惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Google DeepMind News
Google DeepMind News
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Security Latest
Security Latest
P
Palo Alto Networks Blog
AWS News Blog
AWS News Blog
NISL@THU
NISL@THU
T
Threatpost
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Latest news
Latest news
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
WordPress大学
WordPress大学
J
Java Code Geeks
P
Privacy International News Feed
阮一峰的网络日志
阮一峰的网络日志
S
Schneier on Security
博客园 - 聂微东
Project Zero
Project Zero
美团技术团队
Recent Commits to openclaw:main
Recent Commits to openclaw:main
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Scott Helme
Scott Helme
I
Intezer
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
H
Hacker News: Front Page
S
Security @ Cisco Blogs
博客园 - 司徒正美
O
OpenAI News
Last Week in AI
Last Week in AI
L
LINUX DO - 热门话题
酷 壳 – CoolShell
酷 壳 – CoolShell
SecWiki News
SecWiki News
月光博客
月光博客
S
Security Affairs
The GitHub Blog
The GitHub Blog
P
Privacy & Cybersecurity Law Blog
S
Secure Thoughts
V
V2EX
S
Securelist
F
Fortinet All Blogs
W
WeLiveSecurity
D
Docker
博客园 - 三生石上(FineUI控件)
Simon Willison's Weblog
Simon Willison's Weblog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
C
Cyber Attacks, Cyber Crime and Cyber Security
V
Visual Studio Blog
www.infosecurity-magazine.com
www.infosecurity-magazine.com
Webroot Blog
Webroot Blog
Engineering at Meta
Engineering at Meta

Latest news

Why I'm recommending last year's phones over 2026 models - with one exception This powerful Gemini setting made my AI results way more personal and accurate After testing this HP laptop, I get why its 'boring' design is adored by business users The best TV antenna of 2026: Expert tested Your old iPad or Android tablet can be your new smart home panel - here's how Apple's original AirTag still tracks effectively, and you can get a 4-pack for its best price ever T-Mobile will give you an iPad for $99 when you sign up for a new line - here's how How to qualify for Apple's education discount - and get a $499 MacBook Neo for school T-Mobile will give you a Samsung Galaxy Watch 8 for free - how to get yours Prolonged AI use can be hazardous to your health and work: 4 ways to stay safe Verizon will give you a free iPad or Apple Watch with your next iPhone - how the deal works The best laptops of 2026: Expert tested and reviewed I hid 4 Bluetooth trackers (including AirTags) to test their reliability - here's how Android rivals compared I stopped using my iPhone's hotspot after testing this 5G router - and that won't change The best Kindles in 2026: Expert recommended Does Best Buy price match? Everything to know about matching prices online and in-store The best WordPress hosting services of 2026: Expert tested and reviewed The best Apple Watch of 2026: Expert tested and reviewed The best TV screen cleaners of 2026: Expert recommended The best 50-inch TVs of 2026: Expert tested I traded my Sonos Era 300 for Denon's new home speaker - and see no reason to go back AI-powered website builders have come a long way - here's your best option in 2026 Amazon just slashed $250 off the Google Pixel 10 - and a Prime subscription isn't required I found the apps slowing down my PC - how to kill the biggest memory hogs These companies are actually upskilling their workers for AI - here's how they do it Verizon will give you Meta Ray-Bans for free with this Fios Internet deal - how to get yours I tried the new Gemini app for Mac - it has one major advantage over the web version How Google's updated AI Mode will ease your tab clutter when you search Why this MagSafe battery pack is our readers' favorite model right now - especially at its price T-Mobile will give you a Google Pixel 10a for free - plus an extra gift OpenAI's Codex Desktop can run your computer now - and has its own browser Want to build a startup that gets acquired? This founder shares 5 proven tips Google to pay $135M settlement to Android phone users - how to claim your share if you qualify Want to stand out on LinkedIn? Try this career strategist's top 3 tips for strengthening your profile I've used Dell's new XPS 16 for a week, and it's the Windows laptop to beat in 2026 You can get 50% off YouTube Premium for 1 year right now - but the deal ends soon Tidal vs. Qobuz: I tried both hi-res streaming services, and they couldn't be more different This stroller turns into a carry on-suitcase, and I recommend it for traveling parents The best small business VoIP providers of 2026: Expert tested and reviewed Protect your devices with our pick for the best antivirus software, now over 60% off MacBook Neo vs. Surface: Why spiraling RAM prices are bruising