
This Shit is Hard: Applying "Zero Trust" to Open Source Software
Chainguard implements Zero Trust principles into everything we do to protect critical infrastructure in the age of open source. See how we do it.
2432 articles

Chainguard implements Zero Trust principles into everything we do to protect critical infrastructure in the age of open source. See how we do it.

Urgent security alert: On September 25, 2025, the npm package ‘postmark-mcp’ was compromised, secretly exfiltrating email contents. Learn about the incident timeline, impact, and immediate mitigation steps, including uninstalling, rotating credentials, and scanning with Snyk’s MCP-Scan.

Chainguard Libraries for JavaScript is designed to protect developers and organizations from compromised packages, malicious updates, and registry-based attacks.

Elie Bursztein and Marianna Tishchenko from Google’s Privacy, Safety and Security Team emphasize the importance of using AI to strengthen cybersecurity. At DEF CON 33, they hosted the GenSec Capture the Flag (CTF) event in partnership with Airbus, focusing on human-AI collaboration. Nearly 500 participants engaged, with many using AI tools for the first time. Positive feedback highlighted the effectiveness of AI in cybersecurity workflows. Sec-Gemini, Google’s Cybersecurity AI, received commendations for its utility. The event’s success and community input will guide future improvements.

Discover how Snyk Learn helps organizations meet PCI DSS v4.0 developer training requirements by providing relevant, just-in-time, interactive, and trackable security education for developers.

Discover more about Chainguard’s new integration with Anchore Enterprise.

We’re thrilled to share that Snyk has, for the sixth time and fifth consecutive year, been named to the Forbes Cloud 100 ranked at #51, recognizing the world’s most innovative private cloud companies.

Learn how to evaluate and select the right Linux distribution to satisfy your team’s needs, simplify migration, and avoid vendor lock-in.

Gain visibility and control over your AI-driven development. Snyk’s new features help AppSec teams govern security, prioritize risks in AI-generated code, and scale your security program effectively.

Discover how Labelbox transformed security backlog management from two years to two weeks with Snyk’s AI-accelerated remediation.

Explore how aligning development and security teams can transform project efficiency and security protocols.

Rowhammer is a hardware vulnerability in DRAM that allows attackers to cause data corruption by repeatedly accessing memory rows. This can lead to unauthorized data access, privilege escalation, or denial of service. While vendors have implemented mitigations like Target Row Refresh (TRR) for DDR5, recent findings reveal these defenses can be bypassed by sophisticated attacks. Google’s collaboration with researchers has resulted in new testing platforms and insights into effective countermeasures, highlighting the need for ongoing improvements to DRAM security, including potential future standards like PRAC.