S/o to the ~good~ KEVs 👋
And for the bad ones, Chainguard will remediate them within 24-hours — the only one in the industry with this SLA.
We’ll worry about the bad ones, so you can enjoy the good ones 😁
Over the past 6 days, a threat actor compromised four npm accounts (mr.4nd3r50n, pik-libs, t-in-one, emcd-vue), publishing 180+ malicious npm packages targeting financial and cloud infrastructure. Chainguard customers were not affected.
Get the details: https://t.co/3ekt4X3nrQ
Chainguard customers are unaffected by today’s wave of Mini Shai-Hulud, which impacts 32 redhat-cloud-services projects and 90+ versions.
Get the details: https://t.co/e4efgThHjm
Assemble New York sold out. Now we're taking it to London! 🇬🇧
Join us in October to hear from the security + engineering leaders defining secure development, catch the latest product announcements, and get hands-on with workshops.
Save your spot ➡️ https://t.co/wtVwEeutCR
Helloooo, New York City! 🗽
Last night we celebrated the opening of our first office with the people who make this work: customers, partners, and the very best team.
We can't wait to see what we build here! Join us: https://t.co/C9tTNgkrsG
Thrilled to be recognized in @Redpoint's 2026 InfraRed 100 list, highlighting 100 of the most promising private companies in AI infrastructure.
Congratulations to all the companies featured this year!
AI models like Mythos can find hundreds of vulnerabilities overnight — across thousands of projects with one maintainer and no obligation to patch anything. We're not ready for that.
More on the hardest fork yet: https://t.co/8f7yut6sDk
@upwindsecurity now scans Chainguard Libraries for Python, so resolving a CVE in Flask or Django actually quiets your scanner, not just your to-do list.
Learn more about our new partnership: https://t.co/gzexjR0xFG
Chainguard Containers are unaffected by an attack on the Laravel Lang PHP project. Attackers injected credential harvesting malware into 700 versions across four projects overnight. Learn more: https://t.co/AycwWrWQeg
How to not get pwnd in 2026, an acrostic ✍
P - Proactively minimize your attack surface
W - Write off public registries as safe source
N - Never assume a clean CVE scan means you're safe
D - Do use Chainguard, the trusted source for open source
314 npm packages compromised in 22 minutes this morning. echarts-for-react, timeago.js, the entire AntV suite.
Chainguard customers were not affected.
Full breakdown + IOCs: https://t.co/QZyWN7ZrY8
🚀 New integration: Chainguard + @EndorLabs
Together, we replace the patching treadmill with a verified chain of trust from build to runtime.
Check out our new partnership here: https://t.co/S2Bv1xTC7Z
node-ipc was compromised today. 3 malicious versions hit npm targeting 500k+ weekly downloads.
The payload steals AWS, GCP, Azure, SSH, kubeconfig, GitHub tokens, and AI API keys.
Chainguard customers were not affected. Details here: https://t.co/jJGWHdHXL5
Mini Shai-Hulud: attackers exploited pull_request_target workflows in TanStack's GitHub repo to inject malware into 84 versions across 42 packages, all with the same provenance as legitimate releases. Chainguard customers were not impacted: https://t.co/62FxyyVcUz
Linky's Top 5 Horror Movies 🐙 😱
1. "We'll fix it in the next sprint"
2. The image with 847 CVEs running in prod
3. The dependency that hasn't been maintained since 2019
4. AI agents running wild without Chainguard
5. Scan and patch security
Chainguard Containers now supports 1st Party RPM compatibility for RHEL 9 and RHEL 10, and we're joining FINOS 🎉
Here's what it means for financial services: https://t.co/BIGDsLRW2j