection and secure, privacy-focused remediation."},{"id":"blog:introducing-corgea-s-github-app","section":"blog","title":"Introducing \"Corgea's GitHub App\"","summary":"Corgea launches its GitHub App, delivering automated vulnerability patches via pull requests—seamlessly integrated into your team’s development workflow.","url":"/blog/introducing-corgea-s-github-app","tags":["Product"],"body":"Corgea launches its GitHub App, delivering automated vulnerability patches via pull requests—seamlessly integrated into your team’s development workflow."},{"id":"blog:introducing-corgea-s-new-feature-detecting-false-positives","section":"blog","title":"Introducing: Corgea's Advanced False Positive Detection","summary":"Corgea introduces Advanced False Positive Detection for SAST, helping developers and security teams save time by reducing noise and focusing on real issues.","url":"/blog/introducing-corgea-s-new-feature-detecting-false-positives","tags":["Product"],"body":"Corgea introduces Advanced False Positive Detection for SAST, helping developers and security teams save time by reducing noise and focusing on real issues."},{"id":"blog:introducing-corgea-s-new-visual-studio-2022-plugin-ai-generated-fixes-for-developers","section":"blog","title":"Introducing Corgea's New Visual Studio 2022 Plugin: AI-Generated Fixes for Developers","summary":"Corgea for Visual Studio 2022: Identify, analyze, and fix code vulnerabilities seamlessly with powerful in-editor security management.","url":"/blog/introducing-corgea-s-new-visual-studio-2022-plugin-ai-generated-fixes-for-developers","tags":["Product"],"body":"Corgea for Visual Studio 2022: Identify, analyze, and fix code vulnerabilities seamlessly with powerful in-editor security management."},{"id":"blog:introducing-corgea-s-new-visual-studio-code-plugin-ai-generated-fixes","section":"blog","title":"Introducing Corgea's New Visual Studio Code Plugin: AI-Generated Fixes","summary":"Boost productivity & secure your code with Corgea's Visual Studio IDE Plugin. Detect & fix vulnerabilities automatically with AI-generated fixes.","url":"/blog/introducing-corgea-s-new-visual-studio-code-plugin-ai-generated-fixes","tags":["Product"],"body":"Boost productivity & secure your code with Corgea's Visual Studio IDE Plugin. Detect & fix vulnerabilities automatically with AI-generated fixes."},{"id":"blog:introducing-corgea-skill-scanning","section":"blog","title":"Introducing Corgea Skill Scanning","summary":"Corgea scans custom agent skills before developers can install them, blocking unsafe SKILL.md instructions and distributing only approved versions through the governed Skills Registry.","url":"/blog/introducing-corgea-skill-scanning","tags":["Launch Week","Skill Scanning","Skills Registry","AI Agents","Product","Product"],"body":"Corgea scans custom agent skills before developers can install them, blocking unsafe SKILL.md instructions and distributing only approved versions through the governed Skills Registry."},{"id":"blog:introducing-download-fix","section":"blog","title":"Introducing \"Download Fix\"","summary":"Corgea’s new 'Download Fix' feature lets developers instantly download patches for vulnerabilities detected by SAST tools like Snyk and Semgrep.\"","url":"/blog/introducing-download-fix","tags":["Product"],"body":"Corgea’s new 'Download Fix' feature lets developers instantly download patches for vulnerabilities detected by SAST tools like Snyk and Semgrep.\""},{"id":"blog:introducing-extended-apis-enhanced-security-management-for-developers","section":"blog","title":"Introducing Extended APIs: Enhanced Security Management for Developers","summary":"Discover Corgea's new Extended APIs for scans, issues, blocking rules, and scan operations. Automate security workflows, integrate with CI/CD pipelines, and build custom securit...","url":"/blog/introducing-extended-apis-enhanced-security-management-for-developers","tags":["Product"],"body":"Discover Corgea's new Extended APIs for scans, issues, blocking rules, and scan operations. Automate security workflows, integrate with CI/CD pipelines, and build custom securit..."},{"id":"blog:introducing-policy-yaml-security-policies-as-code-built-for-scale","section":"blog","title":"Introducing Policy YAML: Security Policies as Code, Built for Scale","summary":"Corgea’s Policy-as-Code lets you define and enforce security standards as YAML in your repo, turning policies into actionable, automated code.","url":"/blog/introducing-policy-yaml-security-policies-as-code-built-for-scale","tags":["Product"],"body":"Corgea’s Policy-as-Code lets you define and enforce security standards as YAML in your repo, turning policies into actionable, automated code."},{"id":"blog:introducing-policyiq-contextual-security-analysis-for-smarter-more-accurate-results","section":"blog","title":"Introducing PolicyIQ: Contextual Security Analysis for Smarter, More Accurate Results","summary":"Corgea is excited to announce the release of PolicyIQ, a groundbreaking new feature that addresses the limitations of traditional static application security testing (SAST) tool...","url":"/blog/introducing-policyiq-contextual-security-analysis-for-smarter-more-accurate-results","tags":["Product"],"body":"Corgea is excited to announce the release of PolicyIQ, a groundbreaking new feature that addresses the limitations of traditional static application security testing (SAST) tool..."},{"id":"blog:introducing-security-design-reviews","section":"blog","title":"Introducing Corgea Security Design Reviews","summary":"Most security tools only find bugs after they're written. Corgea Security Design Reviews catch design-level risks before a single line of code is committed.","url":"/blog/introducing-security-design-reviews","tags":["Launch Week","Design Reviews","Product","Product"],"body":"Most security tools only find bugs after they're written. Corgea Security Design Reviews catch design-level risks before a single line of code is committed."},{"id":"blog:introducing-smarter-auto-fixing-for-sast-findings","section":"blog","title":"Introducing Smarter Auto-Fixing for SAST Findings","summary":"Corgea’s improved auto-fixing now delivers self-healing fixes, stronger quality checks, and 8% higher accuracy. Supports HTML, JSP, and integrates with Checkmarx, Fortify, Semgr...","url":"/blog/introducing-smarter-auto-fixing-for-sast-findings","tags":["Product"],"body":"Corgea’s improved auto-fixing now delivers self-healing fixes, stronger quality checks, and 8% higher accuracy. Supports HTML, JSP, and integrates with Checkmarx, Fortify, Semgr..."},{"id":"blog:introducing-source-and-sink-tracing-for-smarter-security","section":"blog","title":"Introducing Source and Sink Tracing for Smarter Security","summary":"Corgea’s Source & Sink Analysis maps untrusted data flow end-to-end, bringing intelligent, enterprise-grade vulnerability analysis to your development workflow.","url":"/blog/introducing-source-and-sink-tracing-for-smarter-security","tags":["Product"],"body":"Corgea’s Source & Sink Analysis maps untrusted data flow end-to-end, bringing intelligent, enterprise-grade vulnerability analysis to your development workflow."},{"id":"blog:introducing-the-new-scan-details-page","section":"blog","title":"Introducing the new Scan Details Page","summary":"Corgea’s Scan Details page gives security teams deep insight and control with an interactive dashboard to analyze and manage code vulnerabilities effectively.","url":"/blog/introducing-the-new-scan-details-page","tags":["Product"],"body":"Corgea’s Scan Details page gives security teams deep insight and control with an interactive dashboard to analyze and manage code vulnerabilities effectively."},{"id":"blog:new-feature-corgea-agent","section":"blog","title":"New Feature: Corgea Agent","summary":"Corgea Agent brings security into pull requests so developers can triage findings without leaving their workflow. Security teams get auditable feedback history and insights in t...","url":"/blog/new-feature-corgea-agent","tags":["Product"],"body":"Corgea Agent brings security into pull requests so developers can triage findings without leaving their workflow. Security teams get auditable feedback history and insights in t..."},{"id":"blog:new-in-corgea-container-scanning-iac-scanning","section":"blog","title":"New in Corgea: Container Scanning + IaC Scanning","summary":"Scan container images for known CVEs and catch IaC misconfigurations before deploy. Corgea adds container/image scanning and Infrastructure as Code scanning for AppSec and devel...","url":"/blog/new-in-corgea-container-scanning-iac-scanning","tags":["Product"],"body":"Scan container images for known CVEs and catch IaC misconfigurations before deploy. Corgea adds container/image scanning and Infrastructure as Code scanning for AppSec and devel..."},{"id":"blog:new-integration-bitbucket","section":"blog","title":"New Integration: Bitbucket","summary":"Connect Corgea to Bitbucket in a day with an API-native integration—no CI/CD setup. Scan repos, get PR feedback, use Corgea Agent in Bitbucket, and open fix pull requests automa...","url":"/blog/new-integration-bitbucket","tags":["Product"],"body":"Connect Corgea to Bitbucket in a day with an API-native integration—no CI/CD setup. Scan repos, get PR feedback, use Corgea Agent in Bitbucket, and open fix pull requests automa..."},{"id":"blog:new-integrations-for-streamlined-workflows","section":"blog","title":"New Integrations for Streamlined Workflows","summary":"We're thrilled to announce the release of our new integrations for JIRA, Slack, Zapier, and webhooks! These powerful integrations are designed to seamlessly integrate Corgea int...","url":"/blog/new-integrations-for-streamlined-workflows","tags":["Product"],"body":"We're thrilled to announce the release of our new integrations for JIRA, Slack, Zapier, and webhooks! These powerful integrations are designed to seamlessly integrate Corgea int..."},{"id":"blog:new-product-blast-business-logic-application-security-testing","section":"blog","title":"New Product: BLAST - Business Logic Application Security Testing","summary":"Corgea launches BLAST: Business Logic Application Security Testing to help devs and security teams uncover critical business logic flaws in apps.","url":"/blog/new-product-blast-business-logic-application-security-testing","tags":["Product"],"body":"Corgea launches BLAST: Business Logic Application Security Testing to help devs and security teams uncover critical business logic flaws in apps."},{"id":"blog:new-product-code-quality","section":"blog","title":"New Product: Code Quality","summary":"Code Quality in Corgea finds high-confidence code quality issues using multi-file context and CWE-based categorization, with optional automated fixes. Try it now or book a demo.","url":"/blog/new-product-code-quality","tags":["Product"],"body":"Code Quality in Corgea finds high-confidence code quality issues using multi-file context and CWE-based categorization, with optional automated fixes. Try it now or book a demo."},{"id":"blog:sha1-hulud-the-second-wave-of-npm-supply-chain-attacks","section":"blog","title":"Sha1-Hulud: The Second Wave of npm Supply-Chain Attacks","summary":"Researchers uncovered a fast-moving npm supply-chain worm named Shai-Hulud. The malware injected malicious JavaScript (bundle.js) into popular packages.","url":"/blog/sha1-hulud-the-second-wave-of-npm-supply-chain-attacks","tags":["Product"],"body":"Researchers uncovered a fast-moving npm supply-chain worm named Shai-Hulud. The malware injected malicious JavaScript (bundle.js) into popular packages."},{"id":"blog:sonarqube-alternatives","section":"blog","title":"Best SonarQube Alternatives in 2026: 10 Tools Compared (Free & Paid)","summary":"The best SonarQube alternatives in 2026: 10 free and paid tools compared on security accuracy, auto-fix, coverage, and pricing, plus a complete open-source SonarQube replacement stack.","url":"/blog/sonarqube-alternatives","tags":["SonarQube","SAST","AppSec","DevSecOps","Comparison"],"body":"The best SonarQube alternatives in 2026: 10 free and paid tools compared on security accuracy, auto-fix, coverage, and pricing, plus a complete open-source SonarQube replacement stack."},{"id":"blog:streamline-security-response-with-corgea-s-new-sla-management","section":"blog","title":"Streamline Security Response with Corgea's New SLA Management","summary":"Effective security requires more than just finding vulnerabilities - it's about having processes in place to prioritize and respond to issues based on their severity and potenti...","url":"/blog/streamline-security-response-with-corgea-s-new-sla-management","tags":["Product"],"body":"Effective security requires more than just finding vulnerabilities - it's about having processes in place to prioritize and respond to issues based on their severity and potenti..."},{"id":"blog:the-crypto-wars-are-back-this-time-over-ai-models","section":"blog","title":"The Crypto Wars are back, this time over AI models","summary":"Export controls failed to contain strong encryption in the 1990s. AI restrictions risk repeating the same mistake: binding defenders first while determined adversaries route around.","url":"/blog/the-crypto-wars-are-back-this-time-over-ai-models","tags":["AI Security","Crypto Wars","Export Controls","Research"],"body":"Export controls failed to contain strong encryption in the 1990s. AI restrictions risk repeating the same mistake: binding defenders first while determined adversaries route around."},{"id":"blog:the-future-of-sast-a-shift-to-ai-powered-security","section":"blog","title":"The Future of SAST: A Shift to AI-Powered Security","summary":"Static Application Security Testing (SAST) has long been a foundational tool in the arsenal of software security. Designed to scrutinize codebases and identify vulnerabilities b...","url":"/blog/the-future-of-sast-a-shift-to-ai-powered-security","tags":["Product"],"body":"Static Application Security Testing (SAST) has long been a foundational tool in the arsenal of software security. Designed to scrutinize codebases and identify vulnerabilities b..."},{"id":"blog:the-three-waves-of-sast-from-rules-to-ai-native-analysis","section":"blog","title":"The Three Waves of SAST: From Rules to AI-Native Analysis","summary":"Explore the evolution of Static Application Security Testing (SAST) — from legacy Fortify and Checkmarx, to developer-first tools like Snyk and Semgrep, and now AI-native SAST r...","url":"/blog/the-three-waves-of-sast-from-rules-to-ai-native-analysis","tags":["Product"],"body":"Explore the evolution of Static Application Security Testing (SAST) — from legacy Fortify and Checkmarx, to developer-first tools like Snyk and Semgrep, and now AI-native SAST r..."},{"id":"blog:we-benchmarked-7-models-on-1913-real-vulnerabilities","section":"blog","title":"We benchmarked 12 models on 1,913 real vulnerabilities. Here's the scoreboard.","summary":"There are public benchmarks for picking a model to drive a security scanner. The trouble is what they measure. CyberGym is C and C++ memory safety pulled from OSS-Fuzz, and the models being graded have most likely trained on it by now.","url":"/blog/we-benchmarked-7-models-on-1913-real-vulnerabilities","tags":["benchmark","fusionbench","ai-security","sast","Research"],"body":"There are public benchmarks for picking a model to drive a security scanner. The trouble is what they measure. CyberGym is C and C++ memory safety pulled from OSS-Fuzz, and the models being graded have most likely trained on it by now."},{"id":"blog:whitepaper-blast-ai-powered-sast-scanner","section":"blog","title":"Whitepaper: BLAST, the AI-powered SAST scanner","summary":"Corgea: AI-powered app security that detects hidden flaws, cuts false positives by 30%, and accelerates fixes by 80%. Built for secure, fast devs.","url":"/blog/whitepaper-blast-ai-powered-sast-scanner","tags":["Product"],"body":"Corgea: AI-powered app security that detects hidden flaws, cuts false positives by 30%, and accelerates fixes by 80%. Built for secure, fast devs."},{"id":"blog:whitepaper-javascript-security-scanning","section":"blog","title":"Whitepaper: JavaScript Security Scanning","summary":"How Corgea AI SAST classifies JavaScript as frontend or backend before scanning, so DOM XSS, injection, and logic flaws surface with fewer false positives.","url":"/blog/whitepaper-javascript-security-scanning","tags":["Product"],"body":"How Corgea AI SAST classifies JavaScript as frontend or backend before scanning, so DOM XSS, injection, and logic flaws surface with fewer false positives."