The world Veriom is building toward.
People, tools and software change. What matters should carry forward.
Veriom maps code, cloud and CI/CD, so you’re never left in the dark about what has been built, why it was built that way or whether the next change is safe.
The world Veriom is building toward.
People, tools and software change. What matters should carry forward.
Veriom maps code, cloud and CI/CD, so you’re never left in the dark about what has been built, why it was built that way or whether the next change is safe.
There's something almost nobody in software says out loud.
Some of us inherited our systems from someone who left. More of us built them this year with agents.
Either way, most of us couldn't fully explain what we're running. And we keep building on top of it anyway.
There's something almost nobody in software says out loud.
Some of us inherited our systems from someone who left. More of us built them this year with agents.
Either way, most of us couldn't fully explain what we're running. And we keep building on top of it anyway.
If you’re not being proactive with your applications security are you truly secure?
There’s a difference between securing your architecture and patching vulnerabilities, and it’s time we start talking about it more.
Patching what’s already broken isn’t the same as securing the system before it breaks.
And now AI is repeating the same structural flaws faster than any scanner can catch them.
We don’t need faster fixes. We need fewer reasons to fix, better control and stronger visibility.
The binary had a second, nastier path it never used.
A ready-made GitHub Actions workflow replacement that dumps all CI secrets via ${{ toJSON(secrets) }} to a build artifact, GitHub’s own infrastructure as the exfiltration channel, zero external C2.
The eBPF rootkit still had debug metadata in it. The operator hardcoded his own wallet recovery phrase into the skip list so the malware wouldn’t rob him.
If you work in repos that used any of the 37 asteroiddao packages, audit your GitHub Actions history for commits from [email protected], dependabot[bot], or renovate[bot] outside their normal context. Git timestamps are forgeable, check the push date in Actions logs, not the commit date.
⚠️ New "IronWorm" supply-chain attack: 30+ npm packages from @ asteroiddao shipped a malicious Rust binary firing on preinstall.
It sweeps 86 env vars + 20 credential files (AWS, GCP, Vault, npm, plus AI keys like Anthropic & OpenAI), hits Exodus wallets, hides behind an eBPF rootkit, and beacons over Tor. Self-propagates via npm Trusted Publishing OIDC, with backdated commits faked as claude/dependabot/renovate.
npm preinstall hooks executing arbitrary code on install isn’t a misconfiguration, it’s a feature. pnpm finally defaulted to blocking lifecycle scripts in v11 this April, npm still defaults to running them.
Until npm changes that default, campaigns like this aren’t incidents to patch through, they’re a permanent fixture of the ecosystem.
Microsoft has identified an active supply chain attack using typosquatted npm packages to steal cloud and CI/CD secrets. On May 28, 2026, a single threat actor operating under newly created maintainer alias vpmdhaj published 14 malicious packages within a 4-hour window. https://t.co/jC3f2m6EBp
The packages typosquat well-known OpenSearch, ElasticSearch, DevOps, and environment-configuration libraries, and several spoof the upstream OpenSearch project’s repository URL in their package.json to appear legitimate.
Once installed, the packages harvest AWS credentials, HashiCorp Vault tokens, and CI/CD pipeline secrets from the host environment. Read the blog from the Microsoft Defender Research team to an in-depth analysis, as well as mitigation, detection, and hunting guidance.
Thinking about putting together a small gathering for engineers and security folks in SF and London.
No agenda. Just builders bringing their real security challenges and talking through them honestly.
Not a panel. Not a pitch. No shame. Just people who get it, in a room together.
Let me know if this sounds useful