
AI & MLAug 24, 2026
Sigstore and Cosign: Verify Container Images
Sign and verify container images with Cosign, keyless identities, transparency evidence, digest pinning, and admission policies that check the signer.
4 min read

Supply ChainAug 24, 2026
SLSA Provenance: Verify the Software Supply Chain
Use SLSA provenance to trace artifacts to source and build systems, verify expectations, improve CI controls, and respond to tampering.
4 min read

Supply ChainAug 24, 2026
Malicious PyPI Packages: Detect Supply-Chain Attacks
Detect malicious PyPI packages through provenance, dependency controls, install behavior, network telemetry, hashes, and a Python incident playbook.
3 min read

DNSAug 24, 2026
Subdomain Takeover: Find Dangling DNS First
Prevent subdomain takeover by finding dangling DNS records, linking names to cloud owners, monitoring certificates, and fixing decommissioning order.
4 min read