# devrel

Published articles for devrel.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## От рабочего опыта к публичной экспертизе в эпоху AI

DevFeed: [От рабочего опыта к публичной экспертизе в эпоху AI](<https://devfeed.tech/articles/ai-40880.md>)

Original publisher: [Read original article](<https://habr.com/ru/companies/garage8/news/1083018/>)

Author: GarageEight (Garage Eight)

Published: 2026-09-16T13:41:35Z

Content type: news

Language: ru

Sources: [Tagir Valeev](<https://devfeed.tech/sources/tagir-valeev.md>)

Topics: [devrel](<https://devfeed.tech/topics/devrel.md>), [developer-relations](<https://devfeed.tech/topics/developer-relations.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [developer-relations](<https://devfeed.tech/tags/developer-relations.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [tag-15a71fee6e18](<https://devfeed.tech/tags/tag-15a71fee6e18.md>), [tag-32c09290faee](<https://devfeed.tech/tags/tag-32c09290faee.md>), [tag-86b843454893](<https://devfeed.tech/tags/tag-86b843454893.md>)

### AI overview

A webinar hosted by Katya Yaradaykina of Garage Eight will discuss how IT and digital professionals can turn workplace cases, experiments, mistakes, and solutions into talks, articles, or posts. It will also cover using AI to develop ideas and prepare materials while preserving personal expertise and voice.

### Source excerpt

У многих за плечами кейсы, эксперименты, ошибки и найденные решения -- но публично о них почти никто не рассказывает. 17 сентября в 18:30 МСК Катя Ярадайкина, DevRel Garage Eight, проведёт вебинар "От рабочего опыта к публичной экспертизе в эпоху AI" в комьюнити Women in Tech Russia. О мероприятии и ссылка для подключения

## DevRel Field Notes: Build Review Into the Work

DevFeed: [DevRel Field Notes: Build Review Into the Work](<https://devfeed.tech/articles/devrel-field-notes-build-review-into-the-work-39047.md>)

Original publisher: [Read original article](<https://www.michaelcrump.net/posts/devrel-field-notes-build-review-into-the-work/>)

Published: 2026-09-15T00:44:32Z

Content type: opinion

Language: en

Sources: [Michael Crump](<https://devfeed.tech/sources/michael-crump.md>)

Topics: [devrel](<https://devfeed.tech/topics/devrel.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [Google](<https://devfeed.tech/topics/google.md>)

Tags: [coaching](<https://devfeed.tech/tags/coaching.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [evaluation](<https://devfeed.tech/tags/evaluation.md>), [live-stream](<https://devfeed.tech/tags/live-stream.md>), [reporting](<https://devfeed.tech/tags/reporting.md>), [review](<https://devfeed.tech/tags/review.md>)

### AI overview

This DevRel field note argues that rehearsal, behavioral evaluation, and honest reporting should be integrated throughout content production rather than left as final checks. Drawing on creator livestream rehearsal and Google's discussion of behavioral evaluations, it presents these practices as ways to improve tutorial, demo, and live-content quality while acknowledging that the examples do not establish a measured industry trend.

### Source excerpt

What creator rehearsal, behavioral evaluation, and transparent reporting suggest about making DevRel content more trustworthy.

## DevRel Field Notes: Help Developers Decide What to Do Next

DevFeed: [DevRel Field Notes: Help Developers Decide What to Do Next](<https://devfeed.tech/articles/devrel-field-notes-help-developers-decide-what-to-do-next-39048.md>)

Original publisher: [Read original article](<https://www.michaelcrump.net/posts/devrel-field-notes-help-developers-decide/>)

Published: 2026-09-04T17:59:24Z

Content type: opinion

Language: en

Sources: [Michael Crump](<https://devfeed.tech/sources/michael-crump.md>)

Topics: [devrel](<https://devfeed.tech/topics/devrel.md>), [GitHub Copilot app](<https://devfeed.tech/topics/github-copilot-app.md>), [Tutorial](<https://devfeed.tech/topics/tutorial.md>), [Accessibility](<https://devfeed.tech/topics/accessibility.md>)

Tags: [accessibility](<https://devfeed.tech/tags/accessibility.md>), [article](<https://devfeed.tech/tags/article.md>), [developers](<https://devfeed.tech/tags/developers.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [github-copilot-app](<https://devfeed.tech/tags/github-copilot-app.md>), [tutorial](<https://devfeed.tech/tags/tutorial.md>)

### AI overview

This DevRel commentary examines a newsletter, a beginner tutorial, and a developer community story as examples of content that helps developers decide what to do next. It emphasizes explaining limitations, giving readers a manageable next step, and coaching creators to make useful editorial choices.

### Source excerpt

What this week's developer newsletter, tutorial, and community storytelling examples suggest about running a useful DevRel content program.