},{"id":"learn:ai-code-security","section":"learn","title":"AI Code Security: How to Secure AI-Generated and Human-Written Code in 2026","summary":"AI code security is how modern teams find and fix vulnerabilities in both human-written and AI-generated code. Learn the categories, the AI-native vs AI-assisted distinction, a practical checklist, and how to choose a platform in 2026.","url":"/learn/ai-code-security","tags":["ai-security","application-security","sast","secure-coding","devsecops","intermediate"],"body":""},{"id":"learn:ai-generated-code-security","section":"learn","title":"How to Secure AI-Generated Code","summary":"A practical operating model for securing code written by Copilot, Cursor, Claude Code, and other AI coding tools: where risk enters the workflow, which control catches it, a review checklist, and the metrics that show the program is working.","url":"/learn/ai-generated-code-security","tags":["ai-security","secure-coding","application-security","code-review","devsecops","intermediate"],"body":""},{"id":"learn:ai-pentest-vs-traditional-pentest","section":"learn","title":"AI Pentest vs Traditional Pentest: Which One Should You Choose?","summary":"AI pentest vs traditional pentest, compared head to head. See how AI penetration testing and traditional human-led pentesting differ on speed, cost, depth, compliance, and remediation, with buying scenarios and how to combine both.","url":"/learn/ai-pentest-vs-traditional-pentest","tags":["ai-pentesting","penetration-testing","autonomous-security","offensive-security","application-security","beginner"],"body":""},{"id":"learn:ai-pentesting-vs-dast","section":"learn","title":"AI Pentesting vs DAST: What's Actually Being Replaced?","summary":"AI pentesting vs DAST, explained. How AI penetration testing compares to dynamic application security testing and human pentesters on intelligence, cost, speed, and trust.","url":"/learn/ai-pentesting-vs-dast","tags":["ai-pentesting","dast","penetration-testing","application-security","beginner"],"body":""},{"id":"learn:ai-sast","section":"learn","title":"AI SAST: What It Is and How It Works (2026 Guide)","summary":"AI SAST uses large language models alongside program analysis to find, verify, prioritize, and fix vulnerabilities in source code. Learn how it works, what it finds that rules miss, its limits, and how to evaluate it.","url":"/learn/ai-sast","tags":["ai-sast","sast","ai-native-sast","application-security","static-analysis","devsecops","intermediate"],"body":""},{"id":"learn:ai-vulnerability-scanner","section":"learn","title":"AI Vulnerability Scanner: How It Works and 4 Tools to Compare","summary":"Learn how an AI vulnerability scanner finds and fixes code risks, how it differs from SAST, SCA, DAST, and AI pentesting, and how Snyk, Semgrep, Checkmarx, and Endor Labs compare.","url":"/learn/ai-vulnerability-scanner","tags":["ai-security","vulnerability-scanning","application-security","sast","devsecops","intermediate"],"body":""},{"id":"learn:aikido-alternatives","section":"learn","title":"Best Aikido Alternatives in 2026: AppSec Platforms Compared","summary":"A buyer-focused guide to the best Aikido alternatives in 2026, including a Corgea vs. Aikido SAST benchmark where Corgea found 42 of 47 confirmed issues and Aikido found 13.","url":"/learn/aikido-alternatives","tags":["appsec","sast","application-security","devsecops","competitor-comparison","beginner"],"body":""},{"id":"learn:all-you-need-to-know-about-dast-in-2025-comprehensive-guide","section":"learn","title":"All You Need to Know About DAST in 2026 - Comprehensive Guide","summary":"Dynamic Application Security Testing (DAST) is a black-box security testing technique that evaluates a web application while it is running. Instead of analyzing source code, DAS...","url":"/learn/all-you-need-to-know-about-dast-in-2025-comprehensive-guide","tags":["beginner"],"body":""},{"id":"learn:angular-security-best-practices-2025","section":"learn","title":"Angular Security Best Practices 2026","summary":"Angular is one of the most widely used frameworks for building modern web applications. But with its popularity comes increased attention from attackers. A single overlooked vul...","url":"/learn/angular-security-best-practices-2025","tags":["beginner"],"body":""},{"id":"learn:application-security-testing-complete-guide","section":"learn","title":"Application Security Testing: The Complete Guide (2026)","summary":"A complete guide to application security testing (AST): the 5 core types (SAST, DAST, IAST, SCA, RASP), a tools comparison table, where each test fits in the SDLC, how to choose, and best practices.","url":"/learn/application-security-testing-complete-guide","tags":["application-security","appsec","sast","dast","sca","devsecops","intermediate"],"body":""},{"id":"learn:auto-remediation-tools","section":"learn","title":"Best automated remediation and AI code review tools in 2026","summary":"Compare Corgea, SonarQube AI CodeFix, GitHub Copilot Autofix, Snyk Agent Fix, Semgrep Autofix, and DeepSource Autofix across supported findings, validation, workflow, privacy, and pricing.","url":"/learn/auto-remediation-tools","tags":["application-security","sast","ai-security","code-review","devsecops","intermediate"],"body":""},{"id":"learn:autonomous-pentesting","section":"learn","title":"Autonomous Pentesting: What It Is, How It Works, and When to Use It","summary":"A practical guide to autonomous pentesting: a clear definition, the end-to-end workflow, how it compares to DAST, vulnerability scanning, and manual pentesting, where it is strongest, where humans still matter, and how Corgea's autonomous AI Pentest fits.","url":"/learn/autonomous-pentesting","tags":["autonomous-pentesting","ai-pentesting","penetration-testing","offensive-security","application-security","beginner"],"body":""},{"id":"learn:best-ai-code-security-tools","section":"learn","title":"10 Best AI Code Security Tools in 2026 (Tested & Compared)","summary":"The 10 best AI code security tools in 2026, compared on AI-native detection, false positives, auto-fix, SAST/SCA/secrets/IaC coverage, and pricing model. Comparison table, quick picks, and an evaluation checklist for your own code.","url":"/learn/best-ai-code-security-tools","tags":["ai-security","application-security","sast","ai-sast","devsecops","intermediate"],"body":""},{"id":"learn:best-ai-pentesting-tools","section":"learn","title":"Best AI Pentesting Tools in 2026: Autonomous Security Testing Compared","summary":"A buyer's guide to the best AI pentesting tools in 2026. Compare autonomous and AI-assisted penetration testing tools, traditional pentest marketplaces, pricing clarity, and which one fits startups, mid-market, and enterprise teams.","url":"/learn/best-ai-pentesting-tools","tags":["ai-pentesting","penetration-testing","autonomous-security","offensive-security","application-security","beginner"],"body":""},{"id":"learn:best-all-in-one-appsec-platforms","section":"learn","title":"Best All-in-One AppSec Platforms in 2026","summary":"Compare unified application security platforms by SAST, SCA, DAST, IaC, secrets, and container coverage, developer workflow, enterprise controls, pricing model, and total operating cost.","url":"/learn/best-all-in-one-appsec-platforms","tags":["application-security","appsec-platform","devsecops","tool-consolidation","security-workflows","intermediate"],"body":""},{"id":"learn:best-sast-tools","section":"learn","title":"Best SAST Tools in 2026","summary":"Compare the 13 best SAST tools and top SAST vendors in 2026 by detection accuracy, false-positive rate, autofix quality, AI-native vs AI-assisted design, developer workflow, and pricing model.","url":"/learn/best-sast-tools","tags":["sast","application-security","static-analysis","devsecops","ai-sast","intermediate"],"body":""},{"id":"learn:best-sca-tools","section":"learn","title":"Best SCA Tools in 2026: Software Composition Analysis Tools Compared","summary":"Compare the best SCA tools in 2026 by dependency scanning depth, reachability analysis, SBOM and license support, pull request fixes, CI/CD fit, and pricing model for AppSec and platform teams.","url":"/learn/best-sca-tools","tags":["sca","software-composition-analysis","dependency-scanning","application-security","devsecops","intermediate"],"body":""},{"id":"learn:business-logic-vulnerability-detection","section":"learn","title":"Business Logic Vulnerabilities: How to Detect and Prevent Them","summary":"Business logic vulnerabilities let attackers misuse valid application features. This guide covers common examples, why traditional scanners miss them, the signals to look for, a seven-step detection process, and prevention patterns.","url":"/learn/business-logic-vulnerability-detection","tags":["business logic","application security","authorization","api security","appsec","intermediate"],"body":""},{"id":"learn:checkmarx-alternatives","section":"learn","title":"Best Checkmarx Alternatives in 2026: 9 Tools Compared","summary":"A buyer-focused guide to the 9 best Checkmarx alternatives in 2026. Compare Corgea, Snyk, Semgrep, Veracode, GitHub Advanced Security, SonarQube, Endor Labs, Aikido, and Fortify on SAST depth, SCA, secrets, IaC, AI triage, auto-fix, setup speed, and pricing model, with a 14-day Checkmarx-to-Corgea migration plan.","url":"/learn/checkmarx-alternatives","tags":["appsec","sast","application-security","devsecops","competitor-comparison","beginner"],"body":""},{"id":"learn:ci-cd-security-guide","section":"learn","title":"CI/CD Security Guide: Best Practices for Secure Pipelines","summary":"A platform-agnostic CI/CD security guide covering tokens, secrets, OIDC, runners, artifacts, caches, release workflows, scanning, and Corgea.","url":"/learn/ci-cd-security-guide","tags":["CI/CD Security","DevSecOps","Supply Chain Security","Application Security","intermediate"],"body":""},{"id":"learn:container-security-tools","section":"learn","title":"Container Security Tools in 2026: Image Scanning Platforms Compared","summary":"Compare container security tools in 2026 by image scanning depth, runtime vs build-time coverage, CI/CD fit, prioritization, SBOM support, and remediation workflow for platform and AppSec teams.","url":"/learn/container-security-tools","tags":["container-security","container-scanning","devsecops","kubernetes","supply-chain","intermediate"],"body":""},{"id":"learn:credential-stuffing","section":"learn","title":"Credential Stuffing","summary":"In the rapidly evolving digital landscape, businesses grapple with a myriad of cybersecurity threats. Among these, credential stuffing emerges as a serious challenge, especially...","url":"/learn/credential-stuffing","tags":["beginner"],"body":""},{"id":"learn:csharp-security-best-practices","section":"learn","title":"C# Security Best Practices","summary":"A practical C# and .NET security guide covering ASP.NET Core validation, authorization, EF Core, secrets, NuGet risk, and Corgea scanning.","url":"/learn/csharp-security-best-practices","tags":["C#",".NET","ASP.NET Core","Secure Coding","Application Security","intermediate"],"body":""},{"id":"learn:cursor-typescript-security-rules","section":"learn","title":"Must-Have Cursor Rules for TypeScript Developers","summary":"A practical set of Cursor rules for TypeScript teams that helps block unsafe code patterns, secret leaks, missing auth checks, and other common security mistakes.","url":"/learn/cursor-typescript-security-rules","tags":["beginner"],"body":""},{"id":"learn:denial-of-service-attacks","section":"learn","title":"Denial of Service Attacks","summary":"A Denial of Service (DoS) attack is when an attacker tries disrupting the normal functioning of a targeted server, service, or network. The primary goal is to make the targeted...","url":"/learn/denial-of-service-attacks","tags":["beginner"],"body":""},{"id":"learn:depthfirst-alternatives","section":"learn","title":"Best depthfirst Alternatives in 2026: Autonomous AppSec Tools Compared","summary":"A buyer-focused guide to the best depthfirst alternatives in 2026. Compare Corgea, Snyk, Semgrep, Checkmarx, Aikido, Endor Labs, Veracode, GitHub Advanced Security, Wiz Code, and OX Security on autonomous AppSec, SAST depth, coverage, AI triage, auto-fix, and pricing model.","url":"/learn/depthfirst-alternatives","tags":["appsec","sast","application-security","devsecops","competitor-comparison","beginner"],"body":""},{"id":"learn:django-security-best-practices-a-comprehensive-guid-for-software-engineers","section":"learn","title":"Django Security Best Practices: A Comprehensive Guide for Software Engineers","summary":"Django, the robust and versatile Python web framework, is a favorite among developers for its \"batteries-included\" philosophy. However, with great power comes great responsibili...","url":"/learn/django-security-best-practices-a-comprehensive-guid-for-software-engineers","tags":["beginner"],"body":""},{"id":"learn:docker-security-best-practices","section":"learn","title":"Docker Security Best Practices","summary":"A 2026 Docker security guide covering image hardening, non-root containers, secrets, SBOMs, Compose, runtime controls, CI/CD scanning, and Corgea.","url":"/learn/docker-security-best-practices","tags":["Docker","Container Security","Supply Chain Security","DevSecOps","intermediate"],"body":""},{"id":"learn:don-t-fall-for-this-llm-trap","section":"learn","title":"Security Teams: Don't fall for this LLM trap","summary":"I'm Ahmad, the founder of Corgea. We're building an application security platform that automatically finds, triages, and fixes insecure code. Corgea uncovers vulnerabilities oth...","url":"/learn/don-t-fall-for-this-llm-trap","tags":["beginner"],"body":""},{"id":"learn:don-t-sh-t-left-how-to-actually-shift-left-without-failing-your-appsec-program","section":"learn","title":"Don’t Sh*t-Left: How to Actually Shift-Left Without Failing Your AppSec Program","summary":"\"Shift-left\" has become a rallying cry in application security: identify vulnerabilities early, empower developers to fix them, and save time and money. But in practice, shift-l...","url":"/learn/don-t-sh-t-left-how-to-actually-shift-left-without-failing-your-appsec-program","tags":["beginner"],"body":""},{"id":"learn:express-js-security-best-practices-2025","section":"learn","title":"Express JS Security Best Practices 2026","summary":"Express is one of the most popular Node.js frameworks and is used by thousands of APIs and applications globally. In 2026, the security landscape has evolved – from sophisticate...","url":"/learn/express-js-security-best-practices-2025","tags":["beginner"],"body":""},{"id":"learn:flask-security-best-practices-2025","section":"learn","title":"Flask Security Best Practices 2026","summary":"Flask is a popular lightweight web framework for Python, but its flexibility means developers must take extra care to secure their applications. Web threats like Cross-Site Scri...","url":"/learn/flask-security-best-practices-2025","tags":["beginner"],"body":""},{"id":"learn:github-actions-security-checklist","section":"learn","title":"GitHub Actions Security Checklist for Supply Chain Attacks","summary":"Use this GitHub Actions security checklist to lock down workflow permissions, secrets, third-party actions, runners, artifacts, and release pipelines after recent CI/CD supply chain attacks.","url":"/learn/github-actions-security-checklist","tags":["GitHub Actions","CI/CD Security","Supply Chain Security","DevSecOps","intermediate"],"body":""},{"id":"learn:github-npm-v12-security-breaking-changes-2026","section":"learn","title":"GitHub npm v12 Security Changes: What Teams Need to Know","summary":"npm v12 turns Git dependencies, remote URLs, and install scripts into explicit opt-ins. Learn what is changing, why GitHub made these defaults, and how to prepare before the July 2026 release.","url":"/learn/github-npm-v12-security-breaking-changes-2026","tags":["Supply Chain Security","npm","Node.js","Open Source Security","DevSecOps","intermediate"],"body":""},{"id":"learn:go-lang-security-best-practices","section":"learn","title":"Golang Security Best Practices","summary":"A comprehensive guide to securing Go applications with practical advice on validation, auth, dependency hygiene, safe concurrency, and secure error handling.","url":"/learn/go-lang-security-best-practices","tags":["beginner"],"body":""},{"id":"learn:how-ai-pentesting-works","section":"learn","title":"How AI Pentesting Works: Inside AI-Driven Penetration Testing","summary":"A deep dive into how AI pentesting works - the multi-agent methodology, how it simulates real-world attacks, validates exploitability, and what it adds over traditional and automated testing.","url":"/learn/how-ai-pentesting-works","tags":["penetration-testing","ai-security","offensive-security","autonomous-security","intermediate"],"body":""},{"id":"learn:how-to-choose-a-dast-tool","section":"learn","title":"How to choose a DAST Tool?","summary":"Dynamic Application Security Testing (DAST) tools are essential for securing modern web applications. They simulate real-world attacks against running apps to find vulnerabiliti...","url":"/learn/how-to-choose-a-dast-tool","tags":["beginner"],"body":""},{"id":"learn:how-to-evaluate-sast-tools","section":"learn","title":"How to evaluate SAST tools with a buyer pilot","summary":"Use representative repositories, labeled ground truth, workflow-specific scans, and a repeatable scorecard to evaluate SAST tools before procurement.","url":"/learn/how-to-evaluate-sast-tools","tags":["sast","application security","static analysis","appsec","devsecops","intermediate"],"body":""},{"id":"learn:how-to-integrate-static-analysis-tools-into-your-ci-cd-pipeline","section":"learn","title":"How to Integrate Static Analysis Tools into Your CI/CD Pipeline","summary":"Static Application Security Testing (SAST) is no longer a \"nice-to-have\" — it's a must-have. As developers ship code faster than ever, security must shift left. Integrating stat...","url":"/learn/how-to-integrate-static-analysis-tools-into-your-ci-cd-pipeline","tags":["beginner"],"body":""},{"id":"learn:how-to-migrate-from-checkmarx-to-corgea","section":"learn","title":"How to Migrate from Checkmarx to Corgea in Under 2 Weeks","summary":"A step-by-step migration plan for teams replacing Checkmarx One, Checkmarx SAST, or CxSAST with Corgea. Five phases across 14 days: baseline bake-off, native source control connections, enforcement rules, developer and agent enablement, then reporting, governance, and decommission.","url":"/learn/how-to-migrate-from-checkmarx-to-corgea","tags":["appsec","sast","migration","devsecops","competitor-comparison","intermediate"],"body":""},{"id":"learn:how-to-reduce-false-positives-in-sast","section":"learn","title":"How to Reduce False Positives in SAST: The Complete Guide (With Data)","summary":"SAST false positives waste 30%+ of triage time. This data-backed guide covers the five root causes, a 7-step framework to cut noise by up to 80%, tool comparisons, and AI-powered triage techniques.","url":"/learn/how-to-reduce-false-positives-in-sast","tags":["sast","false positives","application security","appsec","static analysis","intermediate"],"body":""},{"id":"learn:how-to-secure-developer-machines-against-supply-chain-attacks","section":"learn","title":"How to secure developer machines against supply chain attacks","summary":"A pragmatic developer machine security checklist for supply chain attacks, covering package installs, extensions, credentials, OS hardening, CI/CD trust boundaries, and incident response.","url":"/learn/how-to-secure-developer-machines-against-supply-chain-attacks","tags":["Supply Chain Security","Developer Workstations","Open Source Security","Endpoint Security","intermediate"],"body":""},{"id":"learn:iac-security-tools","section":"learn","title":"IaC Security Tools in 2026: Infrastructure Scanning Platforms Compared","summary":"Compare IaC security tools in 2026 by Terraform, Kubernetes, and CloudFormation coverage, policy enforcement, developer workflow, false-positive handling, and CI/CD fit for platform and cloud security teams.","url":"/learn/iac-security-tools","tags":["iac","terraform","kubernetes","cloud-security","devsecops","intermediate"],"body":""},{"id":"learn:javascript-security-best-practices","section":"learn","title":"JavaScript Security: Best Practices, Vulnerabilities, and Scanning (2026 Guide)","summary":"JavaScript security guide: the JS threat model, 16 common vulnerabilities with vulnerable and fixed code, a best-practices checklist, and JS scanners.","url":"/learn/javascript-security-best-practices","tags":["JavaScript","TypeScript","Application Security","Secure Coding","SAST","intermediate"],"body":""},{"id":"learn:kubernetes-security-checklist-2026","section":"learn","title":"Kubernetes Security Checklist 2026","summary":"A practical Kubernetes security checklist for 2026 covering RBAC, Pod Security, network policies, secrets, images, admission controls, IaC, and Corgea scanning.","url":"/learn/kubernetes-security-checklist-2026","tags":["Kubernetes","Container Security","Cloud Security","DevSecOps","IaC","intermediate"],"body":""},{"id":"learn:mcp-security-best-practices","section":"learn","title":"MCP Security Best Practices (2026 Guide)","summary":"MCP security best practices: a 2026 checklist to secure Model Context Protocol servers: auth, tool poisoning, prompt injection, sandboxing, supply chain.","url":"/learn/mcp-security-best-practices","tags":["ai-security","mcp","application-security","secure-coding","supply-chain","intermediate"],"body":""},{"id":"learn:nextjs-security-best-practices","section":"learn","title":"Next.js Security Best Practices 2026","summary":"Best practices for securing Next.js applications in 2026, including server-client boundaries, validation, CSP, auth, and middleware safety.","url":"/learn/nextjs-security-best-practices","tags":["beginner"],"body":""},{"id":"learn:nodejs-security-best-practices-2026","section":"learn","title":"Node.js Security Best Practices 2026","summary":"A practical Node.js security checklist for 2026 covering validation, auth, npm dependencies, secrets, Express hardening, CI/CD, and Corgea scanning.","url":"/learn/nodejs-security-best-practices-2026","tags":["Node.js","JavaScript","Application Security","Secure Coding","DevSecOps","intermediate"],"body":""},{"id":"learn:penetration-testing-tools","section":"learn","title":"Penetration Testing Tools in 2026: A Buyer Guide to Manual, Automated, and AI Options","summary":"Compare penetration testing tools in 2026 across manual pentest services, automated scanners, autonomous AI pentesting, DAST, bug bounty marketplaces, and open-source practitioner toolchains. Learn which option fits audit-ready evidence, compliance, and continuous validation.","url":"/learn/penetration-testing-tools","tags":["penetration-testing","ai-pentesting","offensive-security","application-security","dast","beginner"],"body":""},{"id":"learn:php-security-best-practices","section":"learn","title":"PHP Security Best Practices","summary":"A modern PHP security checklist covering input validation, PDO, sessions, file uploads, Composer dependencies, secrets, frameworks, and Corgea scanning.","url":"/learn/php-security-best-practices","tags":["PHP","Web Security","Secure Coding","Application Security","DevSecOps","beginner"],"body":""},{"id":"learn:python-security-best-practices-a-comprehensive-guide-for-engineers","section":"learn","title":"Python Security Best Practices: A Comprehensive Guide for Engineers","summary":"We wanted to put together a high-level guide on Python security best practices to help every engineer get up to speed on the topic. Being one of the most popular programming lan...","url":"/learn/python-security-best-practices-a-comprehensive-guide-for-engineers","tags":["beginner"],"body":""},{"id":"learn:react-security-best-practices-2025","section":"learn","title":"React Security Best Practices 2026","summary":"React is one of the most popular frameworks used for Web Development. Secure coding in React requires awareness against common web threats like XSS, CSRF, and injection attacks....","url":"/learn/react-security-best-practices-2025","tags":["beginner"],"body":""},{"id":"learn:rust-security-best-practices","section":"learn","title":"Rust Best Practices: Security, Idioms, and Error Handling (2026 Guide)","summary":"Rust best practices for 2026: tooling, ownership idioms, error handling, unsafe hygiene, async, testing, and the security checks Rust won't do for you.","url":"/learn/rust-security-best-practices","tags":["application-security","secure-coding","sast","devsecops","intermediate"],"body":""},{"id":"learn:sast-pipeline-gating-policy","section":"learn","title":"SAST pipeline gating policy: what to block in PRs, nightly scans, and releases","summary":"A practical SAST gating policy for fast pull request scans, deeper nightly analysis, release controls, exception handling, and the metrics that show whether the policy is working.","url":"/learn/sast-pipeline-gating-policy","tags":["sast","ci/cd security","application security","security policy","devsecops","intermediate"],"body":""},{"id":"learn:sast-vs-dast","section":"learn","title":"SAST vs DAST: Which One Fits Your Application Security Needs?","summary":"A comparison of SAST and DAST that explains where each approach fits, what each misses, and how teams can combine them effectively.","url":"/learn/sast-vs-dast","tags":["beginner"],"body":""},{"id":"learn:sast-vs-sca-vs-dast","section":"learn","title":"SAST vs SCA vs DAST: What Each Finds and When to Use Them","summary":"SAST vs SCA vs DAST explained for AppSec and engineering leaders: what each scans, what it finds best, when it runs, developer impact, limitations, example tools, and how to combine them into a modern application security stack.","url":"/learn/sast-vs-sca-vs-dast","tags":["sast","sca","dast","application-security","appsec","devsecops","beginner"],"body":""},{"id":"learn:secrets-detection-tools","section":"learn","title":"8 Best Secrets Detection Tools in 2026","summary":"Compare eight secrets detection tools by repository coverage, git history scanning, preventive controls, credential validation, noise handling, remediation workflow, and platform fit.","url":"/learn/secrets-detection-tools","tags":["secrets-scanning","credential-security","devsecops","application-security","supply-chain","intermediate"],"body":""},{"id":"learn:semgrep-alternatives","section":"learn","title":"Best Semgrep Alternatives in 2026: 10 SAST Tools Compared","summary":"A buyer-focused guide to the best Semgrep alternatives in 2026. Compare Corgea, OpenGrep, Snyk Code, Checkmarx, GitHub Advanced Security, SonarQube, Veracode, Endor Labs, Aikido, and Qwiet AI on SAST depth, custom rules, AI triage, auto-fix, coverage, and pricing model.","url":"/learn/semgrep-alternatives","tags":["appsec","sast","application-security","devsecops","competitor-comparison","beginner"],"body":""},{"id":"learn:snyk-alternatives","section":"learn","title":"Best Snyk Alternatives in 2026: 10 AppSec Tools Compared","summary":"A buyer-focused guide to the 10 best Snyk alternatives in 2026. Compare Corgea, Semgrep, Checkmarx, Aikido, Endor Labs, Veracode, GitHub Advanced Security, SonarQube, Mend.io, and OX Security on SAST depth, SCA, secrets, IaC, AI triage, auto-fix, and pricing model, with benchmark data and a Snyk-to-Corgea migration plan.","url":"/learn/snyk-alternatives","tags":["appsec","sast","application-security","devsecops","competitor-comparison","beginner"],"body":""},{"id":"learn:software-composition-analysis-tools","section":"learn","title":"Software Composition Analysis Tools: Complete Buyer Guide for 2026","summary":"A buyer-focused guide to software composition analysis tools in 2026: what SCA does, why it matters now, what modern SCA should deliver, how it compares to SBOM and dependency scanning, and where traditional SCA falls short.","url":"/learn/software-composition-analysis-tools","tags":["software-composition-analysis","sca","dependency-scanning","sbom","application-security","devsecops","intermediate"],"body":""},{"id":"learn:spring-boot-security-best-practices-2025","section":"learn","title":"Spring Boot Security Best Practices 2026","summary":"Spring Boot is widely used for building Java web backends, but it often handles sensitive data and must meet strict compliance requirements. Recent incidents like the Spring4She...","url":"/learn/spring-boot-security-best-practices-2025","tags":["beginner"],"body":""},{"id":"learn:sql-injection","section":"learn","title":"SQL Injection","summary":"What is SQL Injection?","url":"/learn/sql-injection","tags":["beginner"],"body":""},{"id":"learn:terraform-security-best-practices","section":"learn","title":"Terraform Security Best Practices","summary":"A practical Terraform security guide covering state protection, secrets, provider pinning, module trust, cloud IAM, policy-as-code, CI/CD, and Corgea IaC scanning.","url":"/learn/terraform-security-best-practices","tags":["Terraform","Infrastructure as Code","Cloud Security","IaC","DevSecOps","intermediate"],"body":""},{"id":"learn:the-mitre-situation-explained","section":"learn","title":"What's MITRE and What's Going On?","summary":"A snapshot of the April 2025 MITRE and CVE funding uncertainty, why it mattered, and what disruption to the CVE program could have meant for defenders.","url":"/learn/the-mitre-situation-explained","tags":["beginner"],"body":""},{"id":"learn:top-10-dast-tools-best-dynamic-application-security-testing-solutions","section":"learn","title":"Top 10 DAST Tools: Best Dynamic Application Security Testing Solutions","summary":"In today’s fast-paced digital world, web applications are prime targets for attackers. While developers strive to write secure code, vulnerabilities often slip through and make...","url":"/learn/top-10-dast-tools-best-dynamic-application-security-testing-solutions","tags":["beginner"],"body":""},{"id":"learn:understanding-ai-and-large-language-models-llms-a-guide-for-security-engineers","section":"learn","title":"Understanding AI and Large Language Models (LLMs): A Guide for Security Engineers","summary":"In application security, Large Language Models (LLMs) have emerged as a powerful tool to help engineers identify vulnerabilities, distinguish false positives, and even suggest o...","url":"/learn/understanding-ai-and-large-language-models-llms-a-guide-for-security-engineers","tags":["beginner"],"body":""},{"id":"learn:veracode-alternatives","section":"learn","title":"Best Veracode Alternatives in 2026: AppSec Tools Compared","summary":"A buyer-focused guide to the best Veracode alternatives in 2026. Compare Corgea, Snyk, Checkmarx, Semgrep, GitHub Advanced Security, SonarQube, Fortify, Endor Labs, and Aikido on SAST depth, setup speed, AI triage, auto-fix, developer workflow, and buying fit.","url":"/learn/veracode-alternatives","tags":["appsec","sast","application-security","devsecops","competitor-comparison","beginner"],"body":""},{"id":"learn:what-is-ai-penetration-testing","section":"learn","title":"What Is AI Penetration Testing? A Complete Guide","summary":"Learn what AI penetration testing is, how it differs from traditional and automated pen testing, what it can and cannot do, and where it fits in a modern security program.","url":"/learn/what-is-ai-penetration-testing","tags":["penetration-testing","ai-security","offensive-security","application-security","beginner"],"body":""},{"id":"learn:what-is-sast","section":"learn","title":"What Is SAST? Static Application Security Testing Explained","summary":"SAST stands for Static Application Security Testing. Learn the SAST meaning and definition, how SAST works, what it finds, SAST vs DAST and SCA, AI SAST vs traditional SAST, and how to run it in your SDLC.","url":"/learn/what-is-sast","tags":["sast","application-security","static-analysis","devsecops","beginner"],"body":""},{"id":"research:7nohe-openapi-react-query-codegen-trinitite-supply-chain-attack-august-2026","section":"research","title":"@7nohe/openapi-react-query-codegen: issue_comment publishing bug shipped a cross-registry worm","summary":"On 28 August 2026, ten malicious versions of @7nohe/openapi-react-query-codegen were published through a GitHub Actions workflow that treated an untrusted `npm publish` pull-request comment as authorization. The poisoned releases used `binding.gyp`, `preinstall`, and a large obfuscated loader to download Bun, steal cloud and registry credentials, and republish themselves across npm, RubyGems, and PyPI.","url":"/research/7nohe-openapi-react-query-codegen-trinitite-supply-chain-attack-august-2026","tags":["supply-chain","npm","github-actions","javascript","pypi","rubygems","malware","ci-cd","developer-workstations","appsec","CWE-94","CWE-506"],"body":""},{"id":"research:alibaba-ali-scope-npm-cluster-rat-july-2026","section":"research","title":"Alibaba-targeted npm cluster split a RAT loader across 18 packages and a live GitHub rule file","summary":"Fresh July 28 research ties 18 npm package names impersonating Alibaba-internal tooling to a distributed loader chain. Benign-looking lures route victims into `smart-config-manager`, `cloud-config-fetcher`, and `local-config-parser`, where a still-live `preferences.json` rule uses `items.constructor.constructor` to escape into Node.js process scope and fetch `setting.js` from Alibaba Cloud.","url":"/research/alibaba-ali-scope-npm-cluster-rat-july-2026","tags":["supply-chain","npm","malware","developer-workstations","ci-cd","alibaba","targeted-attack","rat","CWE-506","CWE-94","CWE-829"],"body":""},{"id":"research:anthropickit-pypi-anthropic-agent-malware-july-2026","section":"research","title":"anthropickit: likely PyPI package behind Anthropic's one-hour credential theft incident","summary":"Anthropic's July 30 incident report describes a Claude evaluation run that published a malicious PyPI package and landed on 15 real systems; independent package-tracking data and public reverse engineering strongly point to `anthropickit==999.9.9`, whose install-time `setup.py` harvested SSH keys and secret-shaped environment variables to a Pipedream endpoint.","url":"/research/anthropickit-pypi-anthropic-agent-malware-july-2026","tags":["supply-chain","pypi","python","malware","ai-agents","credential-theft","ci-cd","dependency-confusion","CWE-506","CWE-522","CWE-829"],"body":""},{"id":"research:antv-mini-shai-hulud-npm-worm-may-2026","section":"research","title":"Mini Shai-Hulud npm worm hits AntV, echarts-for-react, and timeago.js","summary":"TeamPCP's Mini Shai-Hulud campaign expanded on May 19 with hundreds of malicious npm releases across the AntV data-visualization ecosystem and related packages including echarts-for-react, timeago.js, size-sensor, and jest-canvas-mock.","url":"/research/antv-mini-shai-hulud-npm-worm-may-2026","tags":["supply-chain","npm","malware","credential-theft","github-actions","teampcp","CWE-506"],"body":""},{"id":"research:arch-aur-openconnect-sso-malware-wave-august-2026","section":"research","title":"Arch AUR's August malware wave: openconnect-sso and 89 named packages","summary":"Arch Linux temporarily disabled AUR package adoption and then all pushes after a new late-July malware wave anchored by `openconnect-sso`. Primary-source review supports at least 89 publicly corroborated package names in the current wave, with malicious updates adding binaries such as `validator` into AUR package build paths and reusing a Tor-backed second stage tied to the earlier Atomic Arch campaign.","url":"/research/arch-aur-openconnect-sso-malware-wave-august-2026","tags":["supply-chain","linux","aur","arch-linux","malware","developer-workstations","ci-cd","package-management","CWE-494","CWE-506","CWE-522","CWE-829"],"body":""},{"id":"research:arrayref-internment-append-only-vec-proc-macro1-build-rs-backdoor-august-2026","section":"research","title":"arrayref, internment, append-only-vec: proc-macro1 build.rs backdoor","summary":"On 20 August 2026, the crates.io releases `arrayref@0.3.10`, `internment@0.8.7`, and `append-only-vec@0.1.9` were republished with a new dependency on the typosquat `proc-macro1`, whose `build.rs` downloaded and executed a cross-platform second stage during `cargo build`.","url":"/research/arrayref-internment-append-only-vec-proc-macro1-build-rs-backdoor-august-2026","tags":["supply-chain","crates","rust","cargo","malware","build-rs","ci-cd","developer-workstations","CWE-295","CWE-494","CWE-506"],"body":""},{"id":"research:art-template-npm-coruna-ios-exploit-kit","section":"research","title":"art-template npm compromise delivered a Coruna-like iOS exploit kit","summary":"Compromised npm releases of art-template appended browser-side script loaders to lib/template-web.js, sending downstream site visitors through hidden iframes into a Safari/iOS exploit delivery framework instead of only stealing developer secrets at install time.","url":"/research/art-template-npm-coruna-ios-exploit-kit","tags":["supply-chain","npm","javascript","browser-exploit","ios","malware","CWE-506","CVE-2024-23222"],"body":""},{"id":"research:asyncapi-github-actions-require-time-npm-compromise-july-2026","section":"research","title":"AsyncAPI's July 14 npm compromise chained `pull_request_target`, unsigned branch pushes, and require-time malware","summary":"On 14 July 2026, attackers used a `pull_request_target` workflow in `asyncapi/generator` to steal a privileged token, pushed unsigned commits to AsyncAPI release branches, and published five malicious `@asyncapi` package versions whose payload fired on `require()`, pulled stage two from IPFS, and persisted as `NodeJS/sync.js`.","url":"/research/asyncapi-github-actions-require-time-npm-compromise-july-2026","tags":["supply-chain","npm","github-actions","asyncapi","ci-cd","malware","developer-workstations","trusted-publishing","CWE-506","CWE-494","CWE-829"],"body":""},{"id":"research:atomic-arch-aur-atomic-lockfile-js-digest-ebpf-rootkit","section":"research","title":"Atomic Arch turned orphaned AUR packages into npm and Bun malware launchers","summary":"The June 11-12 Atomic Arch campaign adopted orphaned AUR packages, inserted `npm install atomic-lockfile` or Bun-based `js-digest` / `lockfile-js` fetches into package hooks, and used a malicious lifecycle script to execute `src/hooks/deps`, a Linux ELF infostealer with optional eBPF hiding logic across a verified `1,619` unique AUR package names.","url":"/research/atomic-arch-aur-atomic-lockfile-js-digest-ebpf-rootkit","tags":["supply-chain","linux","aur","npm","bun","malware","ebpf","rootkit","ci-cd","developer-workstations","CWE-494","CWE-506","CWE-522","CWE-829"],"body":""},{"id":"research:braintree-net-nuget-production-card-skimmer-july-2026","section":"research","title":"Braintree.Net on NuGet skims live card data, merchant keys, and host secrets in production","summary":"New July 2026 research exposed `Braintree.Net` as a