InvisiRisk Blog Posts

Malicious Post-Install Scripts: npm and PyPI Attacks Explained
Installing a package isn’t a passive download. Both npm and PyPI can run code on your machine the moment a

What are Secrets Leaks in CI/CD Pipelines?
Almost every modern application is assembled by an automated pipeline, and that pipeline can’t do its job without credentials. The

Slopsquatting: How AI-Hallucinated Packages Threaten the Software Supply Chain
Slopsquatting is a software supply chain attack where criminals register malicious packages under the fake names that AI coding assistants

InvisRisk Expands Build Application Firewall with Real-Time CI/CD Enforcement Across AWS and GitLab
New release extends runtime policy enforcement, stopping software supply chain threats during build execution before release. Houston, TX – June

The Executive Guide to SBOM Security
By David Pulaski, CXO & Co-Founder, InvisiRiskPublished June 2026 TL;DR A Software Bill of Materials (SBOM) is a complete inventory

Healthcare Software Supply Chain Security Explained
By David Pulaski, CXO & Co-Founder, InvisiRiskPublished June 2026 TL;DR Healthcare software is assembled from open-source packages, third-party code, and

Open Source Vulnerability Management at Build Time
Open source vulnerability management at build time means inspecting and enforcing policy on every open source package the moment it

The Complete Application Security Stack Guide For 2026
A modern application security stack rests on four foundational categories (code security or SAST, dependency security or SCA, runtime security

What Is a Build Application Firewall?
TL;DR A Build Application Firewall (BAF) does for CI/CD pipelines what a WAF does for web applications: it sits inline,

What Is Build-Time Security for CI/CD Pipelines?
TL;DR A CI/CD pipeline is privileged, networked, and often executes third-party packages, scripts, actions, containers, or build tools as software

Build-Time Security: The Missing Layer in Application Security
TL;DR AppSec tools cover code (SAST), dependencies (SCA), and deployed applications (DAST), but most do not monitor and enforce policy

InvisiRisk Expands Build Application Firewall with Encoded Secret Detection and Hardened CI/CD Integration
Latest release (v1.1.38) delivers real-time encoded secret interception, deep dependency intelligence, and expanded GitHub Actions support Houston, TX, April 21,