## An insider argues that Google remains committed to Flutter and Dart

DevFeed: [An insider argues that Google remains committed to Flutter and Dart](<https://devfeed.tech/articles/i-ve-been-a-flutter-gde-for-8-years-here-s-the-ground-truth-on-flutter-is-dying-23052.md>)

Original publisher: [Read original article](<https://medium.com/flutter-community/ive-been-a-flutter-gde-for-8-years-here-s-the-ground-truth-on-flutter-is-dying-6ffc50ca4088?source=rss----86fb29d7cc6a---4>)

Author: Randal L. Schwartz

Published: 2026-08-19T16:02:19Z

Content type: opinion

Language: en

Sources: [Flutter Community - Medium](<https://devfeed.tech/sources/flutter-community-medium.md>)

Topics: [Flutter](<https://devfeed.tech/topics/flutter.md>), [Dart](<https://devfeed.tech/topics/dart.md>), [Google](<https://devfeed.tech/topics/google.md>), [multiplatform](<https://devfeed.tech/topics/multiplatform.md>), [WebAssembly](<https://devfeed.tech/topics/web-assembly.md>)

Tags: [cross-platform](<https://devfeed.tech/tags/cross-platform.md>), [dart](<https://devfeed.tech/tags/dart.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [flutter](<https://devfeed.tech/tags/flutter.md>), [google](<https://devfeed.tech/tags/google.md>), [mobile-app-development](<https://devfeed.tech/tags/mobile-app-development.md>), [programming](<https://devfeed.tech/tags/programming.md>), [software-development](<https://devfeed.tech/tags/software-development.md>), [wasm](<https://devfeed.tech/tags/wasm.md>), [webassembly](<https://devfeed.tech/tags/webassembly.md>)

### AI overview

This commentary argues, from the author's stated experience as a Flutter Google Developer Expert, that Google remains committed to Flutter and Dart despite restructuring-related concerns and reduced public communication. It cites renewed advocacy and investment in rendering, Dart ergonomics, WebAssembly compilation, and multiplatform performance.

### Source excerpt

Every few months, like clockwork, the tech blogosphere gets flooded with the same recycled headline: "Is Flutter Dying?", "Why CTOs Are Quietly Leaving Flutter", or "Why Google is Killing Its Cross-Platform Bet." As someone who has been a Flutter Google Developer Expert for eight years now -- literally from day one of the GDE program -- and a five-decade software industry veteran, I usually just chuckle at the clickbait. "Flutter is dead." -- Said every six months since 2018. Meanwhile: Flutter is kicking tail on every single measurable scale. The alarmist articles point to standard corporate reorganizations, shifting tech job boards, and "state management fatigue" as evidence of Flutter's demise. But having watched this ecosystem evolve from an experimental alpha into an enterprise powerhouse, the reality on the ground is the exact opposite. Here is the real insider story on what's actually happening with Dart and Flutter. 1. The Inside Story: What Happened at Google? When tech companies restructured engineering teams recently, the internet spun a wild narrative that "Google put Flutter on life support." Having direct access to internal teams, I watched the commitment to Dart and Flutter remain steadfast within the organization. However, there was a temporary disconnect: internal engineering activity was roaring, but external communications and public advocacy had slowed down, leaving an information vacuum that clickbait writers eagerly filled. I personally called out to team leaders and senior VPs that this perception gap needed immediate correction. And the leadership responded strongly: Revitalized DevRel & Advocacy: A renewed surge in active community engagement, tutorials, and public roadmaps. Enterprise Adoption Transparency: Showcasing massive internal and external production milestones. Aggressive Core Investment: Deep work on the Impeller rendering engine, Dart 3.x ergonomics, WebAssembly (Wasm) compilation, and native multiplatform performance. Flutter is no

## Elastic community newsletter -- August 2026

DevFeed: [Elastic community newsletter -- August 2026](<https://devfeed.tech/articles/elastic-community-newsletter-august-2026-4798.md>)

Original publisher: [Read original article](<https://www.elastic.co/blog/devrel-newsletter-august-2026>)

Author: Elastic DevRel team

Published: 2026-08-13T00:00:00Z

Content type: news

Language: en

Sources: [Elastic Blog - Elasticsearch, Kibana, and ELK Stack](<https://devfeed.tech/sources/elastic-blog-elasticsearch-kibana-and-elk-stack.md>)

Topics: [elasticsearch](<https://devfeed.tech/topics/elasticsearch.md>), [devrel](<https://devfeed.tech/topics/devrel.md>), [dashboards](<https://devfeed.tech/topics/dashboards.md>), [Embeddings](<https://devfeed.tech/topics/embeddings.md>), [multimodal](<https://devfeed.tech/topics/multimodal.md>), [quantization](<https://devfeed.tech/topics/quantization.md>), [AI search](<https://devfeed.tech/topics/ai-search.md>), [tracing](<https://devfeed.tech/topics/tracing.md>)

Tags: [audio](<https://devfeed.tech/tags/audio.md>), [dashboards](<https://devfeed.tech/tags/dashboards.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [elasticsearch](<https://devfeed.tech/tags/elasticsearch.md>), [embeddings](<https://devfeed.tech/tags/embeddings.md>), [images](<https://devfeed.tech/tags/images.md>), [multimodal](<https://devfeed.tech/tags/multimodal.md>), [pdf](<https://devfeed.tech/tags/pdf.md>), [quantization](<https://devfeed.tech/tags/quantization.md>), [tracing](<https://devfeed.tech/tags/tracing.md>), [video](<https://devfeed.tech/tags/video.md>)

### AI overview

The Elastic community newsletter covers Elasticsearch 9.5, including native PromQL, the Dashboards API, Columnar Mode, vector search improvements, multimodal semantic search, and Elastic Agent Builder tracing in technical preview.

### Source excerpt

In this newsletter, we cover version 9.5 of Elasticsearch, the latest blogs and videos, and upcoming events.