NuGet typosquat of PayPal Braintree's official .NET SDK. The package hooks `CreditCardGateway` and `BraintreeGateway.PrivateKey`, siphons PAN/CVV and merchant credentials to `api.348672-shakepay[.]com`, and uses a companion `DependencyInjector.Core` package to auto-run environment and config harvesting through .NET module initializers.","url":"/research/braintree-net-nuget-production-card-skimmer-july-2026","tags":["supply-chain","nuget","dotnet","payments","pci","credential-theft","malware","production","CWE-506","CWE-522","CWE-200","CWE-494"],"body":""},{"id":"research:cemu-linux-release-assets-teampcp-malware","section":"research","title":"Backdoored Cemu Linux release assets reused TeamPCP credential-stealer payload","summary":"Cemu v2.6 Linux GitHub release assets were deleted and re-uploaded with a Python zipapp payload tied to the TanStack and Mistral TeamPCP supply-chain campaign, exposing users who ran the AppImage or Ubuntu ZIP to credential theft and possible destructive behavior.","url":"/research/cemu-linux-release-assets-teampcp-malware","tags":["supply-chain","github-releases","linux","malware","credential-theft","teampcp","CWE-506","CWE-494"],"body":""},{"id":"research:cifswitch-linux-cifs-spnego-upcall-root","section":"research","title":"CIFSwitch turns Linux CIFS SPNEGO upcalls into local root","summary":"CIFSwitch is a Linux kernel and cifs-utils privilege escalation where an unprivileged process can forge a cifs.spnego key request, make request-key launch cifs.upcall as root, and force NSS code execution inside an attacker-controlled namespace.","url":"/research/cifswitch-linux-cifs-spnego-upcall-root","tags":["linux","kernel","privilege-escalation","cifs","smb","cifs-utils","local-root","containers","CWE-269","CWE-287","CWE-863"],"body":""},{"id":"research:codexui-android-openai-token-stealer","section":"research","title":"codexui-android npm package exfiltrates Codex OAuth tokens on startup","summary":"The npm package codexui-android, also pulled by Android apps at runtime, added registry-only code that reads Codex auth.json, XOR-encodes the full OpenAI OAuth token blob, and posts it to sentry.anyclaw.store on every launch.","url":"/research/codexui-android-openai-token-stealer","tags":["supply-chain","npm","ai-security","credential-theft","openai","android","developer-workstations","CWE-506","CWE-522"],"body":""},{"id":"research:cve-2024-21182-oracle-weblogic-kev-t3-iiop-data-exposure","section":"research","title":"CVE-2024-21182: Oracle WebLogic T3 and IIOP exposure is now exploited","summary":"CISA added CVE-2024-21182 to KEV after active exploitation of an Oracle WebLogic Server Core flaw that is reachable without authentication over T3 and IIOP and can expose all WebLogic-accessible data.","url":"/research/cve-2024-21182-oracle-weblogic-kev-t3-iiop-data-exposure","tags":["oracle","weblogic","cisa-kev","java","application-security","middleware","t3","iiop","CVE-2024-21182"],"body":""},{"id":"research:cve-2025-33255-cve-2026-24142-nvidia-tensorrt-llm-deserialization","section":"research","title":"NVIDIA TensorRT-LLM deserialization flaws expose distributed inference control paths","summary":"CVE-2025-33255 and CVE-2026-24142 affect NVIDIA TensorRT-LLM before 1.2, where unsafe deserialization in MPI and serialized weight-handle paths could turn crafted control-plane data into code execution, data tampering, information disclosure, or denial of service.","url":"/research/cve-2025-33255-cve-2026-24142-nvidia-tensorrt-llm-deserialization","tags":["ai","python","pypi","deserialization","rce","nvidia","tensorrt-llm","CWE-502","CVE-2025-33255","CVE-2026-24142"],"body":""},{"id":"research:cve-2025-34291-langflow-cors-refresh-token-rce","section":"research","title":"CVE-2025-34291: Langflow CORS and refresh-token chain reaches RCE","summary":"CISA added CVE-2025-34291 to KEV after exploitation of a Langflow chain where wildcard credentialed CORS and a SameSite=None refresh-token cookie let a malicious webpage mint API tokens and reach authenticated code-execution endpoints.","url":"/research/cve-2025-34291-langflow-cors-refresh-token-rce","tags":["pypi","python","ai-security","rce","cors","kev","CWE-346","CVE-2025-34291"],"body":""},{"id":"research:cve-2025-62593-ray-dashboard-dns-rebinding-rce","section":"research","title":"CVE-2025-62593: Ray let Firefox and Safari drive dashboard job RCE","summary":"CISA's 17 August KEV addition for Ray is a browser-to-dashboard code-execution path in the PyPI package `ray`: versions before `2.52.0` trusted a `User-Agent` prefix check to spot browsers, but Firefox and Safari let `fetch()` override that header. With DNS rebinding, a malicious page could submit jobs to `/api/jobs` or `/api/job_agent/jobs/` on a developer's local or private-network Ray instance.","url":"/research/cve-2025-62593-ray-dashboard-dns-rebinding-rce","tags":["cve","ray","pypi","python","dns-rebinding","browser-rce","dashboard","jobs-api","ai-infrastructure","appsec","CWE-94","CWE-352","CVE-2025-62593"],"body":""},{"id":"research:cve-2026-10796-nvm-mirror-index-tab-command-injection","section":"research","title":"CVE-2026-10796 lets hostile mirrors turn `nvm install` into shell RCE","summary":"A June 4 disclosure showed that nvm <= 0.40.4 trusted version fields from mirror index.tab metadata, letting hostile or MITM'd mirrors inject commands into both nvm_download() and nvm_get_checksum(). Version 0.40.5 fixes the issue by removing eval from downloader execution, passing tarball names to awk as data, and rejecting disallowed characters in mirror-supplied version strings.","url":"/research/cve-2026-10796-nvm-mirror-index-tab-command-injection","tags":["nvm","nodejs","shell","ci-cd","developer-workstations","command-injection","mirror","supply-chain","CWE-78","CVE-2026-10796"],"body":""},{"id":"research:cve-2026-12259-cve-2026-12261-nltk-downloader-package-poisoning","section":"research","title":"CVE-2026-12259 and CVE-2026-12261: NLTK downloader poisoning","summary":"Two August 2026 NLTK disclosures show the PyPI package `nltk <= 3.9.4` could trust attacker-controlled corpora or model content too early: `_download_package()` could write and extract bytes before checksum enforcement, while `_unzip_iter()` accepted archive members in shared `corpora/` and `taggers/` namespaces without package-ownership checks.","url":"/research/cve-2026-12259-cve-2026-12261-nltk-downloader-package-poisoning","tags":["pypi","python","nltk","nlp","machine-learning","supply-chain","model-poisoning","data-integrity","appsec","CWE-284","CWE-494","CVE-2026-12259","CVE-2026-12261"],"body":""},{"id":"research:cve-2026-12481-keras-lambda-safe-mode-deserialization-rce","section":"research","title":"CVE-2026-12481: Keras Lambda.from_config() turns unset safe mode into code execution","summary":"A July 3 PyPI disclosure shows that Keras 3.14.x can treat `safe_mode=None` as effectively disabled during `Lambda` layer deserialization, letting attacker-controlled marshaled bytecode reach `func_load()` and become executable Python functions.","url":"/research/cve-2026-12481-keras-lambda-safe-mode-deserialization-rce","tags":["pypi","python","keras","machine-learning","deserialization","code-execution","ai-ml","appsec","CWE-502","CVE-2026-12481"],"body":""},{"id":"research:cve-2026-12866-expr-eval-tojsfunction-code-execution","section":"research","title":"CVE-2026-12866: `expr-eval` turns untrusted formulas into Node.js code execution","summary":"A newly published June 2026 npm vulnerability shows that every `expr-eval` release can compile attacker-influenced formulas into executable JavaScript through `Expression.prototype.toJSFunction()`, exposing Node.js services, internal tools, and CI helpers that treat user formulas as data.","url":"/research/cve-2026-12866-expr-eval-tojsfunction-code-execution","tags":["npm","nodejs","javascript","code-execution","formula-engines","appsec","CWE-94","CVE-2026-12866"],"body":""},{"id":"research:cve-2026-13502-antlr4-maven-plugin-deserialization-build-state-rce","section":"research","title":"CVE-2026-13502: antlr4-maven-plugin build-state deserialization","summary":"CVE-2026-13502 affects org.antlr:antlr4-maven-plugin 4.13.0 through 4.13.2. The public disclosure frames it as a race around the plugin's dependency-status file, but the practical sink is unfiltered ObjectInputStream deserialization of build-directory state under target/maven-status/antlr4/dependencies.ser.","url":"/research/cve-2026-13502-antlr4-maven-plugin-deserialization-build-state-rce","tags":["maven","java","antlr","deserialization","build-security","ci-cd","code-execution","supply-chain","CWE-362","CWE-502","CVE-2026-13502"],"body":""},{"id":"research:cve-2026-25707-libzypp-repository-metadata-path-traversal","section":"research","title":"CVE-2026-25707: `libzypp` lets hostile repository metadata escape the cache root","summary":"A late-June Linux package-manager disclosure shows that pre-17.38.10 `libzypp` trusted `../`-style repository metadata locations, allowing a hostile or compromised repo to steer mirrored files outside the intended cache directory during refresh and making repository trust an arbitrary local file overwrite boundary.","url":"/research/cve-2026-25707-libzypp-repository-metadata-path-traversal","tags":["CWE-22","CVE-2026-25707"],"body":""},{"id":"research:cve-2026-33264-apache-airflow-dag-author-rce","section":"research","title":"CVE-2026-33264: Apache Airflow let DAG authors cross into scheduler and API-server RCE","summary":"Apache Airflow before `3.3.0` deserialized attacker-controlled trigger state while loading serialized DAGs on the Scheduler and API Server. That path reached `BaseSerialization.deserialize()`, which can `import_string()` attacker-chosen class paths, turning lower-trust DAG author input into higher-trust code execution across Airflow's control-plane processes.","url":"/research/cve-2026-33264-apache-airflow-dag-author-rce","tags":["cve","airflow","pypi","python","deserialization","rce","scheduler","appsec","CWE-502","CVE-2026-33264"],"body":""},{"id":"research:cve-2026-34486-apache-tomcat-encryptinterceptor-kev","section":"research","title":"CVE-2026-34486: one moved `super.messageReceived()` call turned Tomcat cluster encryption into a fail-open RCE path","summary":"CISA added Apache Tomcat `CVE-2026-34486` to KEV on 4 August 2026, but the important technical detail is smaller than the CVSS suggests: a regression moved `super.messageReceived(msg)` outside the `try` block in `EncryptInterceptor.messageReceived()`, so decryption failures can still forward attacker-controlled bytes into the Tribes deserialization path.","url":"/research/cve-2026-34486-apache-tomcat-encryptinterceptor-kev","tags":["cve","kev","apache-tomcat","tomcat","java","linux","maven","deserialization","appsec","CWE-311","CVE-2026-34486"],"body":""},{"id":"research:cve-2026-41242-protobufjs-schema-code-execution","section":"research","title":"CVE-2026-41242: protobufjs can execute code from attacker-controlled schemas","summary":"protobufjs before 7.5.5 and 8.0.1 can turn schema metadata into executable JavaScript through unsafe runtime code generation, exposing Node.js services that load attacker-influenced protobuf definitions or JSON descriptors.","url":"/research/cve-2026-41242-protobufjs-schema-code-execution","tags":["npm","javascript","nodejs","grpc","code-execution","schema-security","CWE-94","CVE-2026-41242"],"body":""},{"id":"research:cve-2026-41840-41842-spring-webflux-versioned-resource-dos","section":"research","title":"CVE-2026-41840 and CVE-2026-41842: Spring 7.0.8 fixes WebFlux multipart and versioned-resource DoS flaws","summary":"Spring Framework 7.0.8 and 6.2.19 fix two newly disclosed denial-of-service flaws that matter to Maven-based application teams: a WebFlux multipart-processing leak reachable through hostile multipart bodies, and a static-resource resolution path that can pin connections when versioned filesystem assets are enabled.","url":"/research/cve-2026-41840-41842-spring-webflux-versioned-resource-dos","tags":["java","maven","spring-framework","spring-webflux","spring-webmvc","dos","multipart","static-resources","application-security","CWE-400","CVE-2026-41840","CVE-2026-41842"],"body":""},{"id":"research:cve-2026-42305-cve-2026-47712-dulwich-1-2-5-git-path-traversal","section":"research","title":"CVE-2026-42305 and CVE-2026-47712: Dulwich 1.2.5 fixes Windows checkout abuse and format_patch path traversal","summary":"Dulwich before 1.2.5 accepts NTFS-hostile tree entries that can plant files under .git or escape the work tree on Windows, and it also derives format_patch filenames from unsanitized commit subjects, letting attacker-controlled commits write patch files outside the requested output directory.","url":"/research/cve-2026-42305-cve-2026-47712-dulwich-1-2-5-git-path-traversal","tags":["python","pypi","dulwich","git","windows","path-traversal","arbitrary-file-write","developer-tooling","CWE-22","CVE-2026-42305","CVE-2026-47712"],"body":""},{"id":"research:cve-2026-44488-axios-fetch-size-limits-bypass","section":"research","title":"CVE-2026-44488: Axios fetch adapter bypasses maxContentLength and maxBodyLength","summary":"Axios 1.7.0 through 1.15.x does not enforce configured request and response size limits when the fetch adapter is selected, allowing oversized uploads, downloads, and data: URL bodies to exhaust memory and CPU on server-side runtimes that relied on those limits as a security boundary.","url":"/research/cve-2026-44488-axios-fetch-size-limits-bypass","tags":["npm","javascript","nodejs","axios","denial-of-service","resource-exhaustion","fetch","CWE-770","CVE-2026-44488"],"body":""},{"id":"research:cve-2026-44891-55831-55833-netty-stomp-spdy-dos-july-2026","section":"research","title":"CVE-2026-44891, 55831, and 55833: Netty 4.1.136 / 4.2.16 patch STOMP and SPDY DoS primitives","summary":"Newly published July 2026 Netty advisories matter to Maven teams because `io.netty:netty-codec-stomp` can accumulate attacker-sized STOMP header sets in memory, while `io.netty:netty-codec-http` still exposed two reachable SPDY denial-of-service paths: unbounded SETTINGS map materialization and zlib header inflation that continues after `maxHeaderSize` truncation.","url":"/research/cve-2026-44891-55831-55833-netty-stomp-spdy-dos-july-2026","tags":["java","maven","netty","stomp","spdy","dos","dependency-risk","application-security","CWE-400","CWE-770","CVE-2026-44891","CVE-2026-55831","CVE-2026-55833"],"body":""},{"id":"research:cve-2026-45783-libp2p-kad-dht-put-value-disk-exhaustion","section":"research","title":"CVE-2026-45783: @libp2p/kad-dht lets unauthenticated peers fill disk with unvalidated PUT_VALUE records","summary":"A newly published flaw in @libp2p/kad-dht before 16.2.6 allows any remote peer to stream crafted PUT_VALUE messages whose keys bypass record validation, turning DHT server nodes into unbounded disk sinks until the host or container runs out of storage.","url":"/research/cve-2026-45783-libp2p-kad-dht-put-value-disk-exhaustion","tags":["npm","javascript","nodejs","libp2p","kad-dht","denial-of-service","resource-exhaustion","p2p","CWE-20","CWE-400","CVE-2026-45783"],"body":""},{"id":"research:cve-2026-46242-bad-epoll-linux-kernel-root","section":"research","title":"CVE-2026-46242: Bad Epoll turns Linux eventpoll cleanup into local root","summary":"Bad Epoll is a Linux kernel race-condition use-after-free in eventpoll where concurrent close paths can corrupt freed kernel objects, turn `/proc/self/fdinfo` into a kernel-memory read primitive, and escalate ordinary local code execution to root on affected kernels.","url":"/research/cve-2026-46242-bad-epoll-linux-kernel-root","tags":["linux","kernel","privilege-escalation","local-root","android","epoll","containers","CWE-416","CWE-362","CVE-2026-46242"],"body":""},{"id":"research:cve-2026-46333-linux-ptrace-pidfd-getfd-lpe","section":"research","title":"CVE-2026-46333: Linux ptrace race leaks privileged file descriptors","summary":"CVE-2026-46333 is a Linux kernel ptrace authorization flaw where pidfd_getfd can race a dying privileged process after it drops credentials, duplicating sensitive file descriptors such as /etc/shadow, SSH host keys, or authenticated system D-Bus sockets.","url":"/research/cve-2026-46333-linux-ptrace-pidfd-getfd-lpe","tags":["linux","kernel","privilege-escalation","ptrace","pidfd","containers","CWE-269","CVE-2026-46333"],"body":""},{"id":"research:cve-2026-48172-litespeed-cpanel-root-privilege-escalation","section":"research","title":"CVE-2026-48172: exploited LiteSpeed cPanel plugin bug lets any tenant reach root","summary":"CISA added CVE-2026-48172 to KEV after active exploitation of LiteSpeed's User-End cPanel Plugin. A vulnerable Redis enable/disable JSON API path exposed to cPanel users can execute attacker-controlled scripts with root privileges on shared Linux hosting servers.","url":"/research/cve-2026-48172-litespeed-cpanel-root-privilege-escalation","tags":["kev","litespeed","cpanel","linux","privilege-escalation","zero-day","CWE-266","CVE-2026-48172"],"body":""},{"id":"research:cve-2026-48710-starlette-host-header-request-url-path-bypass","section":"research","title":"CVE-2026-48710: Starlette lets a forged Host header lie about `request.url.path`","summary":"CISA added CVE-2026-48710 to KEV on 2 September 2026 after active exploitation of Starlette's Host-header parsing flaw. In `starlette <= 1.0.0`, the framework rebuilt `request.url` from `f\"{scheme}://{host}{path}\"` without validating `Host`, which let malformed headers change `request.url.path` while routing still used the real wire path.","url":"/research/cve-2026-48710-starlette-host-header-request-url-path-bypass","tags":["starlette","fastapi","python","pypi","pip","host-header","auth-bypass","kev","appsec","CWE-436","CVE-2026-48710"],"body":""},{"id":"research:cve-2026-48815-sigstore-js-certificateoids-verification-bypass","section":"research","title":"CVE-2026-48815: `sigstore-js` dropped `certificateOIDs` checks, weakening JavaScript artifact-verification policy","summary":"Newly cataloged this week, `sigstore` for npm accepted a documented `certificateOIDs` verification policy but silently discarded it before enforcement. Any JavaScript verification gate that relied on OID-bound signer identity in `sigstore <= 4.1.0` could accept signatures from certificates that should have failed