Author
Melissa Bischoping

May 2026 GitHub breach: Extension hygiene is still a challenge–so what can we do about it?
On May 20, 2026, GitHub disclosed that an employee device was compromised through a malicious VS Code extension, with attackers claiming to have exfiltrated roughly 3,800 internal repositories.

Mini Shai-Hulud supply chain attack: Why this campaign changes how defenders should think about trusted software
The Mini Shai-Hulud supply chain attack compromised more than 170 packages across npm and PyPI, including packages from TanStack, Mistral AI, and Guardrails AI, by hijacking legitimate CI/CD publishing workflows to distribute malicious versions that still carried apparently valid provenance signals.

How smart governance can contain agentic sprawl
As AI agents multiply at machine speed across the enterprise, governance must evolve to match their autonomy, scale, and risk.

Understanding shadow AI in your endpoint environment
Learn how shadow AI appears on endpoints, from local models to MCP servers, and why visibility, governance, and secure configuration matter now.

IDE extensions: a new persistent risk to your organization
User-installable extensions for Visual Studio Code, Cursor, and other Integrated Development Environments are an increasingly exploited attack vector, with new malicious extensions discovered almost weekly. Do you have visibility and control?

7 Ways to Defend Your Software Supply Chain
As hackers get more sophisticated and software more complex, CISOs must improve their ability to identify, isolate, and mitigate malicious software attacks.

Develop a Cybersecurity Action Plan: Understanding IT Risk Management
Part two in this series on how to create and deploy an action plan that strengthens your organization’s cyber defenses.

Develop a Cybersecurity Action Plan: Focusing on Visibility and Breaking Down Silos
A cybersecurity action plan that prioritizes visibility and breaks down IT silos is essential for protecting your organization.

Endpoint hardening and preparedness in a changing threat landscape
With the conflict between Russia and Ukraine impacting the cyber threat landscape, organizations must close any gaps in patching workflows.

Best Practices for Responding to the Log4j Vulnerability and Preparing for the Next
Learn how to respond to the Log4j vulnerability and prepare for the future with tools for detecting vulnerable software components.