TCH ECO SPT AM Amit Spitzer SLSA Provenance Didn’t Stop the Keyv npm Worm. It Vouched For It. Every poisoned version of Keyv that went out this week carried a valid SLSA attestation and a legitimate OIDC signature. The build pipeline…
TCH ECO AM Amit Spitzer Three Russian Spy Crews Hijacked Accounts Without Stealing a Single Password Google’s Threat Intelligence Group published a report this week on three Russian-linked hacking clusters, tracked as UNC6293, UNC7005, and…
AI TCH ECO AM Amit Spitzer AI Wrote 6,080 Patches for Six Bugs. Fewer Than Half of Them Worked. The patch pipelines I built always had one gate that slowed everyone down: a human had to reproduce the original exploit against the fixed…