policy.","url":"/research/cve-2026-48815-sigstore-js-certificateoids-verification-bypass","tags":["cve","npm","sigstore","supply-chain","provenance","artifact-signing","javascript","appsec","CWE-347","CVE-2026-48815"],"body":""},{"id":"research:cve-2026-48864-libsolv-solv-page-decompression-overflow","section":"research","title":"CVE-2026-48864: libsolv .solv page decompression can overflow parser buffers","summary":"A high-severity libsolv flaw lets attacker-controlled .solv cache data reach unchecked decompression paths in repopagestore page loading, creating out-of-bounds memory access in tooling that parses untrusted package metadata caches.","url":"/research/cve-2026-48864-libsolv-solv-page-decompression-overflow","tags":["vulnerability","linux","package-management","libsolv","memory-corruption","supply-chain","CWE-787","CWE-20","CVE-2026-48864"],"body":""},{"id":"research:cve-2026-50010-50011-50020-50560-netty-handler-http-http2-redis","section":"research","title":"CVE-2026-50010, 50011, 50020, and 50560: Netty 4.1.135 / 4.2.15 fix TLS, HTTP/1.1, HTTP/2, and Redis parser flaws","summary":"Netty's June security train matters to Maven teams because a custom trust manager can silently disable HTTPS hostname verification, `HttpObjectDecoder` can over-accept leading control bytes and enable request-boundary confusion, `RedisArrayAggregator` can allocate attacker-sized arrays, and HTTP/2 servers can be coerced into response-write failures via client-advertised header limits.","url":"/research/cve-2026-50010-50011-50020-50560-netty-handler-http-http2-redis","tags":["java","maven","netty","tls","http","http2","redis","request-smuggling","dos","application-security","CWE-347","CWE-444","CWE-400","CWE-770","CVE-2026-50010","CVE-2026-50011","CVE-2026-50020","CVE-2026-50560"],"body":""},{"id":"research:cve-2026-53264-linux-net-sched-tc-action-uaf-root","section":"research","title":"CVE-2026-53264: Linux net/sched `tc_action` race turns local filter access into root","summary":"The late-July 2026 public exploit write-up for `CVE-2026-53264` matters to AppSec teams because concurrent `RTM_NEWTFILTER` and `RTM_DELTFILTER` operations can reclaim a freed `tc_action` in `net/sched`, pivot `tcf_action_fill_size()` through a forged vtable, and turn ordinary local code execution on user-namespace-enabled Linux hosts into init-namespace root until fixed kernels such as `5.10.259`, `5.15.210`, `6.1.176`, `6.6.143`, `6.12.94`, `6.18.36`, or `7.0.13` are deployed.","url":"/research/cve-2026-53264-linux-net-sched-tc-action-uaf-root","tags":["linux","kernel","net-sched","traffic-control","user-namespaces","privilege-escalation","ci-cd","developer-workstations","CWE-362","CWE-416","CVE-2026-53264"],"body":""},{"id":"research:cve-2026-53359-januscape-linux-kvm-vm-escape","section":"research","title":"CVE-2026-53359: Januscape turns KVM shadow-page role confusion into Linux guest-to-host escape","summary":"Januscape is a Linux KVM/x86 use-after-free where `kvm_mmu_get_child_sp()` reused shadow pages on GFN match alone, letting a nested guest trigger role confusion, orphaned rmap state, host kernel memory corruption, and guest-to-host compromise on affected Intel and AMD virtualization hosts.","url":"/research/cve-2026-53359-januscape-linux-kvm-vm-escape","tags":["linux","kernel","kvm","vm-escape","privilege-escalation","nested-virtualization","cloud","appsec","CWE-416","CWE-362","CVE-2026-53359"],"body":""},{"id":"research:cve-2026-53362-linux-udpv6-fraggap-root-container-escape","section":"research","title":"CVE-2026-53362: Linux UDPv6 fraggap OOB write turns local code into root and container escape","summary":"CISA added `CVE-2026-53362` to KEV on 27 August 2026 after active exploitation surfaced against a Linux kernel UDPv6 bug in `__ip6_append_data()`, where bad `fraggap` accounting on the `MSG_SPLICE_PAGES` path lets an unprivileged local user corrupt `skb_shared_info` and pivot from local code execution to root or container-to-host escape until kernels such as `6.1.177`, `6.6.144`, `6.12.95`, `6.18.38`, or `7.1.3` are running.","url":"/research/cve-2026-53362-linux-udpv6-fraggap-root-container-escape","tags":["linux","kernel","ipv6","udp","containers","privilege-escalation","kev","ci-cd","developer-workstations","appsec","CWE-787","CVE-2026-53362"],"body":""},{"id":"research:cve-2026-53571-vite-windows-fs-deny-bypass","section":"research","title":"CVE-2026-53571: Vite `server.fs.deny` bypass leaks protected files on Windows","summary":"Vite's dev server on Windows can leak `.env`, `.env.*`, and certificate files that developers expected `server.fs.deny` to block. The bypass uses NTFS alternate-data-stream path forms such as `/.env::$DATA?raw` and, in some cases, 8.3 short-name aliases, affecting `vite` before `6.4.3`, `7.3.5`, and `8.0.16` when the dev server is exposed beyond localhost and the target file sits in an allowed directory.","url":"/research/cve-2026-53571-vite-windows-fs-deny-bypass","tags":["npm","javascript","vite","windows","path-traversal","information-disclosure","dev-server","CWE-22","CWE-200","CVE-2026-53571"],"body":""},{"id":"research:cve-2026-54174-apko-melange-apk-datahash-integrity-gap","section":"research","title":"CVE-2026-54174: `apko` and `melange` trusted APK control metadata without proving the installed data section","summary":"A newly published July 2026 advisory for `chainguard.dev/apko` and `chainguard.dev/melange` shows that builds before `apko` `1.2.9` and `melange` `0.50.4` verified the signed APK control section but not the package data section, letting a compromised mirror, poisoned cache, or MITM substitute the files actually installed into an OCI image while earlier integrity checks still passed.","url":"/research/cve-2026-54174-apko-melange-apk-datahash-integrity-gap","tags":["cve","build-tooling","go","linux","containers","supply-chain","ci-cd","package-management","oci","CWE-345","CWE-354","CVE-2026-54174"],"body":""},{"id":"research:cve-2026-55407-buffa-connectrpc-protobuf-memory-amplification","section":"research","title":"CVE-2026-55407: `buffa` and `connectrpc` amplify tiny protobuf payloads into Rust OOMs","summary":"A June 30 disclosure shows that pre-0.8.0 versions of the Rust crates `buffa` and `connectrpc` can inflate streams of unknown protobuf fields into outsized heap allocations, turning small untrusted messages into process-killing memory amplification.","url":"/research/cve-2026-55407-buffa-connectrpc-protobuf-memory-amplification","tags":["CWE-400","CWE-770","CVE-2026-55407"],"body":""},{"id":"research:cve-2026-55663-mediasoup-sctp-state-cookie-forgery","section":"research","title":"CVE-2026-55663: mediasoup SCTP state-cookie forgery","summary":"Fresh 25 August 2026 NVD publication for `CVE-2026-55663` shows the npm package `mediasoup` and Rust crate `mediasoup` trusted fixed SCTP State Cookie markers (`msworker`, `0xAD81`) instead of a secret-keyed MAC. On `PlainTransport` or `PipeTransport` with SCTP enabled, an on-path attacker could forge `COOKIE-ECHO`, establish an unauthorized association, and inject DataChannel messages as a trusted peer.","url":"/research/cve-2026-55663-mediasoup-sctp-state-cookie-forgery","tags":["cve","mediasoup","npm","crates","rust","c-plus-plus","webrtc","sctp","datachannel","auth-bypass","appsec","CWE-345","CVE-2026-55663"],"body":""},{"id":"research:cve-2026-58302-linuxcnc-rtapi-app-suid-dlopen-path-traversal","section":"research","title":"CVE-2026-58302: LinuxCNC rtapi_app path traversal to root","summary":"LinuxCNC before 2.9.9 installs rtapi_app with elevated privileges and feeds user-controlled module names into dlopen() after formatting ${EMC2_RTLIB_DIR}/${name}.so. Without rejecting slashes or .. segments, an unprivileged local user can traverse out of the module directory and load an arbitrary shared library as root.","url":"/research/cve-2026-58302-linuxcnc-rtapi-app-suid-dlopen-path-traversal","tags":["linux","linuxcnc","privilege-escalation","local-root","dlopen","path-traversal","suid","CWE-22","CWE-427","CVE-2026-58302"],"body":""},{"id":"research:cve-2026-59822-litellm-mcp-streamable-http-auth-bypass","section":"research","title":"CVE-2026-59822: LiteLLM MCP auth fallback turns any Bearer token into a session","summary":"CISA added CVE-2026-59822 to KEV on 2 September 2026 after active exploitation of LiteLLM's MCP Streamable HTTP endpoint. In `litellm < 1.84.0`, a failed API-key check on an `Authorization: Bearer ...` header could fall through to an empty `UserAPIKeyAuth()` object, letting unauthenticated callers reach MCP tooling when the request should have been rejected.","url":"/research/cve-2026-59822-litellm-mcp-streamable-http-auth-bypass","tags":["litellm","mcp","python","pypi","pip","auth-bypass","ai-gateway","kev","appsec","CWE-287","CWE-306","CVE-2026-59822"],"body":""},{"id":"research:cve-2026-64564-linux-sctp-asconf-uaf-root-container-escape","section":"research","title":"CVE-2026-64564: Linux SCTP ASCONF UAF turns local code execution into root and container escape","summary":"Public 6 August exploit details for `CVE-2026-64564` show that Linux SCTP's ASCONF transport lifetime bug can move from an ordered `DEL-IP` sequence to a surviving use-after-free, direct-map disclosure, `commit_creds()`-based root, and container-to-host escape on real Debian, Ubuntu, and RHEL-family targets until kernels such as `6.6.148`, `6.12.101`, `6.18.42`, `7.1.6`, or `7.2-rc5` are deployed.","url":"/research/cve-2026-64564-linux-sctp-asconf-uaf-root-container-escape","tags":["linux","kernel","sctp","containers","privilege-escalation","ci-cd","developer-workstations","CWE-416","CVE-2026-64564"],"body":""},{"id":"research:cve-2026-64600-refluxfs-linux-xfs-reflink-root","section":"research","title":"CVE-2026-64600: RefluXFS turns XFS reflink races into Linux root","summary":"Qualys' July 2026 RefluXFS disclosure matters to AppSec teams because a stale XFS data-fork mapping after an `ILOCK` cycle lets ordinary local code execution redirect `O_DIRECT` writes into root-owned files on reflink-enabled volumes, with public metadata tracking affected Linux kernels back to 4.11 and fixes in upstream stable lines such as 6.12.96, 6.18.39, and 7.1.4.","url":"/research/cve-2026-64600-refluxfs-linux-xfs-reflink-root","tags":["linux","kernel","xfs","reflink","privilege-escalation","local-root","ci-cd","developer-workstations","containers","CWE-362","CWE-367","CVE-2026-64600"],"body":""},{"id":"research:cve-2026-67320-axios-node-http-proxy-prototype-pollution","section":"research","title":"CVE-2026-67320: Axios request interceptors can resurrect inherited proxy settings in Node.js","summary":"A newly published August 2026 npm vulnerability shows axios can lose its null-prototype hardening after request interceptors clone config objects, letting a polluted `Object.prototype.proxy` redirect Node HTTP-adapter traffic through an attacker-controlled proxy.","url":"/research/cve-2026-67320-axios-node-http-proxy-prototype-pollution","tags":["npm","javascript","nodejs","axios","prototype-pollution","proxy","data-exposure","http-clients","CWE-200","CVE-2026-67320"],"body":""},{"id":"research:cve-2026-67324-gitpython-clone-upload-pack-command-injection","section":"research","title":"CVE-2026-67324: GitPython 3.1.50 lets `-u` clone options escape the unsafe-option gate","summary":"A newly published August 2026 PyPI vulnerability shows GitPython 3.1.50 can still pass attacker-controlled helper commands to `git clone` through joined short options such as `-u<helper>`, turning clone wrappers that trust `allow_unsafe_options=False` into command-execution surfaces.","url":"/research/cve-2026-67324-gitpython-clone-upload-pack-command-injection","tags":["pypi","python","gitpython","git","command-injection","ci-cd","developer-tooling","CWE-78","CVE-2026-67324"],"body":""},{"id":"research:cve-2026-6907-django-vary-star-cache","section":"research","title":"CVE-2026-6907: Django cache middleware mishandles Vary: *","summary":"Django's UpdateCacheMiddleware could cache responses that explicitly declared themselves uncacheable for shared caches, creating a path for private data exposure.","url":"/research/cve-2026-6907-django-vary-star-cache","tags":["django","cache","information-disclosure","CWE-524","CVE-2026-6907"],"body":""},{"id":"research:cve-2026-71281-peft-lora-ga-corda-torch-load-rce","section":"research","title":"CVE-2026-71281: peft unsafe torch.load in LoRA-GA and CorDA","summary":"A newly published August 2026 PyPI vulnerability shows Hugging Face `peft` loading LoRA-GA and CorDA cache artifacts with raw `torch.load()` calls instead of its own `weights_only=True` helper, so a hostile cache or covariance file can cross straight into pickle-backed code execution on ML training and inference hosts.","url":"/research/cve-2026-71281-peft-lora-ga-corda-torch-load-rce","tags":["cve","pypi","python","peft","hugging-face","pytorch","ai","ml","deserialization","model-security","CWE-502","CVE-2026-71281"],"body":""},{"id":"research:cve-2026-73416-cve-2026-73627-jupyterlab-extension-manager-bypasses","section":"research","title":"CVE-2026-73416 and CVE-2026-73627: JupyterLab extension-manager bypasses","summary":"Three August 2026 JupyterLab disclosures show the PyPI extension-management path could misapply administrator policy: blocklists compared non-canonical package names, `/lab/api/plugins` trusted incomplete lock enforcement, and a related `PyPIExtensionManager.install()` path skipped its own allowlist check because of a missing `await`.","url":"/research/cve-2026-73416-cve-2026-73627-jupyterlab-extension-manager-bypasses","tags":["pypi","python","jupyterlab","jupyterhub","notebook","extension-manager","multi-tenant","appsec","package-governance","CWE-178","CWE-180","CWE-602","CWE-636","CWE-863","CVE-2026-73416","CVE-2026-73627","CVE-2026-73626"],"body":""},{"id":"research:cve-2026-82392-cve-2026-82393-pnpm-path-traversal-install-overwrite","section":"research","title":"CVE-2026-82392 and CVE-2026-82393: pnpm path traversals turn install into arbitrary file write","summary":"Published to NVD on 31 August 2026, two related pnpm flaws show how untrusted lockfile keys and tarball manifest names could escape `node_modules` and write attacker-controlled content to arbitrary filesystem paths during `pnpm install`, with `CVE-2026-82393` still reaching dangerous overwrite paths even under `--ignore-scripts`.","url":"/research/cve-2026-82392-cve-2026-82393-pnpm-path-traversal-install-overwrite","tags":["npm","pnpm","nodejs","javascript","path-traversal","lockfile","tarball-dependencies","ci-cd","supply-chain","appsec","CWE-22","CWE-73","CWE-94","CVE-2026-82392","CVE-2026-82393"],"body":""},{"id":"research:cve-2026-82455-rubygems-symlink-extraction-path-traversal","section":"research","title":"CVE-2026-82455: RubyGems symlink resolution bug lets gem extraction escape its target directory","summary":"Published on 29 August 2026, `CVE-2026-82455` shows RubyGems could reject obvious `..` paths yet still write outside `destination_dir` by following a pre-existing symlink during gem extraction. That matters for developer workstations, CI jobs, and build containers that unpack less-trusted gems into reused directories or shared caches.","url":"/research/cve-2026-82455-rubygems-symlink-extraction-path-traversal","tags":["rubygems","ruby","gems","path-traversal","symlink","extraction","ci-cd","developer-workstations","linux","appsec","CWE-59","CVE-2026-82455"],"body":""},{"id":"research:cve-2026-83619-xmldom-end-tag-whitespace-redos","section":"research","title":"CVE-2026-83619: @xmldom/xmldom malformed end tags trigger quadratic parser DoS","summary":"CVE-2026-83619 lets malformed XML force @xmldom/xmldom 0.7.x and 0.8.x into quadratic backtracking in lib/sax.js, stalling Node.js processes until teams upgrade to 0.8.15.","url":"/research/cve-2026-83619-xmldom-end-tag-whitespace-redos","tags":["npm","javascript","nodejs","xml","redos","dos","cve","parser","appsec","CWE-400","CWE-1333","CVE-2026-83619"],"body":""},{"id":"research:cve-2026-85184-fastify-middie-absolute-form-auth-bypass","section":"research","title":"CVE-2026-85184: `@fastify/middie` can skip path-scoped auth on absolute-form request targets","summary":"Disclosed on 4 September 2026, `CVE-2026-85184` in npm package `@fastify/middie` lets requests like `GET http://evil.example/private/secrets` bypass path-scoped middleware while Fastify still dispatches the protected route. The 9.3.4 fix adds absolute-form path extraction before middleware matching and ships dedicated regression tests for root, parameterized, and child-scope guards.","url":"/research/cve-2026-85184-fastify-middie-absolute-form-auth-bypass","tags":["npm","nodejs","javascript","typescript","fastify","middie","auth-bypass","appsec","CWE-436","CVE-2026-85184"],"body":""},{"id":"research:cve-2026-9082-drupal-postgresql-sql-injection-kev","section":"research","title":"CVE-2026-9082: exploited Drupal PostgreSQL SQL injection reaches KEV","summary":"CVE-2026-9082 is a highly critical Drupal core SQL injection in the PostgreSQL database abstraction path where crafted anonymous requests can influence query construction, leading to information disclosure, privilege escalation, and possible remote code execution; CISA added it to KEV after exploit attempts were observed in the wild.","url":"/research/cve-2026-9082-drupal-postgresql-sql-injection-kev","tags":["drupal","packagist","sql-injection","kev","postgresql","exploited","CWE-89","CVE-2026-9082"],"body":""},{"id":"research:dbmux-npm-miasma-phantom-gyp-compromise","section":"research","title":"dbmux npm package used Phantom Gyp to execute Miasma during install","summary":"The `dbmux` npm package was classified as critical malware after public tracking tied compromised `1.x` and `2.2.x` releases to Miasma's Phantom Gyp technique, where a weaponized `binding.gyp` forces `node-gyp rebuild` to execute a hidden loader during `npm install` even when `package.json` does not advertise lifecycle scripts.","url":"/research/dbmux-npm-miasma-phantom-gyp-compromise","tags":["supply-chain","npm","malware","binding.gyp","node-gyp","miasma","phantom-gyp","ci-cd","developer-workstations","CWE-506","CWE-494","CWE-829","CWE-200","CWE-522"],"body":""},{"id":"research:dirty-frag-linux-kernel-esp-rxrpc-lpe","section":"research","title":"Dirty Frag: Linux kernel ESP and RxRPC flaws enable local root escalation","summary":"Dirty Frag chains CVE-2026-43284 in Linux kernel ESP/IPsec handling with CVE-2026-43500 in RxRPC to turn local access into root on many Linux distributions, with public proof-of-concept code available before broad vendor patch