
Introducing the Activity Center: One place for every change that matters
Chainguard’s Activity Center centralizes alerts for CVEs, breaking changes, and updates — delivering real-time notifications where your teams already work.
2432 articles

Chainguard’s Activity Center centralizes alerts for CVEs, breaking changes, and updates — delivering real-time notifications where your teams already work.

On March 24, 2026, threat actor known as TeamPCP published backdoored versions of the litellm Python package after stealing PyPI credentials via a compromised Trivy GitHub Action in LiteLLM’s CI/CD pipeline. Here’s what happened, how the three-stage malware works, and how to check if you’re affected.

Hackers compromised litellm on PyPI to steal secrets. Chainguard Libraries prevented exposure by rebuilding only verified source, blocking malicious releases.

Introducing Agent Security, a unified approach to governing AI agents and ensuring safe behavior from code to runtime. Start with Evo AI-SPM, now generally available.

Chainguard customers are unaffected by the Trivy supply chain attack.

Static analysis tells you what might be vulnerable, but dynamic testing tells you what is actually exploitable. Learn why the next era of AppSec requires combining code-level context with live environment testing to secure AI-generated code.

Speed has outpaced validation. With 62% of LLM-generated code testing as insecure and AI agents using undocumented APIs, legacy tools fall short. Learn how Snyk’s AI-powered dynamic testing secures your expanding attack surface.

At Chainguard Assemble 2026, Outsystems shared how it transformed its release process through platform engineering.

Snyk is opening a new innovation hub in downtown San Francisco, creating a strategic center of gravity for AI security. This new community space invites all Bay Area builders to join weekly hackathons and technical sessions to help shape the future of secure AI innovation.

Cursor built AI security agents that review 3,000+ PRs weekly and catch 200+ vulnerabilities. Here’s what they get right—and what’s missing for enterprise security.

Snyk and Tessl have partnered to bring security scanning to every skill in the Tessl Registry. Every public skill now carries a Snyk security score, bringing the same trust signals developers expect from package managers to the agent skills ecosystem.

Catch up on all the announcements Chainguard made at Assemble 2026, featuring AI agent skills, CI/CD workflows, and more.