## A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope

DevFeed: [A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope](<https://devfeed.tech/articles/a-forgotten-contributor-account-compromised-the-entire-mastra-npm-package-scope-7788.md>)

Original publisher: [Read original article](<https://snyk.io/blog/a-forgotten-contributor-account-compromised-the-entire-mastra-npm-package-scope/>)

Author: Liran Tal; Marian Corneci

Published: 2026-06-16T21:00:00Z

Content type: news

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [incident](<https://devfeed.tech/topics/incident.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cross-platform](<https://devfeed.tech/tags/cross-platform.md>), [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [incident](<https://devfeed.tech/tags/incident.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [payload](<https://devfeed.tech/tags/payload.md>), [persistence](<https://devfeed.tech/tags/persistence.md>), [remote-access-trojan](<https://devfeed.tech/tags/remote-access-trojan.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [scm](<https://devfeed.tech/tags/scm.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [tech](<https://devfeed.tech/tags/tech.md>), [tls](<https://devfeed.tech/tags/tls.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>)

### AI overview

A dormant former-contributor npm account was compromised and used to republish the Mastra package scope with a malicious dependency that installs cryptocurrency-stealing malware and a persistent remote-access trojan. The article describes the stale access control that enabled the supply-chain incident and advises treating affected installations as credential and wallet exposure events.

### Source excerpt

A dormant contributor account was used to republish the entire @mastra npm scope, each injected with a single dependency, easy-day-js, that drops a cross-platform cryptocurrency stealer. Here is how the attack worked, how to check exposure, and how to remediate.

## When a Government Pulls an AI Model: What the Fable 5 and Mythos 5 Suspension Means for Security Teams

DevFeed: [When a Government Pulls an AI Model: What the Fable 5 and Mythos 5 Suspension Means for Security Teams](<https://devfeed.tech/articles/when-a-government-pulls-an-ai-model-what-the-fable-5-and-mythos-5-suspension-means-for-security-teams-7914.md>)

Original publisher: [Read original article](<https://snyk.io/blog/fable-mythos-suspension-security-takeaways/>)

Author: Stephen Thoemmes

Published: 2026-06-14T13:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [anthropic](<https://devfeed.tech/topics/anthropic.md>), [Claude](<https://devfeed.tech/topics/claude.md>), [Frontier Model](<https://devfeed.tech/topics/frontier-model.md>), [Jailbreak](<https://devfeed.tech/topics/jailbreak.md>), [Code](<https://devfeed.tech/topics/code.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [anthropic](<https://devfeed.tech/tags/anthropic.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [claude](<https://devfeed.tech/tags/claude.md>), [code](<https://devfeed.tech/tags/code.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [frontier-model](<https://devfeed.tech/tags/frontier-model.md>), [jailbreak](<https://devfeed.tech/tags/jailbreak.md>), [policy](<https://devfeed.tech/tags/policy.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [us](<https://devfeed.tech/tags/us.md>)

### AI overview

The article examines Anthropic's worldwide suspension of Claude Fable 5 and Mythos 5 after a US export-control directive concerning foreign-national access and a reported narrow jailbreak involving code analysis. It discusses the distinction between the directive's scope and the blanket shutdown, and considers the implications for security teams that depend on external frontier models.

### Source excerpt

On June 12, 2026, a US export-control directive led Anthropic to disable Claude Fable 5 and Mythos 5 worldwide over a reported jailbreak. The reported trigger was a code-analysis capability that defenders use routinely. Here is what happened, how the security community read it, and what security teams can take from it.

## Laravel Lang Supply Chain Advisory

DevFeed: [Laravel Lang Supply Chain Advisory](<https://devfeed.tech/articles/laravel-lang-supply-chain-advisory-7997.md>)

Original publisher: [Read original article](<https://snyk.io/blog/laravel-lang-supply-chain-advisory/>)

Author: Brian Clark

Published: 2026-05-23T16:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Laravel](<https://devfeed.tech/topics/laravel.md>), [Composer](<https://devfeed.tech/topics/composer.md>), [Credential theft](<https://devfeed.tech/topics/credential-theft.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [PHP](<https://devfeed.tech/topics/php.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [ssh](<https://devfeed.tech/topics/ssh.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [article](<https://devfeed.tech/tags/article.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [code](<https://devfeed.tech/tags/code.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [github](<https://devfeed.tech/tags/github.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [laravel](<https://devfeed.tech/tags/laravel.md>), [php](<https://devfeed.tech/tags/php.md>), [scm](<https://devfeed.tech/tags/scm.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [security-labs](<https://devfeed.tech/tags/security-labs.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-security-intel](<https://devfeed.tech/tags/snyk-security-intel.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [tech](<https://devfeed.tech/tags/tech.md>), [tokens](<https://devfeed.tech/tags/tokens.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>)

### AI overview

The article examines a Laravel Lang supply-chain attack in which hundreds of historical Packagist releases for four community-maintained Laravel localization libraries were republished with malicious code. The injected Composer hook executes on PHP requests, downloads a second stage, and runs a credential stealer targeting cloud keys, Kubernetes and Vault secrets, CI/CD tokens, SSH material, environment files, browser data, password-manager vaults, crypto wallets, and messaging tokens.

### Source excerpt

Hundreds of historical Laravel Lang Packagist releases were republished with malicious code, putting Composer installs at risk of credential theft and secret exfiltration.

