
Removing supply chain friction: How PeopleTec improved developer productivity with Chainguard
Learn how PeopleTec used Chainguard to reduce security friction, accelerate adoption, and align platform consistency with developer velocity.
2432 articles

Learn how PeopleTec used Chainguard to reduce security friction, accelerate adoption, and align platform consistency with developer velocity.

Public registries create supply chain risk. Learn how source-built libraries help APRA-regulated teams improve security, resilience, and auditability.

Open Source Security Advisory Update: Wednesday, April 1, 2026 Boston, MA 10:00 AM ET Over the past week, we have nearly finalized our investigation and are now in the final stages of documentation and review. There continues to be no indication that Aqua’s commercial products have been affected. As part of this process, we identified

Learn 5 key lessons from Snyk’s Evo design partner program. Discover how AI discovery, risk intelligence, and policy automation help teams secure generative AI and govern AI sprawl at scale.

In 2025, Google celebrated the 15th anniversary of its Vulnerability Reward Program (VRP), enhancing collaborations with the security research community. The program awarded over $17 million to more than 700 researchers globally, marking a 40% increase from the previous year. New initiatives included a dedicated AI VRP and a patch rewards program for open-source vulnerabilities. Significant bugSWAT events resulted in numerous reports and rewards. Looking ahead to 2026, Google plans to continue these efforts, fostering innovation and security enhancements.

Malicious axios versions on npm delivered a RAT via a hidden dependency. Chainguard customers were protected by blocking unsafe packages and verifying source.

AI is accelerating software and CVE growth. Chainguard’s latest report shows rising risk in the long tail and how teams can stay secure at scale.

Meta description: Malicious versions of the Axios npm package (1.14.1 and 0.30.4) were published via a compromised maintainer account, injecting a hidden dependency that deploys a cross-platform remote access trojan. Here’s what happened, who’s affected, and how to check your exposure.

Malicious telnyx versions hit PyPI in a wider supply chain attack. Chainguard customers stayed protected by using source-built, verified libraries.

Discover the 5 principles behind Snyk’s developer experience. Learn how seamless workflows, actionable fixes, and AI-driven security help developers ship secure code faster without disrupting productivity.

Google is addressing the imminent threats posed by quantum computing to digital security through the introduction of Post-Quantum Cryptography (PQC) in Android 17. This transition aims to safeguard essential digital systems currently reliant on public-key cryptography. Key upgrades include PQC integration in Android Verified Boot and Remote Attestation, which enhance foundational security, and updates to the Android Keystore for developers to utilize quantum-resistant cryptography. The approach also promotes hybrid signing for Google Play apps to ensure app authenticity against quantum-enabled signature forgery. This initiative, part of a broader plan initiated in 2016, aims to fortify the entire Android ecosystem against future quantum threats.

AI red teaming is the next step after AI-SPM. Learn how Evo Agent Red Teaming simulates real attacks to uncover prompt injection, data exposure, and behavioral vulnerabilities in AI systems.