Chainguard Blog
RSS FeedLatest updates
- security
Responding to the Five Eyes guidance on AI and cyber risk
Chris Carty, Enterprise Solutions Engineer
- security
AsyncAPI supply chain compromise: npm packages backdoored via GitHub Actions "pwn request" (July 2026)
Quincy Castro, CISO
- security
We're putting our security to the test, and we want your help
Quincy Castro, CISO, and Alex Burrage, Director, Product Security
- security
Summer of Clearinghouses
Dan Lorenc, Co-founder and CEO
- security
@mastra npm scope takeover: 143 packages backdoored via compromised contributor account
Quincy Castro, CISO
- security
Miasma Phantom Gyp npm attack: 57 packages, 286 malicious versions hijack CI/CD pipelines via binding.gyp
Quincy Castro, CISO
- security
Chainguard customers safe from Mini Shai-Hulud worm targeting @redhat-cloud-services npm packages with 100K+ weekly downloads
Quincy Castro, CISO
- security
5 security myths that Mythos ended (as told by a CISO)
Quincy Castro, CISO
- security
Preparing for Mythos: Practical advice for engineering teams
Adrian Mouat, Staff DevRel Engineer
- security
Mini Shai-Hulud npm Attack: AntV Ecosystem Compromise (May 2026)
Mandy Hubbard, Sr. Technical Product Marketing Manager
- security
Canada's CPCSC and Bill C-8 are coming. Here's what you need to do.
Chris Carty, Enterprise Solutions Engineer
- security
Node-ipc compromised: Credential stealer targets package with 500k+ weekly downloads
Quincy Castro, CISO