Blog · corpus.blog/blogs/mend.io/posts
mend.io
mend.io
2026
10 Sept 2026
The skill layer is a dependency problem without a lockfile: what the OWASP Agentic Skills Top 10 gets rightoriginal ↗
26 Aug 2026
28 Jul 2026
199 RubyGems, two techniques, zero working payloads: Inside a cryptomining campaign that never ranoriginal ↗
22 Jul 2026
14 Jul 2026
The ECB just gave banks four months to fix AI vulnerability gaps. Most of the work starts in the software supply chain.original ↗
8 Jul 2026
1 Jul 2026
1 Jun 2026
Mini Shai-Hulud Hits @antv: 323 npm Packages Compromised Through the atool Maintainer Accountoriginal ↗
19 May 2026
Inside the RubyGems Supply Chain Attack: How Mend Defender Caught a Coordinated Flood Before It Spreadoriginal ↗
14 May 2026
7 May 2026
PhantomRaven Wave 5: New Undocumented NPM Supply Chain Campaign Targets DeFi, Cloud, and AI Developersoriginal ↗
3 May 2026
Shai-Hulud Strikes SAP: Supply Chain Worm Weaponized Claude Code to Compromise the CAP Frameworkoriginal ↗
29 Apr 2026
The Butlerian Jihad: Compromised Bitwarden CLI Deploys npm Worm, Poisons AI Assistants, and Dumps GitHub Secretsoriginal ↗
23 Apr 2026
9 Apr 2026
Poisoned Axios: npm Account Takeover, 50 Million Downloads, and a RAT That Vanishes After Installoriginal ↗
31 Mar 2026
CanisterWorm: The Self-Spreading npm Attack That Uses a Decentralized Server to Stay Aliveoriginal ↗
21 Mar 2026
19 Mar 2026
Introducing AI-powered Contextual Project Classification: From severity scores to business riskoriginal ↗
17 Mar 2026
10 Mar 2026
17 Feb 2026
10 Feb 2026
20 Jan 2026
2025
22 Dec 2025
18 Dec 2025
4 Dec 2025
Mend.io + Wiz: A New Code-to-Cloud Integration for Accurate, Context-Driven Risk Prioritizationoriginal ↗
2 Dec 2025
24 Nov 2025