## Mini Shai-Hulud Hits AntV: 300+ Malicious npm Packages Published via Compromised Maintainer Account

DevFeed: [Mini Shai-Hulud Hits AntV: 300+ Malicious npm Packages Published via Compromised Maintainer Account](<https://devfeed.tech/articles/mini-shai-hulud-hits-antv-300-malicious-npm-packages-published-via-compromised-maintainer-account-8015.md>)

Original publisher: [Read original article](<https://snyk.io/blog/mini-shai-hulud-antv-npm-supply-chain-attack/>)

Author: Liran Tal

Published: 2026-05-18T23:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Data visualization](<https://devfeed.tech/topics/data-visualization.md>), [npm packages](<https://devfeed.tech/topics/npm-packages.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [npm](<https://devfeed.tech/topics/npm.md>), [C2](<https://devfeed.tech/topics/c2.md>), [Bun](<https://devfeed.tech/topics/bun.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [c2](<https://devfeed.tech/tags/c2.md>), [data-visualization](<https://devfeed.tech/tags/data-visualization.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [malware](<https://devfeed.tech/tags/malware.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [payload](<https://devfeed.tech/tags/payload.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [teampcp](<https://devfeed.tech/tags/teampcp.md>), [tokens](<https://devfeed.tech/tags/tokens.md>)

### AI overview

This article analyzes the Mini Shai-Hulud supply-chain attack targeting the AntV data visualization ecosystem through a compromised npm maintainer account. It describes the mass publication of malicious package versions, the embedded Bun payload, credential and secret theft, C2 persistence, and self-propagation using stolen npm tokens.

### Source excerpt

A compromised npm maintainer account triggered an automated burst of over 300 malicious package versions across 323 packages in the AntV data visualization ecosystem, part of the ongoing Mini Shai-Hulud supply chain worm campaign. Here's what the malware does, how to detect exposure, and how to respond.

## Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers

DevFeed: [Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers](<https://devfeed.tech/articles/malicious-release-of-elementary-data-pypi-package-steals-cloud-credentials-from-data-engineers-8011.md>)

Original publisher: [Read original article](<https://snyk.io/blog/malicious-release-of-elementary-data-pypi-package-steals-cloud-credentials-from-data-engineers/>)

Author: Liran Tal

Published: 2026-04-27T23:00:00Z

Content type: news

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [data observability](<https://devfeed.tech/topics/data-observability.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>), [Python](<https://devfeed.tech/topics/python.md>), [data-engineering](<https://devfeed.tech/topics/data-engineering.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [ssh](<https://devfeed.tech/topics/ssh.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [aws](<https://devfeed.tech/tags/aws.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [blog](<https://devfeed.tech/tags/blog.md>), [data-engineering](<https://devfeed.tech/tags/data-engineering.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [docker](<https://devfeed.tech/tags/docker.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [python](<https://devfeed.tech/tags/python.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Attackers compromised the elementary-data Python package's GitHub Actions publication pipeline through script injection and released malicious content that stole cloud credentials and SSH secrets from data engineering environments.

### Source excerpt

Attackers exploited a GitHub Actions script injection vulnerability to publish a malicious version of the elementary-data Python CLI (v0.23.3), embedding a credential-stealing backdoor that targeted dbt profiles, cloud provider keys, and SSH secrets from data engineering environments.

## Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT

DevFeed: [Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT](<https://devfeed.tech/articles/axios-npm-package-compromised-supply-chain-attack-delivers-cross-platform-rat-7839.md>)

Original publisher: [Read original article](<https://snyk.io/blog/axios-npm-package-compromised-supply-chain-attack-delivers-cross-platform/>)

Author: Liran Tal

Published: 2026-03-30T23:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [npm](<https://devfeed.tech/topics/npm.md>), [StreamRAT](<https://devfeed.tech/topics/streamrat.md>), [cross-platform](<https://devfeed.tech/topics/cross-platform.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [ide](<https://devfeed.tech/topics/ide.md>), [client](<https://devfeed.tech/topics/client.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [c2](<https://devfeed.tech/tags/c2.md>), [ci](<https://devfeed.tech/tags/ci.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [code](<https://devfeed.tech/tags/code.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [github](<https://devfeed.tech/tags/github.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [macos](<https://devfeed.tech/tags/macos.md>), [malware](<https://devfeed.tech/tags/malware.md>), [obfuscation](<https://devfeed.tech/tags/obfuscation.md>), [payload](<https://devfeed.tech/tags/payload.md>), [remote-access-trojan](<https://devfeed.tech/tags/remote-access-trojan.md>), [security](<https://devfeed.tech/tags/security.md>), [server](<https://devfeed.tech/tags/server.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

The article analyzes a supply-chain attack in which malicious Axios versions published to npm through a compromised maintainer account introduced a hidden dependency. Installing the affected packages could trigger a postinstall dropper that downloaded a platform-specific remote access trojan, contacted a command-and-control server, and erased evidence after execution.

### Source excerpt

Meta description: Malicious versions of the Axios npm package (1.14.1 and 0.30.4) were published via a compromised maintainer account, injecting a hidden dependency that deploys a cross-platform remote access trojan. Here's what happened, who's affected, and how to check your exposure.