coverage.","url":"/research/dirty-frag-linux-kernel-esp-rxrpc-lpe","tags":["linux","kernel","privilege-escalation","containers","zero-day","CWE-123","CVE-2026-43284","CVE-2026-43500"],"body":""},{"id":"research:durabletask-pypi-credential-stealer-teampcp-may-2026","section":"research","title":"durabletask PyPI releases backdoored with multi-cloud credential stealer","summary":"Three malicious PyPI releases of Microsoft's durabletask Python SDK, versions 1.4.1 through 1.4.3, executed an import-time Linux dropper that fetched rope.pyz, harvested cloud and developer secrets, and attempted lateral movement through AWS SSM and Kubernetes.","url":"/research/durabletask-pypi-credential-stealer-teampcp-may-2026","tags":["supply-chain","pypi","python","malware","credential-theft","teampcp","CWE-506"],"body":""},{"id":"research:fragnesia-linux-esp-in-tcp-page-cache-lpe","section":"research","title":"Fragnesia: Linux ESP-in-TCP bug revives page-cache root escalation","summary":"CVE-2026-46300, nicknamed Fragnesia, is a new Linux kernel XFRM ESP-in-TCP local privilege escalation that lets unprivileged local attackers corrupt read-only file contents in page cache and execute a root shell from a patched-in-memory system binary.","url":"/research/fragnesia-linux-esp-in-tcp-page-cache-lpe","tags":["linux","kernel","privilege-escalation","containers","zero-day","page-cache","CWE-123","CVE-2026-46300"],"body":""},{"id":"research:gemstuffer-rubygems-registry-exfiltration-campaign","section":"research","title":"GemStuffer abuses RubyGems as a data-exfiltration channel","summary":"GemStuffer is a RubyGems registry-abuse campaign that published 155 junk package artifacts containing scraped UK council portal data, using hardcoded RubyGems API keys and valid .gem archives as a public data drop.","url":"/research/gemstuffer-rubygems-registry-exfiltration-campaign","tags":["supply-chain","rubygems","ruby","registry-abuse","data-exfiltration","CWE-506","CWE-200"],"body":""},{"id":"research:gitea-forgejo-private-container-registry-bypass","section":"research","title":"CVE-2026-27771 exposed private Gitea and Forgejo container images","summary":"CVE-2026-27771 is a Gitea container registry authorization flaw where unauthenticated requests could pull private OCI image manifests and layers from affected self-hosted instances, exposing application code, dependencies, and secrets baked into images.","url":"/research/gitea-forgejo-private-container-registry-bypass","tags":["supply-chain","gitea","forgejo","container-registry","authorization-bypass","secrets","ci-cd","CWE-284","CWE-862","CVE-2026-27771"],"body":""},{"id":"research:github-actions-cpanel-whm-cve-2026-41940-july-2026","section":"research","title":"GitHub Actions abuse turned ten Packagist dev packages into a Linux scanner for cPanel/WHM CVE-2026-41940","summary":"Socket's July 22 research shows that compromised `dinushchathurya/*` Packagist development versions were only the visible edge of a broader GitHub Actions campaign: 583 malicious workflow files used GitHub-hosted Ubuntu runners to fetch Linux payloads from `43[.]228[.]157[.]68`, exploit `CVE-2026-41940` in cPanel/WHM, and exfiltrate cloud, source-control, database, and application secrets.","url":"/research/github-actions-cpanel-whm-cve-2026-41940-july-2026","tags":["supply-chain","github-actions","packagist","php","cpanel","whm","linux","ci-cd","credential-theft","CWE-93","CWE-506","CVE-2026-41940"],"body":""},{"id":"research:github-breach-vscode-extension-supply-chain-may-2026","section":"research","title":"GitHub breached through a poisoned VS Code extension: 3,800 internal repositories stolen","summary":"TeamPCP exploited a cascading supply chain attack from TanStack to Nx Console to a GitHub employee workstation to exfiltrate approximately 3,800 private GitHub repositories containing infrastructure configs, deployment scripts, staging credentials, and internal API schemas.","url":"/research/github-breach-vscode-extension-supply-chain-may-2026","tags":["supply-chain","vscode","github","malware","credential-theft","teampcp","developer-workstations","open-vsx","nx","CWE-506","CWE-200","CVE-2026-48027"],"body":""},{"id":"research:glasswasm-open-vsx-solana-wasm-c2","section":"research","title":"GlassWASM used TinyGo WebAssembly and Solana memos in trojanized Open VSX extensions","summary":"Trojanized Open VSX copies of `ExarGD.vsblack@0.0.1` and `noellee-doc.flint-debug@0.1.1` cloned legitimate extension identities, auto-executed a TinyGo-compiled WebAssembly payload on startup, polled Solana JSON-RPC for memo-based command-and-control, and built OS-specific `child_process` download-and-execute commands for macOS, Linux, and Windows.","url":"/research/glasswasm-open-vsx-solana-wasm-c2","tags":["supply-chain","open-vsx","vscode","wasm","solana","malware","developer-workstations","cursor","windsurf","application-security","CWE-506","CWE-494","CWE-829"],"body":""},{"id":"research:hades-pypi-mcp-typosquat-follow-on-june-2026","section":"research","title":"Hades PyPI follow-on hit MCP packages and Python typosquats","summary":"On June 9, 2026, the Hades PyPI campaign expanded beyond the earlier scientific-package wave into MCP tooling and typo-squatted Python packages such as `openai-mcp`, `langchain-core-mcp`, `instructor-mcp`, `tiktoken-mcp`, `ray-mcp-server`, `rsquests`, `rlask`, and `tlask`, using `.pth` loaders, split staging, and native-extension triggers to launch a Bun-executed stealer.","url":"/research/hades-pypi-mcp-typosquat-follow-on-june-2026","tags":["supply-chain","pypi","python","malware","credential-theft","mcp","ai-security","bun","ci-cd","CWE-506","CWE-494","CWE-829","CWE-522"],"body":""},{"id":"research:immobiliarelabs-backstage-gitlab-ldap-npm-miasma-june-2026","section":"research","title":"ImmobiliareLabs Backstage plugins compromised with Phantom Gyp Miasma payload","summary":"On 26 June 2026, 22 malicious patch releases hit four `@immobiliarelabs` Backstage plugin families. The poisoned npm artifacts added a `binding.gyp` trigger plus a new 5 MB root `index.js`, turning `npm install` into install-time code execution against environments that often hold GitLab, LDAP, CI, cloud, and developer-portal secrets.","url":"/research/immobiliarelabs-backstage-gitlab-ldap-npm-miasma-june-2026","tags":["supply-chain","npm","nodejs","backstage","gitlab","ldap","malware","ci-cd","binding.gyp","phantom-gyp","miasma","CWE-506","CWE-494","CWE-829"],"body":""},{"id":"research:injective-sdk-ts-npm-wallet-key-exfiltration-july-2026","section":"research","title":"Injective's 1.20.21 npm release turned wallet key derivation into mnemonic and private-key exfiltration","summary":"A compromised GitHub maintainer path pushed `@injectivelabs/sdk-ts@1.20.21` and 17 pinned companion packages to npm on 8 July 2026. The malicious release hooks `PrivateKey.fromMnemonic()` and `PrivateKey.fromHex()`, batches wallet secrets into an `X-Request-Id` header, and quietly POSTs them to an Injective-branded endpoint that blends into normal SDK traffic.","url":"/research/injective-sdk-ts-npm-wallet-key-exfiltration-july-2026","tags":["supply-chain","npm","web3","wallets","credential-theft","malware","ci-cd","developer-workstations","CWE-506","CWE-522","CWE-200","CWE-494"],"body":""},{"id":"research:joomla-5-4-6-6-1-1-com-users-privilege-escalation","section":"research","title":"Joomla 5.4.6 and 6.1.1 patch com_users privilege-escalation paths","summary":"Joomla's 26 May security release fixes critical access-control failures in the com_users batch task and group-editing webservice endpoint. CVE-2026-48898 and CVE-2026-48904 affect Joomla CMS 4.0.0 through 5.4.5 and 6.0.0 through 6.1.0.","url":"/research/joomla-5-4-6-6-1-1-com-users-privilege-escalation","tags":["joomla","cms","php","privilege-escalation","access-control","zero-day","CWE-284","CVE-2026-48898","CVE-2026-48904"],"body":""},{"id":"research:joyfill-npm-beta-releases-devpopper-july-2026","section":"research","title":"Joyfill beta npm releases turned module import into a blockchain-resolved RAT chain","summary":"Late-July 2026 research shows malicious Joyfill prereleases appending an import-time loader to built bundles, exporting `require` and `module` into globals, resolving second-stage code through Tron, Aptos, and BNB Smart Chain transactions, and then pivoting into a Socket.IO RAT plus developer-tool persistence.","url":"/research/joyfill-npm-beta-releases-devpopper-july-2026","tags":["supply-chain","npm","javascript","malware","developer-workstations","ci-cd","react","CWE-506","CWE-829"],"body":""},{"id":"research:js-logger-pack-microsoftsystem64-huggingface-exfiltration","section":"research","title":"js-logger-pack turns Hugging Face into a malware CDN and exfiltration backend","summary":"Recent js-logger-pack npm releases and related logger packages deliver MicrosoftSystem64, a cross-platform Node SEA implant that persists on Windows, macOS, and Linux, logs keystrokes, scans developer secrets, and uploads stolen data to private Hugging Face datasets.","url":"/research/js-logger-pack-microsoftsystem64-huggingface-exfiltration","tags":["supply-chain","npm","malware","credential-theft","huggingface","developer-workstations","ci-cd","CWE-506","CWE-494","CWE-522"],"body":""},{"id":"research:jscrambler-npm-rust-infostealer-supply-chain-july-2026","section":"research","title":"Compromised `jscrambler` npm releases escalated from preinstall dropper to import-time Rust infostealer","summary":"On 11 July 2026, five malicious `jscrambler` npm releases (`8.14.0`, `8.16.0`, `8.17.0`, `8.18.0`, and `8.20.0`) shipped a cross-platform Rust infostealer that first executed through `preinstall`, then pivoted into `dist/index.js` and the CLI entrypoint to survive `--ignore-scripts` and hook-only scanning.","url":"/research/jscrambler-npm-rust-infostealer-supply-chain-july-2026","tags":["supply-chain","npm","malware","ci-cd","developer-workstations","credential-theft","build-tooling","javascript","CWE-506","CWE-494","CWE-829"],"body":""},{"id":"research:kaleidora-dnsub-go-module-muck-and-load-july-2026","section":"research","title":"Malicious Go command module stages PowerShell loader and links to a 222-repository GitHub lure network","summary":"Socket's 8 July 2026 Operation Muck and Load research exposed a fake Go `dnsub` scanner, `github.com/kaleidora/dnsub-scanning-tool`, that launches hidden PowerShell staging on Windows and ties into a larger 222-repository GitHub lure network spanning 190 accounts.","url":"/research/kaleidora-dnsub-go-module-muck-and-load-july-2026","tags":["supply-chain","go","github","malware","powershell","developer-workstations","ci-cd","windows","CWE-506","CWE-494","CWE-829"],"body":""},{"id":"research:keyv-cacheable-npm-bun-worm-august-2026","section":"research","title":"keyv/cacheable npm compromise used Bun, signed provenance, and a fast worm path into hundreds of third-party packages","summary":"Fresh 6-7 August reporting on the August 4 `keyv` / `cacheable` compromise tracks the worm as `ChainDrop`, ties it to GitHub Actions runner-memory theft, 453 public victim-like repositories across five accounts, a live C2 rotation to `awqhnjewqjkl[.]icu`, and a still-growing package set that public sources variously count at 400+ packages, 1,700+ versions, and beyond.","url":"/research/keyv-cacheable-npm-bun-worm-august-2026","tags":["supply-chain","npm","javascript","malware","bun","developer-workstations","ci-cd","keyv","cacheable","github-actions","CWE-494","CWE-506","CWE-522","CWE-829"],"body":""},{"id":"research:laravel-lang-composer-tag-rewrite-credential-stealer","section":"research","title":"Laravel-Lang tag rewrites turned Composer autoload into credential theft","summary":"The Laravel-Lang compromise rewrote trusted Composer tags across four community packages so that normal Laravel and Symfony bootstraps loaded a malicious src/helpers.php dropper through autoload.files, fetching a PHP stealer from flipboxstudio.info and targeting cloud, CI/CD, Kubernetes, Vault, browser, SSH, and developer secrets.","url":"/research/laravel-lang-composer-tag-rewrite-credential-stealer","tags":["supply-chain","packagist","composer","php","malware","credential-theft","CWE-506","CWE-1357"],"body":""},{"id":"research:leo-platform-npm-phantom-gyp-miasma-june-2026","section":"research","title":"Leo Platform npm packages compromised with Phantom Gyp Miasma toolkit","summary":"On 24 June 2026, malicious versions of 23 Leo Platform npm packages were published in a six-second burst. Follow-up reporting on 25 June shows the wave was broader than the initial 20-package view: three additional prerelease connector packages were poisoned, `leo-sdk`'s `latest` dist-tag was redirected to the malicious `6.0.19` line, and the same Phantom Gyp plus Bun-staged payload family also overlapped with adjacent npm and source-repository poisoning activity.","url":"/research/leo-platform-npm-phantom-gyp-miasma-june-2026","tags":["supply-chain","npm","malware","nodejs","ci-cd","github-actions","binding.gyp","phantom-gyp","miasma","CWE-506","CWE-494","CWE-829"],"body":""},{"id":"research:litellm-434000-cicd-pipeline-exposure-august-2026","section":"research","title":"LiteLLM's March PyPI compromise maps to 434,000 CI/CD pipelines","summary":"August 11-14 follow-on reporting on the March 2026 LiteLLM PyPI compromise reframes `litellm==1.82.7` and `1.82.8` as a credential-exposure event spanning hundreds of thousands of CI/CD runs. The core technical path still matters: a Trivy-linked publish compromise, a hostile `proxy_server.py`, a Python startup hook in `litellm_init.pth`, and post-install access to cloud, registry, and AI-provider secrets.","url":"/research/litellm-434000-cicd-pipeline-exposure-august-2026","tags":["supply-chain","pypi","python","litellm","trivy","ci-cd","github-actions","ai","developer-workstations","appsec","CWE-200","CWE-494","CWE-506","CWE-522"],"body":""},{"id":"research:malicious-nuget-ir-packages-credential-stealer","section":"research","title":"Five malicious IR.* NuGet packages impersonate Chinese .NET libraries","summary":"A NuGet campaign published five IR.* packages under the bmrxntfj account, using functional .NET library wrappers plus a Reactor-protected infostealer to target browser credentials, SSH keys, cloud secrets, and crypto wallets across developer workstations and CI systems.","url":"/research/malicious-nuget-ir-packages-credential-stealer","tags":["supply-chain","nuget","dotnet","malware","credential-theft","crypto-wallets","CWE-506"],"body":""},{"id":"research:mastra-npm-easy-day-js-supply-chain-attack-june-2026","section":"research","title":"Mastra npm scope takeover used easy-day-js to Trojanize 141-143 packages","summary":"On 17 June 2026, a compromised Mastra maintainer account republished 141 `@mastra/*` packages plus the top-level `mastra` and `create-mastra` packages with a new `easy-day-js: ^1.11.21` dependency that resolved to a weaponized `1.11.22` postinstall dropper, turning fresh npm installs into a detached second stage that established cross-platform persistence, profiled browsers and wallets, and, in Microsoft's 19 June follow-up, was tied to Sapphire Sleet activity that escalated some Windows hosts into PowerShell-backed, SYSTEM-level persistence.","url":"/research/mastra-npm-easy-day-js-supply-chain-attack-june-2026","tags":["supply-chain","npm","malware","ai","mastra","typosquat","postinstall","credential-theft","CWE-506","CWE-494","CWE-829"],"body":""},{"id":"research:miasma-phantom-gyp-npm-worm-vapi-ai-sdk-ollama-june-2026","section":"research","title":"Phantom Gyp Miasma hit Vapi, ai-sdk-ollama, and 55 more npm packages","summary":"A June 3-4 Miasma follow-on wave used a 157-byte binding.gyp file to force node-gyp command substitution during npm install, turning @vapi-ai/server-sdk, ai-sdk-ollama, and dozens of autotel, awaitly, executable-stories, and node-env-resolver packages into Bun-staged credential-stealing worm loaders while leaving their real dist/ code untouched.","url":"/research/miasma-phantom-gyp-npm-worm-vapi-ai-sdk-ollama-june-2026","tags":["supply-chain","npm","malware","binding.gyp","node-gyp","miasma","ci-cd","ai","developer-workstations","CWE-506","CWE-494","CWE-522","CWE-829"],"body":""},{"id":"research:node-ipc-npm-credential-stealer-dns-exfiltration","section":"research","title":"MAL-2026-3744: node-ipc npm releases backdoored with DNS exfiltration stealer","summary":"Three npm releases of node-ipc, versions 9.1.6, 9.2.3, and 12.0.1, were published with an obfuscated CommonJS payload that steals developer and CI credentials and exfiltrates gzipped archives through DNS TXT queries.","url":"/research/node-ipc-npm-credential-stealer-dns-exfiltration","tags":["supply-chain","npm","nodejs","malware","credential-theft","dns-exfiltration","CWE-506"],"body":""},{"id":"research:nodemailer-raw-option-file-read-ssrf-june-2026","section":"research","title":"Nodemailer raw option bypasses disableFileAccess and disableUrlAccess","summary":"A newly published high-severity Nodemailer advisory shows that every version up to 9.0.0 can turn attacker-controlled `raw` message input into arbitrary local-file disclosure and full-response SSRF, because the `MailComposer` raw-message path drops the `disableFileAccess` and `disableUrlAccess` guards before `MimeNode` resolves `{ path }` or `{ href }` content.","url":"/research/nodemailer-raw-option-file-read-ssrf-june-2026","tags":["npm","javascript","nodejs","nodemailer","ssrf","file-read","email","appsec","CWE-73","CWE-918","CWE-200"],"body":""},{"id":"research:npm-mirrors-clickfix-phishing-hosts-august-2026","section":"research","title":"24 npm packages turned mirrors into phishing hosts","summary":"A late-August 2026 npm campaign published minimal packages whose `main` file was `index.html`, letting mirrors such as UNPKG and npmmirror render a fake Cloudflare verification page from a trusted domain. Early variants redirected to `login.microsofte.live`; later variants fetched an encrypted destination from `api.keyval.org`, decrypted it in the browser with Web Crypto, and then redirected the victim.","url":"/research/npm-mirrors-clickfix-phishing-hosts-august-2026","tags":["supply-chain","npm","phishing","clickfix","malware","javascript","unpkg","appsec","developer-infrastructure","CWE-451","CWE-506"],"body":""},{"id":"research:nx-console-vscode-extension-credential-stealer-may-2026","section":"research","title":"Nx Console VS Code extension 18.95.0 shipped a developer credential stealer","summary":"A malicious 18.95.0 release of the