Latest articles

Application security blog

CVE explainers, code review patterns and practical guidance for people who build and own software.

  1. Security news

    The 2026 Axios attack: why a clean dependency tree cannot clear a build runner

    An evidence-led analysis of the Axios supply-chain compromise: trace package installation, code execution and credential reach before declaring recovery complete.

    Read article