## The 89% Problem: How LLMs Are Resurrecting the "Dormant Majority" of Open Source

DevFeed: [The 89% Problem: How LLMs Are Resurrecting the "Dormant Majority" of Open Source](<https://devfeed.tech/articles/the-89-problem-how-llms-are-resurrecting-the-dormant-majority-of-open-source-8005.md>)

Original publisher: [Read original article](<https://snyk.io/blog/llms-resurrecting-open-source-dormant-majority/>)

Author: Noa Yaffe-Ermoza; Liran Tal; Ezra Tanzer

Published: 2026-03-04T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Large Language Model](<https://devfeed.tech/topics/llm.md>), [ai-coding](<https://devfeed.tech/topics/ai-coding.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Generative AI](<https://devfeed.tech/topics/generative-ai.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-coding](<https://devfeed.tech/tags/ai-coding.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [coding](<https://devfeed.tech/tags/coding.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [generative-ai](<https://devfeed.tech/tags/generative-ai.md>), [interest](<https://devfeed.tech/tags/interest.md>), [llms](<https://devfeed.tech/tags/llms.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [python](<https://devfeed.tech/tags/python.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

The article examines how LLM-powered coding assistants can revive abandoned and obscure open source packages by selecting them from patterns in broad training data rather than relying on popularity or maintenance signals. It argues that package health intelligence is important for identifying supply chain security risks in the open source ecosystem.

### Source excerpt

AI coding assistants are resurrecting millions of abandoned open source packages. Learn how LLMs expose the "Dormant Majority" and why package health intelligence is critical for supply chain security.

## Snyk and uv, Better Together

DevFeed: [Snyk and uv, Better Together](<https://devfeed.tech/articles/snyk-and-uv-better-together-8177.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-uv-partnership/>)

Author: Ryan Searle

Published: 2026-02-24T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Package Management](<https://devfeed.tech/topics/package-management.md>), [Python](<https://devfeed.tech/topics/python.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [JSON](<https://devfeed.tech/topics/json.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [toolchain](<https://devfeed.tech/topics/toolchain.md>), [pip](<https://devfeed.tech/topics/pip.md>), [Poetry](<https://devfeed.tech/topics/poetry.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-development](<https://devfeed.tech/tags/ai-development.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [developer](<https://devfeed.tech/tags/developer.md>), [development](<https://devfeed.tech/tags/development.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [enablement](<https://devfeed.tech/tags/enablement.md>), [executive](<https://devfeed.tech/tags/executive.md>), [github](<https://devfeed.tech/tags/github.md>), [interest](<https://devfeed.tech/tags/interest.md>), [json](<https://devfeed.tech/tags/json.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [package-management](<https://devfeed.tech/tags/package-management.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [python](<https://devfeed.tech/tags/python.md>), [related-content](<https://devfeed.tech/tags/related-content.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [toolchain](<https://devfeed.tech/tags/toolchain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Snyk and uv have partnered to combine uv's high-performance Python package management with supply chain security. Their collaboration adds native CycloneDX SBOM export to uv, enabling Snyk vulnerability and license-compliance testing for uv-managed projects.

### Source excerpt

Snyk and uv have teamed up to provide high-performance package management with native security for Python-based AI development. Build, install, and secure your AI-native applications from inception with Snyk's native support for the uv ecosystem.

## The Rise of the AI Security Engineer: A New Discipline for an AI-Native World

DevFeed: [The Rise of the AI Security Engineer: A New Discipline for an AI-Native World](<https://devfeed.tech/articles/the-rise-of-the-ai-security-engineer-a-new-discipline-for-an-ai-native-world-8206.md>)

Original publisher: [Read original article](<https://snyk.io/blog/the-ai-security-engineer/>)

Author: Manoj Nair

Published: 2026-02-24T05:00:00Z

Content type: opinion

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [AI Bots](<https://devfeed.tech/topics/ai-bots.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [agentic-ai](<https://devfeed.tech/tags/agentic-ai.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-engineering](<https://devfeed.tech/tags/ai-engineering.md>), [ai-models](<https://devfeed.tech/tags/ai-models.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [autonomous](<https://devfeed.tech/tags/autonomous.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [executive](<https://devfeed.tech/tags/executive.md>), [inference](<https://devfeed.tech/tags/inference.md>), [interest](<https://devfeed.tech/tags/interest.md>), [llm](<https://devfeed.tech/tags/llm.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article argues that organizations need AI Security Engineers to defend non-deterministic, autonomous AI systems against emerging security threats.

### Source excerpt

As autonomous AI systems transform business, a new profession is emerging to protect them: the AI Security Engineer. Discover why this specialized discipline is becoming a survival imperative for organizations in an AI-native world.

## How "Clinejection" Turned an AI Bot into a Supply Chain Attack

DevFeed: [How "Clinejection" Turned an AI Bot into a Supply Chain Attack](<https://devfeed.tech/articles/how-clinejection-turned-an-ai-bot-into-a-supply-chain-attack-7864.md>)

Original publisher: [Read original article](<https://snyk.io/blog/cline-supply-chain-attack-prompt-injection-github-actions/>)

Author: Stephen Thoemmes

Published: 2026-02-19T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>), [AI Bots](<https://devfeed.tech/topics/ai-bots.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [ci](<https://devfeed.tech/topics/ci.md>), [incident](<https://devfeed.tech/topics/incident.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [ai-assisted-coding](<https://devfeed.tech/tags/ai-assisted-coding.md>), [anthropic](<https://devfeed.tech/tags/anthropic.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [bash](<https://devfeed.tech/tags/bash.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cache](<https://devfeed.tech/tags/cache.md>), [ci](<https://devfeed.tech/tags/ci.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [claude](<https://devfeed.tech/tags/claude.md>), [cli](<https://devfeed.tech/tags/cli.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [incident](<https://devfeed.tech/tags/incident.md>), [interest](<https://devfeed.tech/tags/interest.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [openclaw](<https://devfeed.tech/tags/openclaw.md>), [payload](<https://devfeed.tech/tags/payload.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>)

### AI overview

The article examines Clinejection, a vulnerability chain that used indirect prompt injection, GitHub Actions cache poisoning, and credential weaknesses to turn Cline's AI issue-triage bot into a supply-chain attack vector. An unauthorized Cline CLI version was published to npm and installed OpenClaw globally during an approximately eight-hour window.

