Skip to main content

New: Announcing our Series A funding

Resources

All resources

Advisory

Technical Advisory: TeamPCP Supply Chain Campaign

A threat actor compromised the Trivy vulnerability scanner and used stolen CI/CD secrets to cascade into Checkmarx, LiteLLM, and 50+ npm packages.

Giuseppe Trovato
Advisory

Technical Advisory: n8n Unauthenticated Remote Code Execution (Ni8mare)

Critical unauthenticated remote code execution vulnerability in n8n workflow automation allows attackers to exploit content-type confusion in Form webhook file upload processing to read arbitrary files, steal credentials, and execute arbitrary code on the server.

Giuseppe Trovato
Advisory

Technical Advisory: n8n Remote Code Execution via Expression Injection

Critical remote code execution vulnerability in n8n workflow automation platform allows authenticated users to execute arbitrary code on the server through specially crafted workflow expressions that escape the sandbox isolation.

Giuseppe Trovato
Blog

Governing AI Agents: Best Practices to Scale Safely

Building on research from Berkeley, this article outlines five barriers to enterprise AI adoption and the AI governance best practices to overcome them with visibility and accountability.

Hanah Darley