This case study is written by Udi-Yehuda Tamar, VP of Platform Engineering and Global CISO at Checkmarx, based on Checkmarx's experience using StepSecurity at scale. The rollout was led by Yevgeny ...
56 supply chain attacks in 12 months, each with a StepSecurity Threat Center alert. The data, the worms, the Team PCP numbers, and how to defend.
An external GitHub user exploited an exposed npm publishing workflow for @7nohe/openapi-react-query-codegen and shipped ten malicious versions that run attacker code during installation.
A compromised maintainer account and a same-day impersonator of one of Rust's best-known authors turned a routine cargo update into silent remote code execution. Three crates from the same owner were ...
What is supported Harden-Runner supports GitHub Actions runners hosted on AWS CodeBuild on EC2 compute, starting with the Harden-Runner GitHub Action v2.20.1. v2.21.0 extends that to CodeBuild runners ...
Ports are not part of a deny list entry. A denied endpoint is denied on every port, and if you write one anyway it is stripped and ignored. registry.example.com:443 denies registry.example.com on ...
Dev Machine Guard now inventories browser extensions across your developer fleet. See every extension installed in Chrome, Edge, and Firefox, what each one is currently permitted to do, whether it ...
As software supply chain attacks targeting the NPM ecosystem accelerated throughout 2025, Utility Warehouse’s security team recognized an opportunity to strengthen its posture before an incident ...
Have a question or feedback? We would love to hear from you. Submit the form below or email us directly at info@stepsecurity.io ...