### Source excerpt

The Clinejection vulnerability chain illustrates a dangerous new era of supply chain attacks where AI agents are turned into exploit vectors. By combining indirect prompt injection with GitHub Actions cache poisoning, attackers successfully pushed unauthorized code to thousands of developers. This incident highlights the critical need for hardened CI/CD pipelines and rigorous security for AI-assisted coding tools.

## The Future of AI Agent Security Is Guardrails

DevFeed: [The Future of AI Agent Security Is Guardrails](<https://devfeed.tech/articles/the-future-of-ai-agent-security-is-guardrails-7933.md>)

Original publisher: [Read original article](<https://snyk.io/blog/future-of-ai-agent-security-guardrails/>)

Author: Randall Degges

Published: 2026-02-12T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [AI Bots](<https://devfeed.tech/topics/ai-bots.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [enablement](<https://devfeed.tech/tags/enablement.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [interest](<https://devfeed.tech/tags/interest.md>), [java](<https://devfeed.tech/tags/java.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [tool](<https://devfeed.tech/tags/tool.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>)

### AI overview

The article argues that AI agent security needs guardrails that inspect and control tool actions before they occur. It highlights risks including prompt injection, credential exfiltration, and command injection, and discusses Arcade.dev's Contextual Access in an MCP runtime.

### Source excerpt

AI agents introduce new security risks like prompt injection and data exfiltration. Learn how guardrails, hook-based controls, and Arcade's Contextual Access secure AI agent tool calls in real time.

## Why Your "Skill Scanner" Is Just False Security (and Maybe Malware)

DevFeed: [Why Your "Skill Scanner" Is Just False Security (and Maybe Malware)](<https://devfeed.tech/articles/why-your-skill-scanner-is-just-false-security-and-maybe-malware-8103.md>)

Original publisher: [Read original article](<https://snyk.io/blog/skill-scanner-false-security/>)

Author: Liran Tal

Published: 2026-02-11T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Agent Skills](<https://devfeed.tech/topics/agent-skills.md>), [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [Security](<https://devfeed.tech/topics/security.md>), [prompt injection](<https://devfeed.tech/topics/prompt-injection.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Code](<https://devfeed.tech/topics/code.md>), [configuration](<https://devfeed.tech/topics/configuration.md>)

Tags: [agent-skills](<https://devfeed.tech/tags/agent-skills.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [bash](<https://devfeed.tech/tags/bash.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code](<https://devfeed.tech/tags/code.md>), [data](<https://devfeed.tech/tags/data.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [interest](<https://devfeed.tech/tags/interest.md>), [prompt-injection](<https://devfeed.tech/tags/prompt-injection.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>)

### AI overview

The article argues that community AI Skill scanners can create false security because regex and denylist approaches cannot reliably detect malicious intent expressed through natural language, code execution, configuration, and context. It highlights risks including prompt injection, data exfiltration, unvetted code execution, and supply-chain exposure in Agent Skills.

### Source excerpt

Are "Skill Scanners" on ClawHub actually safe? We tested popular community tools like Skill Defender and SkillGuard against real malware. The results were alarming.

## How a Malicious Google Skill on ClawHub Tricks Users Into Installing Malware

DevFeed: [How a Malicious Google Skill on ClawHub Tricks Users Into Installing Malware](<https://devfeed.tech/articles/how-a-malicious-google-skill-on-clawhub-tricks-users-into-installing-malware-7863.md>)

Original publisher: [Read original article](<https://snyk.io/blog/clawhub-malicious-google-skill-openclaw-malware/>)

Author: Liran Tal

Published: 2026-02-10T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [OpenClaw](<https://devfeed.tech/topics/openclaw.md>), [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [Agent Skills](<https://devfeed.tech/topics/agent-skills.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [prompt injection](<https://devfeed.tech/topics/prompt-injection.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [Google](<https://devfeed.tech/topics/google.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [macOS](<https://devfeed.tech/topics/macos.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [agent-skills](<https://devfeed.tech/tags/agent-skills.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [github](<https://devfeed.tech/tags/github.md>), [interest](<https://devfeed.tech/tags/interest.md>), [linux](<https://devfeed.tech/tags/linux.md>), [macos](<https://devfeed.tech/tags/macos.md>), [malware](<https://devfeed.tech/tags/malware.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [openclaw](<https://devfeed.tech/tags/openclaw.md>), [prompt-injection](<https://devfeed.tech/tags/prompt-injection.md>), [security](<https://devfeed.tech/tags/security.md>), [security-labs](<https://devfeed.tech/tags/security-labs.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-security-intel](<https://devfeed.tech/tags/snyk-security-intel.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

Snyk researchers describe an active supply chain attack targeting OpenClaw users through a malicious Google integration skill distributed on ClawHub. The skill uses instructions in SKILL.md to fabricate a prerequisite, persuade users to run an installer, and deploy malware across Windows and macOS/Linux systems.

