Qwen 3.8 27B and the year the open weights caught up: how a 17GB download started beating the frontier
Inside the Qwen 3.8 27B release: a 27B Apache 2.0 dense multimodal model that runs on one consumer GPU and claims frontier-class coding, and...
8 posts tagged with "Supply Chain".
All postsInside the Qwen 3.8 27B release: a 27B Apache 2.0 dense multimodal model that runs on one consumer GPU and claims frontier-class coding, and...
Inside the July 14, 2026 AsyncAPI supply chain compromise: a pull_request_target pwn-request stole an org token, and the project's own pipel...
Pragma Core's new CI/CD Pipeline Security module detects misconfigurations in your build pipelines across GitHub Actions, GitLab CI, Azure P...
Inside npm v12: GitHub is disabling preinstall/install/postinstall scripts, Git, and remote-URL dependencies by default, killing the install...
Inside Miasma (Shai-Hulud's npm successor): a 157-byte binding.gyp file executes code during npm install with no lifecycle script, compromis...
Inside Megalodon: how threat actor TeamPCP pushed 5,718 malicious commits to 5,561 GitHub repositories in a six-hour window, injecting dorma...
Breakdown of CVE-2026-45321, the TanStack supply chain compromise. An attacker chained a pull_request_target misconfiguration, GitHub Action...
CVE-2026-3854 turned a single git push into RCE on GitHub.com and GitHub Enterprise Server. We break down what happened for executives, then...
Connect your repositories and let AI agents handle continuous scanning, research, and triage.
Choose which categories you are happy to allow. You can change your mind at any time using the Cookie settings link in the footer.