For the first time the AI Engineer World's Fair has a dedicated AI Security track and Snyk is proud to be the presenting partner.
Join us in San Francisco, Jun 29 – July 2 for sessions built around the belief that security starts at inception.
More here: https://t.co/F0B5GH4fYb
See you in the Fan Zone ⚽️ 🏆
We're bringing the Snyk Connect community together. Part tournament, part tailgate, all defense. Live hacking and head-to-head AISec challenges, stadium-style eats, and giveaways worthy of a champion.
Grab your spot here: https://t.co/GKEX6zhk77
Lots of supply chain attacks right now.
If you use pnpm v11 it will stop updates to packages that were published less than 24 hours ago.
This protects you because most supply chain attacks are fixed within a few hours (at least for major packages).
Couple this with Snyk and Socket for extra protection.
you ready for @AISecSummit in London next Thursday? 🤩
Join us to learn how agentic security looks like from the eyes of CISOs, AppSec and builders of next-gen security tools
Grab your ticket here: https://t.co/jiTdID5Dft
@Mugilan_SS@OpenAI It’s the small things. When we designed this the tradeoff was between a good experience or optimize for margin and not allow to draw more usage than you technically have.
We chose to optimize for the experience as it’s really annoying to have your agent interrupted midway.
We are live on @ProductHunt with Skill Inspector app ✨
Your mission if you choose to accept it:
1. Go to
https://t.co/hZiZbhKtmP
2. Login
3. Upvote
Good luck, agent
The Vercel security breach is a reminder that each and every SaaS tool your team uses IS a security risk of its own - especially if they need broad data access to eg email, internet docs etc (many AI tools do just this)
Security teams onboarding new vendors happens for a reason.
Are you an open source maintainer? 👋💜
If so, we’d love to support your project by providing you with complimentary access to our industry-leading developer security tooling and infrastructure! https://t.co/zswcH5hjoH
Check out Snyk's Free Security for Open Source program
Congratulations on being one of the first people in the world to gain this credential for AI Security Engineer Pratul K.
Keep learning about AI on Snyk Learn https://t.co/T34rqBGTtY ✨
🚨 ACTIVE SUPPLY CHAIN ATTACK
Two malicious versions of `axios`, the npm package with 300M+ weekly downloads, were just published via a hijacked maintainer account and have deployed a cross-platform RAT to affected machines.
Affected: `[email protected]` and `[email protected]` 👇🧵
@karpathy The LiteLLM dependency incident didn't "just happen" though. This is part of a larger campaign
LiteLLM already extends to supply chain security fallout for other projects: https://t.co/7bL3kNHP15
Today, we’re excited to announce Snyk Agent Security and the general availability of Snyk Evo AI-SPM. 🚀
You cannot slow down AI coding agents, but you cannot let them bypass your security stack either. It’s a shadow AI crisis. 👾
See the fix here : https://t.co/Pq2fa0igMJ
if you're building CLI apps in Node.js then you probably want to install my Node.js command line apps best practices
Use Tessl skills manager:
$ npx tessl i lirantal/nodejs-cli-best-practices
Are you attending RSA? Good news: we've got your itinerary sorted ✅
From rooftop cocktails to chats with Team USA soccer legends, we’ve built a roster of can’t-miss events, hands-on trainings, and VIP experiences ⚽️
Stay tuned for more details to come!
“The best security uses both AI and deterministic analysis” << this is the key takeaway. Security has always been about layering 🔒 AI can add security (and insecurity!) layers throughout the SDLC.
The market says Anthropic just ate the security industry’s lunch 🫠
The reality? Finding bugs is the easy part. Fixing them at scale without breaking your entire stack is the real challenge.
Here’s what Claude Code Security actually means for AppSec: https://t.co/qXhH5pBXOJ
Agents introduced a new supply chain: skills with privileges.
@snyksec research: ~4k public skills, over a third had security issues
Blog + research:
https://t.co/FkA0wxDycQ
Curious — are teams allowing skills or blocking them?
We’re thrilled to announce our partnership with Cline, bridging the gap between autonomous speed and security.
You can now maximize the efficiency gains of AI coding without compromising trust 💥
Are you ready to Fetch the Flag in February 2026 ?
@NahamSec and Snyk are partnering for a capture the flag event for all hackers out there, register here: https://t.co/AGJWiofodZ