A CVSS 10.0 flaw in a reporting tool that stores the credentials for every warehouse behind it.
Execution moved from install to import. The flag everyone added after the last campaign is still set, and no longer covers anything.
Hidden native binaries executing at install, in a trusted package name. Compiled code is opaque to the review most registries actually perform.
A credential-stealing worm in a major vendor’s npm namespace. The namespace is the trust signal, and it delivered the reviewer’s assumption too.
Install-time credential theft that republishes itself using the rights it steals. Around 1,948 repositories were tied to exfiltration activity.
The most heavily governed system in the organisation, with a dependency path that has no governance attached to it.
Scanner credentials reached 300+ repositories. Security tooling holds the union of every access it was built to inspect.
Finding problems is fundable because it demonstrates capability. Fixing them is not, because it demonstrates nothing.
A components maker warning of shipment delays. Qualification rules mean a medical supply chain cannot route around a supplier quickly.
Neither actor wanted the vendor. Both wanted what the vendor holds about everyone else — the same reach as a thousand intrusions, from one operation.
A breach notification records an affected count. It does not record what proportion of affected parties took which mitigating action.
An intrusion at one company produced a sovereign commitment in four weeks. Banks too large to fail got capital requirements in exchange; there is no equivalent here.
Everyone scans repositories for committed secrets. Almost nobody scans the ticket system, which accumulates the same material indefinitely.
Nokia was right that its systems were not breached. Its code was published anyway.
The blast radius was tiny because the targeting was precise, not because the access was limited.
Nobody assessing a phone-system vendor thinks to ask about its staff’s trading software.
A signing key burned into shipped hardware cannot be rotated the way a credential can.
Code signing answers "did this come from the vendor". Here the answer was yes, and it was the wrong question.
Cloudflare was not saved by the metal. It was saved by origin binding — and this key was not doing that.
The security of a system is the security of everyone it has delegated to — a set nobody enumerates.
Inventory is waste, so nothing is spare. That is the method working, and it is why one supplier stopped everything.