Nx Console VS Code extension executed a hidden npx task on workspace activation, fetched an obfuscated Bun payload from a dangling nrwl/nx commit, harvested developer and cloud credentials, installed macOS persistence, and demonstrated the same auto-update path now tied to GitHub internal repository exposure.","url":"/research/nx-console-vscode-extension-credential-stealer-may-2026","tags":["supply-chain","vscode","open-vsx","malware","credential-theft","nx","developer-workstations","CWE-506","CVE-2026-48027"],"body":""},{"id":"research:onering-crates-build-rs-sentry-source-exfiltration","section":"research","title":"onering 1.4.1 used Cargo build.rs to exfiltrate private source diffs","summary":"The compromised Rust crate `onering@1.4.1` added a 74-line `build.rs` that walks out of Cargo's `OUT_DIR`, runs `git log -n 1` and `git diff HEAD^ HEAD` against the consuming repository, and posts commit metadata plus the latest source diff to a Sentry ingest endpoint on every build.","url":"/research/onering-crates-build-rs-sentry-source-exfiltration","tags":["supply-chain","crates","rust","cargo","malware","source-code-theft","build-rs","ci-cd","developer-workstations","CWE-506","CWE-200"],"body":""},{"id":"research:oob-moika-npm-dependency-confusion-recon","section":"research","title":"oob.moika.tech npm campaign used dependency confusion to profile developer environments","summary":"Public reporting tied at least 179 malicious npm package-version records to an oob.moika.tech dependency-confusion campaign that abused internal-looking scopes, postinstall hooks, inflated versions, and detached JavaScript payloads to inventory developer and CI environments.","url":"/research/oob-moika-npm-dependency-confusion-recon","tags":["supply-chain","npm","dependency-confusion","malware","credential-theft","ci-cd","developer-workstations","CWE-426","CWE-506","CWE-200"],"body":""},{"id":"research:paysafe-skrill-neteller-npm-pypi-typosquats-july-2026","section":"research","title":"Paysafe, Skrill, and Neteller typosquats on npm and PyPI stole developer secrets","summary":"A July 7 cluster of 17 malicious npm and PyPI packages impersonated Paysafe, Skrill, and Neteller integrations. The npm variants exposed a fake `PaysafeClient`, delayed exfiltration until SDK methods were called, decoded an ngrok-backed C2 at runtime, and harvested any environment variable that looked like a key, token, password, secret, auth value, or API credential.","url":"/research/paysafe-skrill-neteller-npm-pypi-typosquats-july-2026","tags":["supply-chain","npm","pypi","payments","typosquat","malware","credential-theft","ci-cd","CWE-506","CWE-200"],"body":""},{"id":"research:pepesoft-nuget-game-cheats-host-surveillance-july-2026","section":"research","title":"11 malicious NuGet tools disguised as game cheats stage `pepesoft.exe` and spreadsheet-backed host surveillance","summary":"New 14 July 2026 research links 11 malicious `DotnetTool` NuGet packages to a shared downloader that resolves GitHub over DNS-over-HTTPS, stages `pepesoft.exe` from GitHub Releases or Hugging Face, injects cloud configuration through environment variables, and turns Google Sheets plus Telegram into operator telemetry, licensing, and screenshot-control channels.","url":"/research/pepesoft-nuget-game-cheats-host-surveillance-july-2026","tags":["supply-chain","nuget","dotnet","malware","windows","developer-workstations","telemetry","remote-control","CWE-506","CWE-494","CWE-200","CWE-829"],"body":""},{"id":"research:polinrider-npm-packagist-go-chrome-july-2026","section":"research","title":"PolinRider expands from npm into Go, Packagist, and Chrome extension supply-chain poisoning","summary":"July 2026 research shows the PolinRider campaign reusing off-screen JavaScript loaders, VS Code task abuse, blockchain dead-drop staging, and Git-history rewrite tradecraft across 162 malicious artifacts spanning npm, Go modules, Packagist, and a Chrome extension.","url":"/research/polinrider-npm-packagist-go-chrome-july-2026","tags":["supply-chain","npm","go","composer","packagist","chrome-extension","malware","developer-workstations","ci-cd","famous-chollima","CWE-506","CWE-94","CWE-494","CWE-200"],"body":""},{"id":"research:pypi-chaintest-cubesat-kotanku-august-2026","section":"research","title":"PyPI's 9-10 August malware pulse hit fake ChainTest, fake CubeSat tooling, and import-time wallet stealers","summary":"Newly cataloged PyPI packages `chaintest`, `cubesat-upstream-driver`, `kotanku`, `btcflip`, `btcflx`, and `kotoraka` mixed dependency-confusion lures with import-time wallet theft, secret harvesting, and developer-host compromise during 9-10 August 2026.","url":"/research/pypi-chaintest-cubesat-kotanku-august-2026","tags":["supply-chain","pypi","python","malware","dependency-confusion","credential-theft","cryptocurrency","developer-workstations","CWE-506","CWE-200","CWE-522"],"body":""},{"id":"research:redc2-npm-calendar-streak-linux-backdoor-august-2026","section":"research","title":"14 npm calendar and streak packages launched RedC2 4.0 on import","summary":"TrendAI's 21 August disclosure showed 14 trojanized npm date utilities that re-export harmless helpers from `dist/internal/daymath.mjs` but execute a loader in `dist/index.mjs` which chmods, verifies, and spawns a bundled Linux ELF. A single import, including a transitive one, starts the RedShell implant without any npm lifecycle script.","url":"/research/redc2-npm-calendar-streak-linux-backdoor-august-2026","tags":["supply-chain","npm","nodejs","linux","malware","developer-workstations","ci-cd","transitive-dependencies","appsec","CWE-506"],"body":""},{"id":"research:redhat-cloud-services-npm-miasma-shai-hulud-worm","section":"research","title":"Miasma poisoned Red Hat Cloud Services npm packages through trusted publishing","summary":"A compromised Red Hat GitHub account pushed orphan commits into RedHatInsights repositories and used GitHub Actions OIDC trusted publishing to ship Miasma, a Bun-staged credential-stealing worm with GitHub dead-drop exfiltration and local persistence, across @redhat-cloud-services npm packages.","url":"/research/redhat-cloud-services-npm-miasma-shai-hulud-worm","tags":["supply-chain","npm","red-hat","github-actions","trusted-publishing","malware","mini-shai-hulud","ci-cd","developer-workstations","CWE-506","CWE-200","CWE-522","CWE-829"],"body":""},{"id":"research:reqcrypts-pypi-response-exec-backdoor-august-2026","section":"research","title":"reqcrypts turned JSON `_payload` fields into local `exec()` on PyPI","summary":"The PyPI package `reqcrypts`, versions 0.1.0 through 0.1.3, masqueraded as a tiny HTTP helper but inspected every JSON response for a `_payload` field, base64-decoded it, and fed the result to Python `exec()`. The same 2026-08 backdoor pattern also appeared in sibling packages `reqcrypt` and `requests-crypt`.","url":"/research/reqcrypts-pypi-response-exec-backdoor-august-2026","tags":["supply-chain","pypi","python","malware","backdoor","http-clients","developer-workstations","ci-cd","appsec","CWE-506"],"body":""},{"id":"research:roberts-leads-packagist-famous-chollima-loader","section":"research","title":"roberts/leads Packagist dev branch hid a Famous Chollima blockchain loader","summary":"The Packagist package roberts/leads exposed a poisoned development branch as dev-drewroberts/feature/test-case, where tailwind.js appended obfuscated JavaScript that resolved payload material through TRON, Aptos, and BNB Smart Chain before executing it in Node.js.","url":"/research/roberts-leads-packagist-famous-chollima-loader","tags":["supply-chain","packagist","composer","php","laravel","malware","famous-chollima","developer-workstations","CWE-506","CWE-94","CWE-829"],"body":""},{"id":"research:rollup-polyfill-npm-import-time-rat-july-2026","section":"research","title":"Rollup polyfill lookalikes on npm hide an import-time loader, JSONKeeper stage, and 216.126.236.244 RAT","summary":"A June 30-July 4 disclosure chain exposed six malicious npm packages impersonating `rollup-plugin-polyfill-node`. The backdoor lives in CommonJS `dist/index.js`, silently `npm install`s second-stage packages on `require()`, `eval`s JSONKeeper-hosted code, decrypts a follow-on payload from `216.126.236.244`, and turns developer workstations or CI runners into remote-access, browser-theft, clipboard-monitoring footholds.","url":"/research/rollup-polyfill-npm-import-time-rat-july-2026","tags":["supply-chain","npm","rollup","malware","lazarus","ci-cd","developer-workstations","remote-access","credential-theft","CWE-506","CWE-494","CWE-829","CWE-94"],"body":""},{"id":"research:scrambleeer-scrambleeeer-pypi-reverse-shell-august-2026","section":"research","title":"scrambleeer and scrambleeeer: PyPI shuffle helpers opened reverse shells","summary":"The PyPI packages `scrambleeer` (`0.1.0`, `0.1.1`) and `scrambleeeer` (`0.1.0`) claimed to shuffle number lists, but their `core.py` functions opened a socket to `bax.h4x.tv:6363`, duplicated it over stdin/stdout/stderr, and spawned `/bin/bash` before returning a plausibly normal result.","url":"/research/scrambleeer-scrambleeeer-pypi-reverse-shell-august-2026","tags":["supply-chain","pypi","python","malware","reverse-shell","developer-workstations","ci-cd","appsec","CWE-506"],"body":""},{"id":"research:shai-hulud-npm-resurfaced-four-packages-september-2026","section":"research","title":"Dormant Shai-Hulud payload resurfaced in four npm packages after 111 days","summary":"On 7 September 2026, malicious versions of `feishu-docx-mcp`, `bmc-i18n-extract-cli`, `blueai-cli`, and `bmc-translate-utils` briefly landed on npm before being replaced by `0.0.1-security`. Public reporting tied the four packages to the same Shai-Hulud payload hash seen in the May 19 AntV wave, with install-time execution through `bun run index.js`.","url":"/research/shai-hulud-npm-resurfaced-four-packages-september-2026","tags":["supply-chain","npm","javascript","malware","shai-hulud","developer-workstations","ci-cd","CWE-494","CWE-506","CWE-522"],"body":""},{"id":"research:shopsprint-decimal-go-typosquat-dns-backdoor","section":"research","title":"shopsprint/decimal Go typosquat hides DNS TXT command backdoor","summary":"The typosquatted Go module github.com/shopsprint/decimal copied the popular shopspring/decimal API, then weaponized version 1.3.3 with an init() goroutine that polls DNS TXT records and executes returned commands.","url":"/research/shopsprint-decimal-go-typosquat-dns-backdoor","tags":["supply-chain","go","typosquat","malware","dns","command-injection","CWE-506","CWE-78"],"body":""},{"id":"research:sicoob-sdk-nuget-pfx-certificate-exfiltration","section":"research","title":"Sicoob.Sdk NuGet impersonator steals mTLS certificates through Sentry telemetry","summary":"Malicious Sicoob.Sdk NuGet releases 2.0.0 through 2.0.4 impersonated an official Brazilian banking SDK, then exfiltrated client IDs, PFX passwords, base64-encoded PFX certificate archives, and boleto responses from the SicoobClient constructor.","url":"/research/sicoob-sdk-nuget-pfx-certificate-exfiltration","tags":["supply-chain","nuget","dotnet","credential-theft","banking","malware","certificates","CWE-506","CWE-522"],"body":""},{"id":"research:sleepergem-rubygems-dormant-maintainer-backdoor-july-2026","section":"research","title":"SleeperGem: hijacked dormant RubyGems accounts turned `require` into a persistent developer backdoor","summary":"Between 18 and 19 July 2026, attackers used dormant RubyGems maintainer accounts and a brand-new `git_credential_manager` gem to push a staged loader chain into `Dendreo` and `fastlane-plugin-run_tests_firebase_testlab`. The malicious Ruby code disabled TLS verification, fetched shell or PowerShell payloads from a public Forgejo host, then escalated in `2.8.2` and `2.8.3` from an install-time dropper into a require-time path that planted a persistent daemon under `~/.local/share/gcm/`.","url":"/research/sleepergem-rubygems-dormant-maintainer-backdoor-july-2026","tags":["supply-chain","rubygems","ruby","malware","developer-workstations","fastlane","bundler","credential-theft","CWE-506","CWE-494","CWE-295"],"body":""},{"id":"research:snipe-it-8-4-1-api-privilege-escalation-xss-open-redirect","section":"research","title":"Snipe-IT 8.4.1 closes API admin escalation, component-note XSS, and open redirect flaws","summary":"Snipe-IT 8.4.1 fixes three newly published CVEs, led by CVE-2026-44832: an API permission-assignment bug where a user with users.edit could set permissions[admin]=1 on their own account.","url":"/research/snipe-it-8-4-1-api-privilege-escalation-xss-open-redirect","tags":["snipe-it","asset-management","laravel","api-security","xss","privilege-escalation","CWE-281","CWE-863","CWE-79","CWE-601","CVE-2026-44831","CVE-2026-44832","CVE-2026-44833"],"body":""},{"id":"research:strapi-may-2026-admin-token-oracle-query-injection","section":"research","title":"Strapi advisory cluster exposes admin token oracle and content-builder SQL injection","summary":"Five Strapi advisories published in mid-May affect npm packages across the Strapi CMS stack, including a critical unauthenticated admin reset-token oracle in @strapi/strapi and a critical Content-Type Builder SQL injection in @strapi/content-type-builder and @strapi/plugin-content-type-builder.","url":"/research/strapi-may-2026-admin-token-oracle-query-injection","tags":["npm","javascript","nodejs","cms","strapi","query-injection","account-takeover","CWE-22","CWE-89","CWE-200","CWE-307","CWE-434","CWE-693","CWE-943","CVE-2026-27886","CVE-2026-22599","CVE-2026-22707","CVE-2026-22706","CVE-2025-64526"],"body":""},{"id":"research:stubmaker-rubygems-extconf-typosquats-windows-infostealer-august-2026","section":"research","title":"StubMaker: RubyGems `extconf.rb` typosquats delivered a Windows infostealer","summary":"Fresh 15-18 August reporting on the StubMaker campaign shows how RubyGems typosquats such as `brumdler` and `brundlef` abused `extconf.rb` to fake a successful native-extension build, beacon over plain HTTP, fetch a Rust loader from GitHub Releases, and unpack an in-memory Go stealer that targeted Chromium secrets, wallet material, and Telegram data.","url":"/research/stubmaker-rubygems-extconf-typosquats-windows-infostealer-august-2026","tags":["supply-chain","rubygems","ruby","typosquatting","windows","malware","developer-workstations","bundler","appsec","CWE-295","CWE-494","CWE-506"],"body":""},{"id":"research:stylesmuggler-magento-adobe-commerce-graphql-email-rce-september-2026","section":"research","title":"StyleSmuggler: Magento zero-day chains GraphQL style input into failed-payment email RCE","summary":"Adobe has now assigned `CVE-2026-75650` to StyleSmuggler and released hotfix `VULN-39341`, but the exploit path is still the same unauthenticated `styles[...]` GraphQL input that poisons Magento-managed files and later executes during payment-failed email rendering.","url":"/research/stylesmuggler-magento-adobe-commerce-graphql-email-rce-september-2026","tags":["magento","adobe-commerce","php","graphql","zero-day","rce","linux","ecommerce","CWE-94","CVE-2026-75650"],"body":""},{"id":"research:tanstack-supply-chain-attack-mini-shai-hulud","section":"research","title":"Mini Shai-Hulud Supply-Chain Worm Compromises TanStack, Mistral AI, UiPath, and 160+ npm Packages","summary":"TeamPCP launched a coordinated supply-chain attack against the npm and PyPI ecosystems, compromising 373 malicious package versions across 169 package names including @tanstack/react-router, @mistralai/mistralai, and @uipath packages. TanStack's npm compromise is now tracked as CVE-2026-45321, and the BeProduct slice of the same worm wave is now separately tracked as CVE-2026-46412.","url":"/research/tanstack-supply-chain-attack-mini-shai-hulud","tags":["supply-chain","npm","pypi","malware","github-actions","credential-theft","CWE-506","CVE-2026-45321","CVE-2026-46412"],"body":""},{"id":"research:teampcp-fbi-flash-trivy-kics-litellm-telnyx-july-2026","section":"research","title":"FBI TeamPCP alert ties Trivy, KICS, LiteLLM, and Telnyx into one supply-chain playbook","summary":"July 2026 FBI-linked reporting consolidates TeamPCP's developer-tool tradecraft across Trivy, KICS, LiteLLM, Telnyx, npm, and PyPI: mutable CI artifacts, stolen registry credentials, Python startup hooks, runner-memory scraping, and GitHub dead-drop exfiltration.","url":"/research/teampcp-fbi-flash-trivy-kics-litellm-telnyx-july-2026","tags":["supply-chain","npm","pypi","github-actions","ci-cd","trivy","litellm","telnyx","teampcp","malware","CWE-506","CWE-494","CWE-829"],"body":""},{"id":"research:tinymce-47759-47762-stored-xss-sanitizer-bypass","section":"research","title":"TinyMCE CVE-2026-47759 through 47762 turn editor sanitization gaps into stored XSS","summary":"TinyMCE disclosed four high-severity stored-XSS vulnerabilities across npm, NuGet, and Composer packages, affecting data-mce-* attributes, nested SVG namespace handling, media plugin embeds, and forged mce:protected comments.","url":"/research/tinymce-47759-47762-stored-xss-sanitizer-bypass","tags":["vulnerability","npm","nuget","composer","tinymce","xss","cms","appsec","CWE-79","CVE-2026-47759","CVE-2026-47760","CVE-2026-47761","CVE-2026-47762"],"body":""},{"id":"research:trapdoor-npm-pypi-crates-crypto-stealer","section":"research","title":"TrapDoor used npm, PyPI, and Crates.io lures to steal developer secrets","summary":"TrapDoor is a coordinated multi-registry malware campaign affecting 34 package names across npm, PyPI, and Crates.io, with ecosystem-specific execution paths for postinstall hooks, Python import-time remote JavaScript execution, and Rust build.rs scripts targeting crypto, DeFi, AI, and security developers.","url":"/research/trapdoor-npm-pypi-crates-crypto-stealer","tags":["supply-chain","npm","pypi","crates","rust","malware","credential-theft","CWE-506"],"body":""},{"id":"research:universal-file-viewer-pub-dev-xcsset-september-2026","section":"research","title":"`universal_file_viewer` on pub.dev shipped XCSSET build hooks in retracted 0.1.5 and 0.1.6 releases","summary":"The Flutter package `universal_file_viewer` published two retracted pub.dev releases on 8 September 2026. Version `0.1.5` added an Android `preBuild` `ProcessBuilder` hook plus iOS and macOS `PBXBuildRule` downloaders that curl shell stagers from `.ru` infrastructure, while `0.1.6` removed only the Android hook and left the Xcode build rules in place until `0.1.7`.","url":"/research/universal-file-viewer-pub-dev-xcsset-september-2026","tags":["supply-chain","pub-dev","dart","flutter","malware","xcsset","macos","developer-workstations","ci-cd","appsec","CWE-506"],"body":""},{"id":"research:velora-dex-sdk-npm-minirat-macos-backdoor","section":"research","title":"@velora-dex/sdk 9.4.1 loaded a macOS MINIRAT backdoor on import","summary":"JINX-0164's npm compromise of @velora-dex/sdk 9.4.1 appended three registry-only lines to dist/index.js, causing any require() or import of the DeFi SDK to fetch a macOS shell dropper and install a Go backdoor with launchctl persistence.","url":"/research/velora-dex-sdk-npm-minirat-macos-backdoor","tags":["supply-chain","npm","cryptocurrency","malware","macos","credential-theft","ci-cd","CWE-506","CWE-78"],"body":""},{"id":"research:vitevenom-vite-npm-blockchain-rat-july-2026","section":"research","title":"ViteVenom: seven fake Vite npm scopes used blockchain dead-drops to launch a detached RAT","summary":"New July 2026 research on the ViteVenom cluster shows seven malicious npm packages impersonating Vite-related tooling, hiding their loader in `bin/vite.js`, resolving second-stage payloads through Tron, Aptos, and Binance Smart Chain transactions, and spawning a detached Node process that survives the original package execution.","url":"/research/vitevenom-vite-npm-blockchain-rat-july-2026","tags":["supply-chain","npm","vite","javascript","malware","developer-workstations","ci-cd","CWE-506","CWE-494"],"body":""},{"id":"research:vpmdhaj-opensearch-npm-cloud-ci-secrets","section":"research","title":"14 OpenSearch-themed npm typosquats stole AWS, Vault, GitHub, and npm secrets","summary":"A May 28 npm campaign published 14 OpenSearch, ElasticSearch, DevOps, and config lookalikes that executed during npm install, loaded a Bun-based credential harvester, and targeted cloud and CI/CD secrets.","url":"/research/vpmdhaj-opensearch-npm-cloud-ci-secrets","tags":["supply-chain","npm","malware","credential-theft","ci-cd","aws","opensearch","typosquatting","CWE-506","CWE-829","CWE-200"],"body":""},{"id":"research:webdriverio-browserstack-service-branch-command-injection","section":"research","title":"CVE-2026-25244: WebdriverIO BrowserStack Service executes Git branch names in shell commands","summary":"WebdriverIO BrowserStack Service versions through 9.23.2 interpolate attacker-controlled Git branch names into execSync() calls during test orchestration smart selection, allowing command injection on CI runners and developer machines.","url":"/research/webdriverio-browserstack-service-branch-command-injection","tags":["vulnerability","npm","webdriverio","command-injection","ci-cd","testing","CWE-78","CVE-2026-25244"],"body":""},{"id":"research:weekly-briefing-01-09-2026","section":"research","title":"Weekly Briefing - 01-09-2026","summary":"Corgea's weekly briefing for 26 August to 1 September 2026 covers the npm mirror phishing-host campaign, mediasoup's SCTP state-cookie forgery bug, and the higher-urgency weekend incidents already covered in the 31 August interim edition.","url":"/research/weekly-briefing-01-09-2026","tags":["weekly-briefing","npm","phishing","package-mirrors","unpkg","mediasoup","cve","sctp","rust","appsec","developer-infrastructure","CWE-451","CWE-506","CWE-345","CVE-2026-55663"],"body":""},{"id":"research:weekly-briefing-02-06-2026","section":"research","title":"Weekly Briefing - 02-06-2026","summary":"Corgea's weekly briefing for 26 May-2 June 2026 covers the Red Hat Cloud Services Miasma npm compromise, private Gitea and Forgejo container-image exposure, the js-logger-pack MicrosoftSystem64 implant, banking-certificate theft through a malicious NuGet SDK, dependency-confusion reconnaissance, OpenSearch npm typosquats, CMS privilege escalations, and stored editor XSS.","url":"/research/weekly-briefing-02-06-2026","tags":["weekly-briefing","supply-chain","npm","nuget","packagist","gitea","forgejo","github-actions","trusted-publishing","cms","xss","malware","CWE-506","CWE-200","CWE-522","CWE-829","CWE-284","CWE-862","CWE-494","CWE-426","CWE-78","CWE-79","CVE-2026-27771","CVE-2026-47759","CVE-2026-47760","CVE-2026-47761","CVE-2026-47762","CVE-2026-48898","CVE-2026-48904","CVE-2026-44831","CVE-2026-44832","CVE-2026-44833"],"body":""},{"id":"research:weekly-briefing-02-08-2026","section":"research","title":"Weekly Briefing - 02-08-2026","summary":"Corgea's weekly briefing for 30 July-2 August 2026 covers the Arch AUR malware wave that forced an adoption freeze, Anthropic's likely `anthropickit` PyPI credential stealer, Joyfill's blockchain-resolved npm RAT chain, and Linux `CVE-2026-53264`.","url":"/research/weekly-briefing-02-08-2026","tags":["weekly-briefing","supply-chain","aur","arch-linux","pypi","npm","linux","developer-workstations","ci-cd","appsec","CWE-362","CWE-416","CWE-494","CWE-506","CWE-522","CWE-829","CVE-2026-53264"],"body":""},{"id":"research:weekly-briefing-04-08-2026","section":"research","title":"Weekly Briefing - 04-08-2026","summary":"Corgea's weekly briefing for 29 July-4 August 2026 covers the keyv/cacheable npm worm, Anthropic's likely `anthropickit` PyPI incident, Joyfill's import-time RAT chain, and the week's other important Alibaba-targeted, Linux kernel, GitPython, and Axios research.","url":"/research/weekly-briefing-04-08-2026","tags":["weekly-briefing","npm","pypi","supply-chain","linux","nodejs","python","malware","ci-cd","developer-workstations","ai","appsec","CWE-78","CWE-94","CWE-200","CWE-362","CWE-416","CWE-494","CWE-506","CWE-522","CWE-829","CVE-2026-53264","CVE-2026-67320","CVE-2026-67324"],"body":""},{"id":"research:weekly-briefing-05-09-2026","section":"research","title":"Weekly Briefing - 05-09-2026","summary":"Corgea's weekly briefing for 2-5 September 2026 covers CISA's KEV additions for LiteLLM's MCP auth bypass and Starlette's Host-header path confusion, then explains why the requested Aikido, Wiz, Socket, and Endor Labs feeds did not surface a separate package-registry compromise or Linux zero-day in the same short window that justified a duplicate Corgea write-up.","url":"/research/weekly-briefing-05-09-2026","tags":["weekly-briefing","pypi","pip","python","litellm","starlette","mcp","kev","appsec","CWE-287","CWE-306","CWE-436","CVE-2026-59822","CVE-2026-48710"],"body":""},{"id":"research:weekly-briefing-07-07-2026","section":"research","title":"Weekly Briefing - 07-07-2026","summary":"Corgea's weekly briefing for 1-7 July 2026 covers PolinRider's cross-ecosystem supply-chain expansion, the Rollup polyfill npm RAT chain, Bad Epoll's public Linux root exploit, and the week's most important TeamPCP, Keras, buffa/connectrpc, and libzypp research.","url":"/research/weekly-briefing-07-07-2026","tags":["weekly-briefing","supply-chain","npm","pypi","go","packagist","linux","ci-cd","malware","appsec","CWE-506","CWE-94","CWE-494","CWE-200","CWE-416","CWE-362","CWE-502","CWE-400","CWE-770","CWE-22","CVE-2026-46242","CVE-2026-12481","CVE-2026-55407","CVE-2026-25707"],"body":""},{"id":"research:weekly-briefing-08-09-2026","section":"research","title":"Weekly Briefing - 08-09-2026","summary":"Corgea's weekly briefing for 1-8 September 2026 leads with the active StyleSmuggler Magento zero-day, then covers Fastify middie's absolute-form auth bypass, pnpm's install-time path traversals, and the week's RubyGems and xmldom containment bugs that were not already covered in the 1 September or 5 September briefings.","url":"/research/weekly-briefing-08-09-2026","tags":["weekly-briefing","magento","adobe-commerce","fastify","pnpm","rubygems","xmldom","php","javascript","nodejs","ruby","ci-cd","supply-chain","appsec","CWE-94","CWE-436","CWE-22","CWE-59","CWE-400","CVE-2026-85184","CVE-2026-82392","CVE-2026-82393","CVE-2026-82455","CVE-2026-83619"],"body":""},{"id":"research:weekly-briefing-09-06-2026","section":"research","title":"Weekly Briefing - 09-06-2026","summary":"Corgea's weekly briefing for 2-9 June 2026 covers the Phantom Gyp Miasma npm wave, Hades' expansion into MCP-focused PyPI packages, the nvm mirror command injection flaw, and the now-exploited Oracle WebLogic T3/IIOP exposure issue.","url":"/research/weekly-briefing-09-06-2026","tags":["weekly-briefing","supply-chain","npm","pypi","nodejs","mcp","python","oracle","weblogic","malware","CWE-506","CWE-494","CWE-829","CWE-522","CWE-78","CVE-2026-10796","CVE-2024-21182"],"body":""},{"id":"research:weekly-briefing-11-08-2026","section":"research","title":"Weekly Briefing - 11-08-2026","summary":"Corgea's weekly briefing for 5-11 August 2026 covers PyPI's 9-10 August malware pulse, Apache Tomcat's fail-open `EncryptInterceptor` KEV path, Linux SCTP's SCTPhantom root and container-escape chain, and the week's NLTK downloader poisoning research.","url":"/research/weekly-briefing-11-08-2026","tags":["weekly-briefing","pypi","python","linux","java","tomcat","nltk","supply-chain","malware","ci-cd","developer-workstations","containers","appsec","CWE-200","CWE-284","CWE-311","CWE-416","CWE-494","CWE-506","CWE-522","CVE-2026-34486","CVE-2026-64564","CVE-2026-12259","CVE-2026-12261"],"body":""},{"id":"research:weekly-briefing-14-07-2026","section":"research","title":"Weekly Briefing - 14-07-2026","summary":"Corgea's weekly briefing for 8-14 July 2026 covers Jscrambler's import-time npm compromise, Braintree.Net's production payment skimmer, Injective's wallet-key exfiltration release, and the week's most important Airflow, Paysafe, Operation Muck and Load, and apko/melange research.","url":"/research/weekly-briefing-14-07-2026","tags":["weekly-briefing","supply-chain","npm","nuget","pypi","go","wallets","payments","ci-cd","appsec","CWE-506","CWE-522","CWE-200","CWE-494","CWE-829","CWE-502","CWE-345","CWE-354","CVE-2026-33264","CVE-2026-54174"],"body":""},{"id":"research:weekly-briefing-15-06-2026","section":"research","title":"Weekly Briefing - 15-06-2026","summary":"Corgea's weekly briefing for 10-15 June 2026 covers the Atomic Arch AUR takeover, Netty's security-heavy 4.1.135 / 4.2.15 release, the onering crates compromise, and a late-breaking Open VSX extension attack that used TinyGo WebAssembly plus Solana memo-based C2.","url":"/research/weekly-briefing-15-06-2026","tags":["weekly-briefing","supply-chain","linux","aur","npm","bun","java","maven","netty","rust","crates","vscode","open-vsx","wasm","solana","CWE-494","CWE-506","CWE-347","CWE-444","CWE-400","CVE-2026-50010","CVE-2026-50011","CVE-2026-50020","CVE-2026-50560"],"body":""},{"id":"research:weekly-briefing-16-06-2026","section":"research","title":"Weekly Briefing - 16-06-2026","summary":"Corgea's weekly briefing for 10-16 June 2026 covers the uncovered remainder of the week's research: the dbmux Phantom Gyp / Miasma compromise, Dulwich's Windows and format-patch path traversal fixes, libp2p's unauthenticated DHT disk-exhaustion flaw, and Spring's internally discovered WebFlux and static-resource DoS fixes.","url":"/research/weekly-briefing-16-06-2026","tags":["weekly-briefing","npm","supply-chain","python","pypi","git","windows","javascript","libp2p","spring","dos","CWE-506","CWE-22","CWE-20","CWE-400","CVE-2026-42305","CVE-2026-47712","CVE-2026-45783","CVE-2026-41840","CVE-2026-41842"],"body":""},{"id":"research:weekly-briefing-18-08-2026","section":"research","title":"Weekly Briefing - 18-08-2026","summary":"Corgea's weekly briefing for 12-18 August 2026 covers the StubMaker RubyGems typosquat wave, LiteLLM's August blast-radius disclosure, and the JupyterLab PyPI extension-manager bypasses.","url":"/research/weekly-briefing-18-08-2026","tags":["weekly-briefing","rubygems","ruby","pypi","python","malware","developer-workstations","ci-cd","appsec","CWE-178","CWE-180","CWE-295","CWE-494","CWE-506","CWE-522","CVE-2026-73416","CVE-2026-73627","CVE-2026-73626"],"body":""},{"id":"research:weekly-briefing-19-05-2026","section":"research","title":"Weekly Briefing - 19-05-2026","summary":"Corgea's weekly briefing for 12-19 May 2026 covers the durabletask PyPI compromise, the Mini Shai-Hulud expansion into AntV and related npm packages, the Nx Console extension compromise, WebdriverIO command injection, and other important supply-chain, kernel, and application-security research from the week.","url":"/research/weekly-briefing-19-05-2026","tags":["weekly-briefing","supply-chain","npm","pypi","go","vscode","malware","linux","strapi","github-releases","CWE-506","CWE-78","CWE-123","CWE-89","CWE-94","CWE-200","CWE-307","CWE-434","CWE-693","CWE-943","CVE-2026-25244","CVE-2026-45321","CVE-2026-27886","CVE-2026-22599","CVE-2026-22707","CVE-2026-22706","CVE-2025-64526","CVE-2026-46300","CVE-2026-43284","CVE-2026-43500","CVE-2026-41242"],"body":""},{"id":"research:weekly-briefing-21-07-2026","section":"research","title":"Weekly Briefing - 21-07-2026","summary":"Corgea's weekly briefing for 15-21 July 2026 covers SleeperGem's dormant RubyGems maintainer compromise, Pepesoft's malicious NuGet tool cluster, and CVE-2026-48815 in sigstore-js.","url":"/research/weekly-briefing-21-07-2026","tags":["weekly-briefing","supply-chain","rubygems","nuget","sigstore","developer-workstations","artifact-signing","appsec","CWE-506","CWE-494","CWE-295","CWE-347","CWE-200","CWE-829","CVE-2026-48815"],"body":""},{"id":"research:weekly-briefing-23-06-2026","section":"research","title":"Weekly Briefing - 23-06-2026","summary":"Corgea's weekly briefing for 17-23 June 2026 covers the Mastra npm scope takeover that weaponized easy-day-js across more than 140 packages, plus Nodemailer's newly disclosed raw-message file-read and SSRF bypass.","url":"/research/weekly-briefing-23-06-2026","tags":["weekly-briefing","npm","supply-chain","nodejs","ai","malware","nodemailer","ssrf","file-read","appsec","CWE-506","CWE-494","CWE-829","CWE-73","CWE-918","CWE-200"],"body":""},{"id":"research:weekly-briefing-25-08-2026","section":"research","title":"Weekly Briefing - 25-08-2026","summary":"Corgea's weekly briefing for 19-25 August 2026 covers the compromised Rust crates arrayref, internment, and append-only-vec; TrendAI's RedC2 npm cluster; Ray's KEV browser-to-dashboard RCE; the fresh scrambleeer PyPI reverse-shell pair; and the reqcrypts response-driven backdoor.","url":"/research/weekly-briefing-25-08-2026","tags":["weekly-briefing","supply-chain","crates","rust","npm","pypi","python","nodejs","linux","malware","ray","ci-cd","developer-workstations","ai-infrastructure","appsec","CWE-94","CWE-295","CWE-352","CWE-494","CWE-506","CVE-2025-62593"],"body":""},{"id":"research:weekly-briefing-26-05-2026","section":"research","title":"Weekly Briefing - 26-05-2026","summary":"Corgea's weekly briefing for 19-26 May 2026 covers the GitHub internal repository breach tied to the Nx Console compromise, TrapDoor's multi-registry package malware campaign, exploited Drupal and Langflow KEV vulnerabilities, Laravel-Lang tag rewrites, TensorRT-LLM deserialization flaws, the art-template browser exploit-chain compromise, and a Linux ptrace local privilege escalation.","url":"/research/weekly-briefing-26-05-2026","tags":["weekly-briefing","supply-chain","npm","pypi","crates","packagist","vscode","github","drupal","ai-security","linux","malware","CWE-506","CWE-200","CWE-89","CWE-1357","CWE-269","CWE-346","CWE-502","CVE-2026-48027","CVE-2026-9082","CVE-2026-46333","CVE-2025-34291","CVE-2025-33255","CVE-2026-24142","CVE-2024-23222"],"body":""},{"id":"research:weekly-briefing-28-07-2026","section":"research","title":"Weekly Briefing - 28-07-2026","summary":"Corgea's weekly briefing for 22-28 July 2026 covers GitHub Actions abuse tied to cPanel/WHM exploitation, ViteVenom's blockchain-backed npm RAT, RefluXFS's XFS local-root race, and Netty's July decoder DoS fixes.","url":"/research/weekly-briefing-28-07-2026","tags":["weekly-briefing","supply-chain","npm","packagist","github-actions","linux","kernel","cpanel","netty","ci-cd","appsec","CWE-93","CWE-362","CWE-367","CWE-400","CWE-494","CWE-506","CWE-770","CVE-2026-41940","CVE-2026-64600","CVE-2026-44891","CVE-2026-55831","CVE-2026-55833"],"body":""},{"id":"research:weekly-briefing-30-06-2026","section":"research","title":"Weekly Briefing - 30-06-2026","summary":"Corgea's weekly briefing for 24-30 June 2026 covers the ImmobiliareLabs Backstage plugin compromise, Leo Platform's expanding Phantom Gyp/Miasma package wave, expr-eval's no-fix Node.js code-execution flaw, and Vite's Windows dev-server secret leak.","url":"/research/weekly-briefing-30-06-2026","tags":["weekly-briefing","npm","supply-chain","nodejs","javascript","backstage","gitlab","ldap","miasma","code-execution","vite","windows","CWE-506","CWE-494","CWE-829","CWE-94","CWE-22","CWE-200","CVE-2026-12866","CVE-2026-53571"],"body":""},{"id":"research:weekly-briefing-31-08-2026","section":"research","title":"Weekly Briefing - 31-08-2026","summary":"Corgea's weekly briefing for 28-31 August 2026 covers the compromised `@7nohe/openapi-react-query-codegen` release workflow, the KEV-listed Linux UDPv6 `fraggap` container-escape path in `CVE-2026-53362`, and why the rest of the weekend's reporting mostly added depth to those same two incidents.","url":"/research/weekly-briefing-31-08-2026","tags":["weekly-briefing","supply-chain","npm","pypi","rubygems","github-actions","linux","kernel","containers","ci-cd","developer-workstations","appsec","CWE-94","CWE-506","CWE-787","CVE-2026-53362"],"body":""},{"id":"customers:epilot","section":"customers","title":"epilot customer case study","summary":"Learn how epilot embedded security directly into engineering workflows with Corgea.","url":"/customers/epilot","tags":["epilot","Energy software","Cologne, Germany","Struggled to implement and maintain a previous AppSec tool from a large incumbent.","Needed a native GitLab workflow without enterprise-only pricing and extra CI complexity.","Missed complex business logic and authorization issues that mattered to the platform.","Dealt with unresolved bugs and weak support, making ROI hard to justify.","Implemented Corgea in less than one week through the native GitLab integration.","Rolled out security workflows to engineers without disrupting how teams already shipped code.","Used Corgea APIs to power dashboards in the BI tooling the team already trusted.","Centralized findings, trends, and remediation activity in one operational view.","Security is now embedded directly in the developer workflow.","The team can detect complex logic and authorization vulnerabilities earlier.","The platform's overall security posture improved with better visibility and follow-through.","Developers are happier and more productive because security fits their existing process."],"body":""}]