Syft and Trivy reported 43.78% and 32.71% of lockfile packages across 2,050 JavaScript repositories in an Inria and ANSSI study, against 98.72% for cdxgen. The tool, its version and its flags decide what an SBOM lists, so that recipe belongs under version control.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence50
Two men arrested in Australia this week are alleged TeamPCP members. The AFP estimate filed alongside the case puts the worm's take at more than 500,000 credentials and 300GB of data, and that scale makes token lifetime the live question.
Perspective Coverage
17 publishers
- Builder
- Builder 33%
- Operator
- Operator 50%
- Investor
- Investor 17%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+25
- Incentives55
- Confidence62
Mandiant's findings say the intrusion never reached Checkmarx One or production AWS, and that answers the vendor's question rather than the one a customer has about what a build box pulled in late March.
Publishers:checkmarx.com
Reality
- Evidence38
- Adoption
- Insufficient
- Hype gap+25
- Incentives65
- Confidence45
From 11 September 2026, an actively exploited vulnerability starts a 24-hour early warning, a 72-hour notification and a 14-day final report, all timed from awareness. The artifact that decides whether you make it is your SBOM archive.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+15
- Incentives50
- Confidence60
k8s-secure-supply-chain, a kind-based reference build, uses five Kyverno checks to refuse at admission any image that CI did not sign and attest. Its author argues that CI scans and signatures stay advisory until the cluster enforces them.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives20
- Confidence50
Austin Larsen of Google's threat intelligence group says a Mandiant persona sat in TeamPCP's inner circle from almost the start of the campaign. For the companies the group breached, that infiltration was the warning system.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives60
- Confidence55
GitHub's volume counters and Chainguard's account of agent-written code both point at dependency review as the step nobody is doing. Mandiant estimates mean time-to-exploit at minus seven days in 2025.
Reality
- Evidence43
- Adoption55
- Hype gap+27
- Incentives76
- Confidence42
TeamPCP hijacked developer accounts, poisoned hundreds of programs and released a worm to automate the spread. Google says the inside access let it warn victims, revoke stolen credentials and help patch an AI-developed zero-day.
Reality
- Evidence32
- Adoption38
- Hype gap+22
- Incentives68
- Confidence30
Tool text is fetched from the server every time an agent connects, so the description reviewed at install time can differ from the one the model reads next week. A dev.to post proposes pinning a hash of it and checking that hash in CI.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+20
- Incentives80
- Confidence50
The GitOps tooling worked, and seven services still went back to Docker Compose in a day, because the operator consumes every one of those images and cuts release tags for none of them.
Reality
- Evidence45
- Adoption12
- Hype gap+15
- Incentives30
- Confidence55
Install hooks and .pth files execute before your first import, which puts the useful controls in resolver precedence and environment scope rather than in a test suite that passes either way.
Reality
- Evidence34
- Adoption58
- Hype gap+20
- Incentives55
- Confidence33
Two litellm releases that never came out of the project's CI harvested SSH keys and cloud credentials from every host that installed them. litellm traces the entry point to the Trivy scanner in its own pipeline.
Reality
- Evidence48
- Adoption
- Insufficient
- Hype gap+12
- Incentives78
- Confidence42
The maintainers date the second wave to March 19, eighteen days after they disclosed the first one and rotated credentials without doing it all at once, and the only action tag that came through clean was one GitHub had already frozen.
Reality
- Evidence74
- Adoption52
- Hype gap−14
- Incentives68
- Confidence61
Two suspects in Western Australia are in custody over the supply-chain worm that hit Trivy, KICS, LiteLLM and Telnyx. The 500,000 credentials it harvested stay valid until someone rotates them. Only 78,000 have surfaced publicly.
Reality
- Evidence50
- Adoption62
- Hype gap+14
- Incentives45
- Confidence52
Google places the spree with a single operator in South Africa, which makes one arrest plausible, while Palo Alto Networks counts three core members. Either way, the packages moved because almost nobody checks what they ingest.
Reality
- Evidence58
- Adoption74
- Hype gap+10
- Incentives68
- Confidence55
Shai-Hulud is on its fourth iteration. Trivy, Axios and LiteLLM have all shipped compromised releases. ReversingLabs is giving away a plugin that checks every package request against a reputation index inside Artifactory itself.
Reality
- Evidence38
- Adoption8
- Hype gap+22
- Incentives85
- Confidence45
Anthropic, Sysdig, Unit 42 and GitGuardian describe the same shape of failure, which puts the interesting number on your side of the fence: how long an issued token keeps working after it leaves your control.
Reality
- Evidence27
- Adoption44
- Hype gap+37
- Incentives71
- Confidence57
A week of takedowns removed people and froze assets across five separate actions, while the kit that manufactures the stolen Microsoft 365 sessions those crews depend on still sells on Telegram for $320 a month.
Reality
- Evidence28
- Adoption52
- Hype gap+30
- Incentives58
- Confidence36
Unit 42 says the group backdoored Trivy, KICS, LiteLLM and Telnyx's Python SDK, tools that run inside CI with the privileges needed to reach production secrets, which is also why the headline counts deserve a slow read.
Reality
- Evidence55
- Adoption58
- Hype gap+32
- Incentives78
- Confidence48
Datadog's investigation puts genuine PyPI releases of litellm and telnyx inside the same campaign that poisoned Trivy on March 19, which makes the unit of remediation the secrets the build could see rather than the version pin.
Publishers:securitylabs.datadoghq.com
Reality
- Evidence71
- Adoption62
- Hype gap−8
- Incentives58
- Confidence64
Earlier coverage
- Oligo dates the crew behind ShadowRay 2.0's self-propagating botnet back to 2020
Security · August 28, 2026 · 1 publisher
- 56 build-pipeline attacks, one vendor's alert queue, and the February jump nobody can attribute yet
Build · August 23, 2026 · 1 publisher
- Reading OIDC tokens out of runner memory: ChainDrop and the poisoned build
Security · August 21, 2026 · 1 publisher
- Flux moves GitOps' source of truth into registries you own, and mirroring becomes the prerequisite
Build · August 20, 2026 · 1 publisher
- LiteLLM 1.82.7 and 1.82.8 shipped an infostealer: rotate everything those machines touched
Science · August 20, 2026 · 1 publisher
- VECT 2.0 shreds anything over 128 KB, which makes paying its ransom pointless
Leadership · August 18, 2026 · 1 publisher
- One alert, two causes, four green dashboards: the day the stack agreed and was wrong
Build · August 18, 2026 · 1 publisher
- Docker pipes every agent policy decision into your SIEM, and the evidence burden lands on platform teams
Product · August 17, 2026 · 1 publisher
- The 2,500-org compromise was a Trivy problem. LiteLLM was the closing act.
Security · August 14, 2026 · 1 publisher