A signed package publishing pipeline with CI workflow gates, a package registry block, and credential-exfiltration warnings on a dark technical audit surface
[NEWS_ANALYSIS]
lock Supply Chain Security | 11 min read

Red Hat npm Compromise Exposes Provenance Gaps

Red Hat confirmed a supply-chain compromise in @redhat-cloud-services npm packages. The harder lesson is that signed provenance can still carry malicious code when the trusted workflow itself is abused.

Read Full Report arrow_forward
Recent Intelligence View All Intelligence
A cloud identity reset gate connected to directory nodes, key vaults, storage containers, audit logs, and containment boundaries
[NEWS_ANALYSIS] June 3, 2026

Storm-2949 Turns Password Reset Into Cloud Breach

Microsoft's Storm-2949 report shows how self-service password reset abuse can become cloud-wide access across Key Vault, web apps, SQL, storage, VMs, and MFA registration.

A hardware security key, phone biometric prompt, cloud sync icon, and recovery envelope arranged as an account security workflow
[GUIDE] June 2, 2026

Passkeys Move Account Risk To Recovery

Passkeys remove the reusable password from login, but the hard security work moves to recovery, sync, device binding, fallback methods, and privileged account policy.

Two messaging devices connected through a transparent cryptographic module with classical and post-quantum key paths
[GUIDE] June 2, 2026

Post-Quantum Messaging Needs More Than New Keys

Quantum-safe messaging is not a single algorithm swap. Teams need to understand hybrid key agreement, ratchets, group behavior, backups, identity keys, and migration transparency.