LLoginsoftinloginsoft.hashnode.dev·Aug 18 · 23 min readnpm and PyPI Supply Chain Attacks: How Malicious Packages Bypass Security Controls Introduction A clean npm audit does not mean your dependencies are safe. It only means they have no known vulnerabilities. Malicious packages often have none. Traditional vulnerability scanners are bu00
LLoginsoftinloginsoft.hashnode.dev·Aug 11 · 10 min readEPSS Limitations: Why Exploited CVEs Still Get Missed Introduction Security teams have leaned on EPSS for years as the go-to answer to "which CVEs actually matter." It's a reasonable instinct. Thousands of CVEs get published every month, and nobody has t00
LLoginsoftinloginsoft.hashnode.dev·Aug 7 · 12 min readAI Exploitation Is Changing Vulnerability Management: Why Patch SLAs Need to Evolve Executive Summary Organizations have traditionally measured remediation in days or weeks, but AI-assisted exploit generation is now compressing the time between vulnerability disclosure and exploitati00
LLoginsoftinloginsoft.hashnode.dev·Jul 22 · 3 min readWe scored 3,029 CVEs for real-world exploitability, here's what we found For years, discussions about AI and offensive security have run ahead of the evidence. Most claims about what autonomous systems can exploit have come from demos and slide decks rather than data colle00