### Source excerpt

Breaking: Snyk researchers uncover a malicious "Google" skill on ClawHub that tricks users into installing malware via a fake OpenClaw dependency. Learn how the attack works and how to protect your AI agents.

## 280+ Leaky Skills: How OpenClaw & ClawHub Are Exposing API Keys and PII

DevFeed: [280+ Leaky Skills: How OpenClaw & ClawHub Are Exposing API Keys and PII](<https://devfeed.tech/articles/280-leaky-skills-how-openclaw-clawhub-are-exposing-api-keys-and-pii-8040.md>)

Original publisher: [Read original article](<https://snyk.io/blog/openclaw-skills-credential-leaks-research/>)

Author: Luca Beurer-Kellner; Aleksei Kudrinskii; Marco Milanta; Kristian Bonde Nielsen; Hemang Sarkar; Liran Tal

Published: 2026-02-05T18:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Agent Skills](<https://devfeed.tech/topics/agent-skills.md>), [OpenClaw](<https://devfeed.tech/topics/openclaw.md>), [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [API keys](<https://devfeed.tech/topics/api-keys.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [pii](<https://devfeed.tech/topics/pii.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [api-keys](<https://devfeed.tech/tags/api-keys.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [interest](<https://devfeed.tech/tags/interest.md>), [openclaw](<https://devfeed.tech/tags/openclaw.md>), [pii](<https://devfeed.tech/tags/pii.md>), [secrel](<https://devfeed.tech/tags/secrel.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [skills](<https://devfeed.tech/tags/skills.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>)

### AI overview

Snyk reports that 283 of 3,984 skills in the ClawHub marketplace, or 7.1%, contain critical flaws that expose API keys, passwords, credit card numbers, and other sensitive information through LLM context and plaintext logs. The article explains how OpenClaw agent skills can instruct agents to mishandle secrets and describes a credential-leaking email skill as an example.

### Source excerpt

Discover how 7.1% of AI agent skills are designed to leak secrets, PII, and API keys through LLM context. Learn to defend with Evo & mcp-scan.

## ServiceNow's Virtual Agent Vulnerability Shows Why AI Security Needs Traditional AppSec Foundations

DevFeed: [ServiceNow's Virtual Agent Vulnerability Shows Why AI Security Needs Traditional AppSec Foundations](<https://devfeed.tech/articles/servicenow-s-virtual-agent-vulnerability-shows-why-ai-security-needs-traditional-appsec-foundations-8094.md>)

Original publisher: [Read original article](<https://snyk.io/blog/servicenow-virtual-agent-vulnerability/>)

Author: Stephen Thoemmes

Published: 2026-01-14T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [AI Bots](<https://devfeed.tech/topics/ai-bots.md>), [MFA](<https://devfeed.tech/topics/mfa.md>)

Tags: [agentic-ai](<https://devfeed.tech/tags/agentic-ai.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [americas](<https://devfeed.tech/tags/americas.md>), [api](<https://devfeed.tech/tags/api.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [executive](<https://devfeed.tech/tags/executive.md>), [interest](<https://devfeed.tech/tags/interest.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [security-labs](<https://devfeed.tech/tags/security-labs.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>)

### AI overview

A critical ServiceNow Virtual Agent vulnerability illustrates how agentic AI can amplify traditional application-security failures. The reported takeover chain involved hardcoded API credentials, weak identity verification, and excessive privileges, underscoring the importance of authentication and authorization controls.

### Source excerpt

The critical ServiceNow Virtual Agent vulnerability highlights a vital lesson: securing agentic AI requires a return to traditional AppSec foundations. While AI can amplify risks, the root causes often stem from classic failures in authentication and authorization.

## Ways in which GenAI has changed my (tech) life so far

DevFeed: [Ways in which GenAI has changed my (tech) life so far](<https://devfeed.tech/articles/ways-in-which-genai-has-changed-my-tech-life-so-far-38834.md>)

Original publisher: [Read original article](<https://lengrand.fr/ways-in-which-genai-has-changed-my-tech-life-so-far/>)

Author: Julien

Published: 2025-12-07T11:35:32Z

Content type: opinion

Language: en

Sources: [Thoughts, stories and ideas.](<https://devfeed.tech/sources/thoughts-stories-and-ideas.md>)

Topics: [genai](<https://devfeed.tech/topics/genai.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [blogging](<https://devfeed.tech/tags/blogging.md>), [communities](<https://devfeed.tech/tags/communities.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [genai](<https://devfeed.tech/tags/genai.md>), [llms](<https://devfeed.tech/tags/llms.md>), [tech](<https://devfeed.tech/tags/tech.md>)

### AI overview

The author reflects on how generative AI has affected their technology work and online information habits. They argue that AI-generated content has made quality technical material harder to find, increased low-quality and inaccurate social media content, and encouraged people to rely more on specialized communities and documentation.

