A look at the human toll of AI-era supply chain attacks like Trivy's breach, and a practical local LLM setup for smarter CVE triage.
Improve software supply chain security with trusted developer identities. Learn how Keycloak and Sigstore work together to bind identity to artifact signatures.
Package age enforcement closes the attack window CVE scanners miss. A practical guide to implementing it across npm, pnpm, Bun, UV, and NuGet.
Explore the OWASP Top 10 for LLMs and learn how to identify, prioritize, and mitigate key AI risks including prompt injection, data leakage and tool misuse.
Explore how security spans across roles, adapts to evolving threats & AI, and how shared ownership builds a security-first organization.