
The State of Trusted Open Source: June 2026
AI is accelerating vulnerability discovery. Explore the latest trusted open source trends, dependency risks, and CVE insights from Chainguard’s report.
2432 articles

AI is accelerating vulnerability discovery. Explore the latest trusted open source trends, dependency risks, and CVE insights from Chainguard’s report.

The AWS Customer Incident Response Team (AWS CIRT) encounters patterns that repeat across engagements when helping customers respond to security incidents. We’re passionate about making sure that information is accessible so that everyone can improve their security posture and their organization’s resilience to disruption. The primary method we use to share this information is the

Eliminate context-switching during authentication development. Learn how to connect the Auth0 MCP Server to Claude Code for real-time access to the complete Auth0 documentation directly inside your terminal terminal workspace.

The Threat Intelligence Bulletin for the week of June 29 highlights recent cyber research findings. A significant incident involved Polymarket, a cryptocurrency prediction market, which confirmed a supply chain attack. This breach occurred after malware was injected into its website via a compromised third-party frontend vendor. As a result, users were misled into approving fraudulent transactions. The report underscores the ongoing risks associated with supply chain vulnerabilities.

The Cloud Security Alliance (CSA) has partnered with AIUC-1 to create a new designation for enterprises to identify providers that have proven their AI agents and autonomous AI systems are safe, secure, and reliable. Announced on June 30, 2026, this initiative responds to the increasing need for verifiable assurance in AI technologies, emphasizing the CSA’s commitment to promoting education and standards in AI, cloud, and Zero Trust cybersecurity.

Snyk VulnBench JS 1.0: 300 repeated scans show LLM security findings vary by run, while SAST and models catch different vulnerability gaps.

The Shai-Hulud Miasma campaign has introduced new malicious packages due to a compromised maintainer account affecting the Leo Platform and RStreams ecosystems. Sonatype has identified 23 malicious package versions, which exploit techniques like binding.gyp to execute malicious code during installation, thus bypassing standard detection methods. Organizations must treat potentially affected environments as compromised and conduct thorough investigations, removing malicious versions and rotating credentials carefully to prevent further exposure. This incident highlights the escalating risk in the npm ecosystem, where attackers compromise trusted packages and workflows instead of merely publishing new malicious packages. Regular scrutiny of package behaviors at install time is essential for security.

For most of my career, software security has been treated as an individual responsibility.

In this week’s newsletter, Martin considers how AI will help threat intelligence by creating an easily queryable data source of intelligence reports.

Component Object Model (COM) is a fundamental Windows technology used by legitimate applications for object activation, inter-process communication, automation and language-independent component reuse. Those same qualities make it useful to threat actors.

Chainguard Repository adds malware and greyware scanning, expanded policy controls, and visibility to secure AI-driven software supply chains.

Get the details on everything Chainguard announced during AI Readiness Innovation Week, including new features for Chainguard Libraries and Chainguard Containers