### Source excerpt

GenAI changed everything: harder to find quality content, social media flooded with bots, lost communities. But maybe it's making us more human again? #GenAI #TechCommunity

## Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)

DevFeed: [Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)](<https://devfeed.tech/articles/security-advisory-critical-rce-vulnerabilities-in-react-server-components-cve-2025-55182-8087.md>)

Original publisher: [Read original article](<https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/>)

Author: Stephen Thoemmes

Published: 2025-12-03T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [React](<https://devfeed.tech/topics/react.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Next.js](<https://devfeed.tech/topics/next-js.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Security](<https://devfeed.tech/topics/security.md>), [Flight](<https://devfeed.tech/topics/flight.md>), [HTTP](<https://devfeed.tech/topics/http.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cloud-security](<https://devfeed.tech/tags/cloud-security.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [cve](<https://devfeed.tech/tags/cve.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [docker](<https://devfeed.tech/tags/docker.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [http](<https://devfeed.tech/tags/http.md>), [incident](<https://devfeed.tech/tags/incident.md>), [next-js](<https://devfeed.tech/tags/next-js.md>), [react](<https://devfeed.tech/tags/react.md>), [remote](<https://devfeed.tech/tags/remote.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [security](<https://devfeed.tech/tags/security.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>)

### AI overview

The article reports critical unauthenticated remote code execution vulnerabilities in React Server Components and Next.js caused by unsafe deserialization of attacker-controlled data in the RSC "Flight" protocol. It explains that default configurations were exploitable, identifies affected React and Next.js releases and other tools embedding RSC, and urges immediate patching.

### Source excerpt

Critical RCE vulnerabilities (CVE-2025-55182/CVE-2025-66478) were found in React Server Components and Next.js via unsafe deserialization. Immediate upgrade to patched versions is mandatory to prevent unauthenticated remote code execution. Learn how to detect and mitigate the critical flaw.

## Run AutoMCP To Supercharge Your AI Agent with Libraries MCP Servers

DevFeed: [Run AutoMCP To Supercharge Your AI Agent with Libraries MCP Servers](<https://devfeed.tech/articles/run-automcp-to-supercharge-your-ai-agent-with-libraries-mcp-servers-8070.md>)

Original publisher: [Read original article](<https://snyk.io/blog/run-automcp-libraries-mcp-servers/>)

Author: Liran Tal

Published: 2025-12-03T05:00:00Z

Content type: tutorial

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [MSP MCP](<https://devfeed.tech/topics/msp-mcp.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [cursor](<https://devfeed.tech/topics/cursor.md>), [Node.js](<https://devfeed.tech/topics/node-js.md>)

Tags: [agentic-coding](<https://devfeed.tech/tags/agentic-coding.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [mcp-server](<https://devfeed.tech/tags/mcp-server.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [scm](<https://devfeed.tech/tags/scm.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-container](<https://devfeed.tech/tags/snyk-container.md>), [snyk-iac](<https://devfeed.tech/tags/snyk-iac.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [vs-code](<https://devfeed.tech/tags/vs-code.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

A tutorial on using AutoMCP to configure Model Context Protocol servers for AI coding tools, connecting dependency context and Snyk scanning to AI-assisted development.

### Source excerpt

Supercharge your AI agent! Learn how AutoMCP integrates Model Context Protocol (MCP) servers and Snyk Studio for secure, context-aware AI-driven development.

## Snyk Log Sniffer: AI-Powered Audit Log Insights for Security Leaders

DevFeed: [Snyk Log Sniffer: AI-Powered Audit Log Insights for Security Leaders](<https://devfeed.tech/articles/snyk-log-sniffer-ai-powered-audit-log-insights-for-security-leaders-8147.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-log-sniffer/>)

Author: Suganthi Krishnavathi; Rima Chaib; Dylan Havelock

Published: 2025-11-26T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [log management](<https://devfeed.tech/topics/log-management.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Google](<https://devfeed.tech/topics/google.md>), [real-time](<https://devfeed.tech/topics/real-time.md>), [API](<https://devfeed.tech/topics/api.md>), [JSON](<https://devfeed.tech/topics/json.md>), [incident](<https://devfeed.tech/topics/incident.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [analysis](<https://devfeed.tech/tags/analysis.md>), [api](<https://devfeed.tech/tags/api.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [audit](<https://devfeed.tech/tags/audit.md>), [blog](<https://devfeed.tech/tags/blog.md>), [data](<https://devfeed.tech/tags/data.md>), [developer](<https://devfeed.tech/tags/developer.md>), [developers](<https://devfeed.tech/tags/developers.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [gemini](<https://devfeed.tech/tags/gemini.md>), [google](<https://devfeed.tech/tags/google.md>), [google-gemini](<https://devfeed.tech/tags/google-gemini.md>), [insights](<https://devfeed.tech/tags/insights.md>), [integration](<https://devfeed.tech/tags/integration.md>), [interest](<https://devfeed.tech/tags/interest.md>), [json](<https://devfeed.tech/tags/json.md>), [logs](<https://devfeed.tech/tags/logs.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [operational](<https://devfeed.tech/tags/operational.md>), [root-cause-analysis](<https://devfeed.tech/tags/root-cause-analysis.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Snyk Log Sniffer is an open source solution that uses the Snyk API and Google Gemini to analyze audit logs. It provides real-time monitoring, AI-generated executive summaries, natural-language security insights, intelligent filtering, and support for identifying risks, incidents, compliance issues, and root causes.

### Source excerpt

Introducing Log Sniffer: an innovative open source solution powered by Google Gemini AI that transforms Snyk audit logs into instant, actionable security and engineering intelligence.

[Next page](<https://devfeed.tech/tags/devrel.md?cursor=WyIyMDI1LTExLTI2VDA1OjAwOjAwKzAwOjAwIiwgImFkNGU4NDc0LWU2OGMtNGZlMC05Yjk5LTI0NGYxYjNjNGM1YyJd>)