top of page

InvisiRisk Blog Posts


Shai-Hulud NPM Worm Attack: Overview and InvisiRisk Protection
InvisiRisk’s BAF enforces defensive rules in the build pipeline (trusted registries/SCM, blocked packages, secret-leak prevention, response checks, git protections), and the Build Security AI Agent feature provides behavioral detection for novel, suspected worm-style activities. The defensive rules and the agent work together to stop supply-chain worms and credential-theft campaigns from spreading through your builds.

Pranesh Shrestha
Sep 255 min read
Â
Â
Â


The Great NPM Heist – What Happened and How InvisiRisk Protects You
Integrating InvisiRisk Build Application Firewall into your development workflow is a practical way to ensure that even if attackers try to slip malware into NPM or Git, your build process will catch it and shut it down before any damage is done.

Pranesh Shrestha
Sep 196 min read
Â
Â
Â


Git's Silent Takeover: How a Simple Clone Command Can Compromise Your Entire System
This post breaks down how this attack works, it’s devastating potential, and demonstrates how InvisiRisk's Build Application Firewall (BAF) provides a crucial, proactive defense by preventing the use of vulnerable GIT versions before they can be exploited.Â

Pranesh Shrestha
Sep 94 min read
Â
Â


InvisiRisk Unveils Groundbreaking Build Security AI Agent
InvisiRisk, Inc. is excited to announce the launch of its revolutionary Build Security AI Agent, designed to transform the security landscape of software supply chains. This innovative solution leverages advanced artificial intelligence to provide unparalleled protection for CI/CD pipelines, ensuring the integrity and security of software development processes.

InvisiRisk, Inc.
May 82 min read
Â
Â


Why Your Secrets Faucet is Still Leaking
InvisiRisk BAF is an advanced security platform that strengthens software build processes against supply chain threats. It offers real-time defense by applying default security policies that block known vulnerabilities, ensure the use of trusted sources, and restrict unauthorized activities during builds.

InvisiRisk, Inc.
Apr 303 min read
Â
Â
Â


Don't Let a Typo Sink Your Ship: How InvisiRisk BAF Fights The Silent Threat of Typosquatting
Typosquatting attacks are a silent but significant threat in the software supply chain. Relying solely on manual vigilance is no longer sufficient. Our Build Application Firewall (BAF) is designed with a robust set of default security policies to protect your applications from various vulnerabilities.

InvisiRisk, Inc.
Apr 174 min read
Â
Â


Could Standard Security Attestations, Powered by InvisiRisk, Have Shielded the NHS supplier from the £3m ICO Fine?
The ICO fine levied against , Advanced Computer Software Group Ltd, serves as a stark reminder of the importance of supply chain security.

InvisiRisk, Inc.
Apr 32 min read
Â
Â


CVE-2025-29927: Middleware Authorization Bypass in Next.js and How InvisiRisk BAF Prevents it
InvisiRisk BAF’s layered, real-time security stops attacks like the Ultralytics/Action Compromise

InvisiRisk, Inc.
Apr 13 min read
Â
Â


How InvisiRisk BAF Effectively Mitigates GitHub Actions Supply Chain Attacks Like the Ultralytics/Action Compromise
InvisiRisk BAF’s layered, real-time security stops attacks like the Ultralytics/Action Compromise

InvisiRisk, Inc.
Mar 274 min read
Â
Â


Ensuring Software Supply Chain Security with Blessed Open-Source Repositories
The use of blessed open-source repositories, coupled with robust policy enforcement through BAF, is essential.

InvisiRisk, Inc.
Mar 112 min read
Â
Â


Beyond Open-Source Vulnerability Tracking: Comprehensive Software Supply Chain Security with InvisiRisk
By addressing these broader risks, InvisiRisk helps organizations deliver secure software faster and with greater confidence.

InvisiRisk, Inc.
Dec 12, 20242 min read
Â
Â
Â


InvisiRisk Announces the Launch of its Innovative Governance, Risk and Compliance Platform for the Software Supply Chain
Announcement about the launch of our innovative Governance, Risk, and Compliance (GRC) platform for the software supply chain.

InvisiRisk, Inc.
Dec 10, 20243 min read
Â
Â
bottom of page