The Great NPM Heist: How the Attack Worked & How InvisiRisk Can Help Stop It

How InvisiRisk Protects

The Great NPM Heist: What Happened and How InvisiRisk Protects You In early September 2025 attackers orchestrated a large-scale supply chain compromise on the NPM registry. They phished several popular package maintainers to gain publishing rights, then pushed malicious updates to over 18 widely used JavaScript libraries (including chalk, debug, ansi-regex, strip-ansi, wrap-ansi, color-convert, etc.). […]

CVE-2025-48384: How Git’s Clone Command Becomes an Attack Vector

Git’s Silent Takeover: How a Simple Clone Command Can Compromise Your Entire System (CVE-2025-48384) In the world of software development, Git is the undisputed foundation of version control, a tool so integral and trusted that its security is often taken for granted. However, a recently discovered high-severity vulnerability, CVE-2025-48384, shatters this perception. This flaw, which […]

GitHub’s ‘Pwn Request’ misconfiguration: How InvisiRisk BAF Shields Your CI/CD from Hidden Threats

GitHub’s “Pwn Request” Misconfiguration: How InvisiRisk BAF Shields Your CI/CD from Hidden Threats The automation prowess of GitHub Actions, a cornerstone of modern CI/CD pipelines, harbors a subtle yet critical loophole. The pull_request_target trigger, if misconfigured, can be exploited in what’s known as a “pwn request” attack, granting malicious actors access to your repository’s secrets […]

CVE-2025-29927: Next.js Middleware Bypass & How to Prevent It

Next.js Middleware Vulnerability (CVE-2025-29927): How InvisiRisk BAF Provides Real-Time Protection Introduction In the ever-evolving landscape of web development, security remains a paramount concern. A recent discovery of a critical vulnerability in Next.js, identified as CVE-2025-29927, underscores the necessity for robust security measures within build processes. This blog post delves into the specifics of this vulnerability […]

How InvisiRisk BAF Mitigates GitHub Actions Supply Chain Attacks

baf

How InvisiRisk BAF Effectively Mitigates GitHub Actions Supply Chain Attacks Like the Ultralytics Attack Introduction The rise of automation in software development has made CI/CD pipelines indispensable, with GitHub Actions standing out as a cornerstone for streamlining workflows. However, this reliance on automation introduces significant security risks, as demonstrated by the December 2024 supply chain […]

GitHub Actions Supply Chain Attack: How InvisiRisk BAF Mitigates tj-actions/changed-files

github action

In-Depth Analysis: How InvisiRisk BAF Effectively Mitigates GitHub Actions Supply Chain Attacks Introduction The modern software development lifecycle is heavily reliant on automation, with CI/CD pipelines playing a central role. GitHub Actions has emerged as a leading platform for automating these workflows, enabling developers to streamline development and deployment processes. However, this increased reliance on […]