惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Y
Y Combinator Blog
IT之家
IT之家
博客园_首页
量子位
博客园 - 三生石上(FineUI控件)
小众软件
小众软件
博客园 - 聂微东
罗磊的独立博客
酷 壳 – CoolShell
酷 壳 – CoolShell
Hugging Face - Blog
Hugging Face - Blog
V
V2EX
爱范儿
爱范儿
大猫的无限游戏
大猫的无限游戏
宝玉的分享
宝玉的分享
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
雷峰网
雷峰网
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Google DeepMind News
Google DeepMind News
Microsoft Azure Blog
Microsoft Azure Blog
有赞技术团队
有赞技术团队
S
SegmentFault 最新的问题
Engineering at Meta
Engineering at Meta
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com

Step Security Blog

Announcing Dependabot Configuration Enhancements: Cooldown and Group Support - StepSecurity Securing Vibe Coding and AI Coding Agents: An End-to-End Approach with StepSecurity - StepSecurity Introducing StepSecurity Dev Machine Guard: Protecting Developer Machines from Supply Chain Attacks - StepSecurity Top 2024 Predictions for CI/CD Security - StepSecurity Dev Machine Guard Is Now Open Source: See What's Really Running on Your Developer Machine - StepSecurity Datadog's DevSecOps 2026 Report Validates What We've Been Building - StepSecurity hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions - Microsoft, DataDog, and CNCF Projects Hit So Far - StepSecurity Cline Supply Chain Attack Detected: cline@2.3.0 Silently Installs OpenClaw - StepSecurity StepSecurity’s Unified Protection Across the SDLC Infrastructure Threat Framework (SITF) - StepSecurity @velora-dex/sdk Compromised on npm: Malicious Version Drops macOS Backdoor via launchctl Persistence - StepSecurity axios Compromised on npm - Malicious Versions Drop Remote Access Trojan - StepSecurity Behind the Scenes: How StepSecurity Detected and Helped Remediate the Largest npm Supply Chain Attack - StepSecurity 10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Supply Chain Attack on GitHub Actions - StepSecurity Malicious IoliteLabs VSCode Extensions Target Solidity Developers on Windows, macOS, and Linux with Backdoor - StepSecurity TeamPCP Plants WAV Steganography Credential Stealer in telnyx PyPI Package - StepSecurity litellm: Credential Stealer Hidden in PyPI Wheel - StepSecurity Checkmarx KICS GitHub Action Compromised: Malware Injected in All Git Tags - StepSecurity CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Ecosystem - StepSecurity Trivy Compromised a Second Time - Malicious v0.69.4 Release, aquasecurity/setup-trivy, aquasecurity/trivy-action GitHub Actions Compromised - StepSecurity bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys - StepSecurity Malicious npm Releases Found in Popular React Native Packages - 130K+ Monthly Downloads Compromised - StepSecurity Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wallet Keys - StepSecurity ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push - StepSecurity xygeni-action Compromised: C2 Reverse Shell Backdoor Injected via Tag Poisoning - StepSecurity kubernetes-el Compromised: How a Pwn Request Exploited a Popular Emacs Package - StepSecurity How StepSecurity Caught a Release Storm in Microsoft’s @types Packages - StepSecurity Harden Runner Now Supports Windows and macOS GitHub Actions Runners - StepSecurity 10,000 Open-Source Projects Now Secured by Harden-Runner Community-Tier: A Milestone Three Years in the Making - StepSecurity 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) - StepSecurity 2024 in Review: The Evolution of CI/CD Security & What's Next - StepSecurity
Introducing StepSecurity Threat Intelligence: Real-Time S...
2025-09-19 · via Step Security Blog

Supply chain attacks are projected to cost organizations $60 billion globally in 2025—a 30% increase from 2023.

Today, we're excited to announce the launch of StepSecurity Threat Intelligence, a comprehensive solution that delivers real-time alerts about supply chain attacks and compromised packages directly to your existing security infrastructure.

Meeting You Where You Are: SIEM-Ready Intelligence

Over the past six months, we've kept our customers informed about critical compromises—including the tj-actions and nx incidents—through our support Slack channels and email alerts. While our rapid response has been invaluable, we heard one consistent piece of feedback: organizations need threat intelligence delivered in a way that integrates seamlessly with their SIEM and SOC solutions.

Today's launch directly addresses this need.

StepSecurity Threat Intelligence transforms how your organization responds to supply chain threats by delivering actionable intelligence exactly how your security team needs it:

Seamless SIEM Integration

  • No new integrations to configure—uses your existing StepSecurity AWS S3 and webhook setup
  • Automatic ingestion into your SIEM for correlation with other security events
  • Instantly triggers SOC on-call teams to investigate incidents as they happen
  • Dramatically reduces MTTD and MTTR for supply chain attacks—from days to minutes

Intelligence That's Actually Actionable

  • Detection within minutes of compromise, not after the damage is done
  • Context-rich alerts with specific remediation steps for your environment
  • Continuous real-time updates as threats evolve
  • Standardized alerts that fit your existing SOC workflows and playbooks

Proven Detection Capabilities

  • The same systems that discovered tj-actions, nx, and the 20-package npm attacks
  • First-to-detect track record validated by CISA and major media outlets
  • Battle-tested across thousands of organizations worldwide

Unlike generic vulnerability feeds that report issues days or weeks later, you're getting proactive threat intelligence that enables immediate response—turning potential breaches into contained incidents.

Threat Center: Your Command Center for Supply Chain Security

In addition to SIEM integration, we're introducing the Threat Center within the StepSecurity dashboard. This dedicated hub provides:

  • Comprehensive details about active supply chain compromises
  • Historical threat data and patterns
  • Actionable remediation guidance
  • Direct links to our detailed threat analysis

                                                                                          Threat Center

Proven Track Record in Threat Detection

StepSecurity has consistently been at the forefront of supply chain security:

  • We were first to report the tj-actions/changed-files compromise, alerting the community before widespread damage could occur
  • We published the first detailed technical analysis of the nx compromise, providing crucial insights that helped organizations understand and respond to the threat
  • Our threat research has been cited by CISA and major media outlets, establishing StepSecurity as a trusted source for supply chain security intelligence
  • Thousands of organizations worldwide rely on our analysis to protect their software supply chains

Our automated monitoring systems continuously scan npm, GitHub Actions, and other critical ecosystems 24/7. We continuously update these analyses in real-time as new threats emerge, making our blog posts the go-to resource during active incidents. This same detection infrastructure now feeds directly into StepSecurity Threat Intelligence, giving your organization our battle-tested early-warning capabilities.

Why This Matters Now

Supply chain attacks are accelerating in both frequency and sophistication. Bad actors increasingly target the dependencies and tools developers trust most. The window between compromise and exploitation continues to shrink, making real-time, actionable intelligence critical for defense.

With StepSecurity Threat Intelligence, you're not just getting alerts—you're getting the industry's most comprehensive supply chain security intelligence delivered exactly how your security team needs it.

Getting Started

For existing StepSecurity customers:

  • Threat Intelligence is now available through your existing AWS S3 and webhook integrations
  • Visit the new Threat Center in your dashboard to explore current and historical threat data
  • See exactly what a detection event looks like in your SIEM

For organizations not yet using StepSecurity:

  • Learn more about our comprehensive approach to supply chain security

Looking Ahead

This launch represents our commitment to not just detecting threats but ensuring that intelligence reaches the right teams in the right format at the right time. As supply chain attacks evolve, so will our threat intelligence capabilities.