All posts
Topic
Appsec
3 articles on appsec.
Shai-Hulud Took keyv โ and the Malware Shipped With Valid Provenance
A maintainer account compromise poisoned keyv, flat-cache, file-entry-cache and the rest of the family, then spread to 868 more packages across 1,381 versions โ over 2 billion monthly installs. The releases were signed by GitHub Actions and the provenance checks out. That is the part worth your attention.
August 4, 2026
An AI Agent Found 19 Redis Zero-Days โ in About 90 Minutes
Researchers say Kimi K3 agents chained a Redis streams double-free with a RedisBloom heap overflow into working authenticated RCE, with one exploit produced in 27 minutes. Redis shipped seven security releases in response. The claims are self-reported โ but the patches are real.
July 24, 2026
Anthropic Launches Claude Security: AI Vulnerability Scanning Built Into Claude Code
Claude Security is a new beta plugin that scans code changes or entire repos for high-severity vulnerabilities directly in the terminal โ reasoning through data flows like a security researcher instead of pattern-matching, with adversarial self-checks to cut false positives. Here's how it works and what it means for AppSec teams.
July 23, 2026