Microsoft's PC business but not Apple's I tried Google's new desktop app for Windows, and I'll never search the old way again Microsoft's Windows 11 laptop deal for students comes with a $500 bonus - what's included You can buy an LG B5 OLED for $1,500 off at Best Buy - and it comes with a free 4K TV Why Zorin OS 18.1 is simply the best Linux distro - for anyone Why Netgear just got the first FCC router ban exemption in the US Microsoft's latest Windows update now confirms if your PC is Secure Boot-protected - how it works Can this $70 Linux app make up for the lack of Photoshop? I tried it to find out 'Like handing out the blueprint to a bank vault': Why AI led one company to abandon open source iPhone charging slowly? 6 quick fixes to try before blaming your battery Roku TV vs. Fire Stick: Why I'm looking beyond streaming resolution when comparing the two AI is getting better at your job, but you have time to adjust, according to MIT The best internal communication tools of 2026: Expert tested and reviewed Half of all US employees use AI at work now - and waste almost 8 hours a week doing it The latest Google Home update brings Gemini fixes that I'm actually excited to try again I've been subscribed to a data removal service a month now - what I wish I knew sooner You can use Linux 7.0 on these 7 distros today - here's what to expect How I share audio from my Android phone to multiple earbuds (and why it's a big deal) Why the Apple Watch's 20-minute calibration test is worth your time - especially if you're data curious I tested ChatGPT Plus vs. Gemini Pro to see which is better - and if it's worth switching I used the 'Plus Five' rule to fix my iPhone's slow wireless charging - here's how it works The new rules for AI-assisted code in the Linux kernel: What every dev needs to know 'Job seekers have to be detectives': 3 signs that listing is a scam How the latest Netrunner distro delivers a Linux productivity powerhouse This Linux distro offers an easy DNS switcher - but there's more to it that I like I tested Artix Linux: An enjoyable systemd-free distro for experienced users (and ChromeOS speeds) I spent two years testing wind power at home - here's why solar is still my preferred source I camera-tested the Samsung Galaxy S26 Ultra with Oppo and Xiaomi - this model won it for me How I boosted my portable solar panels' power by up to 30% - 11 expert-approved tips I see why Ubuntu 26.04 is more than just a performance bump for thrill-seeking gamers France is ditching Windows for digital sovereignty - and its new Linux stack is taking shape As an Android user, this MagSafe wallet is the clearest reason why Qi2 magnets shouldn't be ignored The best Zoom alternatives in 2026: Expert tested and reviewed KDE Linux is the purest form of Plasma I've used in months - but there's a catch LG C6 vs. LG C5: Why the 2025 model is still the smarter OLED TV model buy for me How I disabled 'fast startup' on my Windows 11 laptop to stop overnight battery drain 30 years later, I returned to Enlightenment Linux to test the Elive beta - and it's much better Here's my favorite email trick for cleaning up inbox clutter - automatically The $30 Google TV stick may be the budget Chromecast successor we've been waiting for The best AR and MR glasses in 2026: Expert tested and reviewed This handy electric screwdriver is now 50% off - here's where to snag the deal This Ryobi yard essentials bundle packs a free power tool - how to get yours After trying these boomless headphones in the office, I'm feeling hopeful for the future of work tech I used this EcoFlow battery to run my 3,000-sq-ft home in a blackout - here's how it kept my AC on Microsoft's Windows Insider Program is no longer a confusing mess Forget Shokz: I tried the Suunto Spark earbuds for a month, and they've sold me on air conduction iOS 26.4 brings essential upgrades to your iPhone - including a vital security fix YouTube Premium is getting a price increase in June - but you can save $32 with one change Your router may be vulnerable to Russian hackers, FBI warns: 5 steps to take now I walked 3,000 steps with my Apple Watch, Google Pixel, and Oura Ring - this tracker was most accurate I stopped guessing which AA batteries are dead - this charging station keeps them in check for me My favorite Android Auto find is these hidden shortcuts that are highly customizable AirDrop is coming to older Samsung phones - is yours supported? How to get it early I'm no longer using Google Photos as just a cloud storage - 5 tools that elevate the app The best data removal services of 2026: Expert tested and reviewed The best Samsung TVs of 2026: Expert tested and reviewed The best mobile scanning apps of 2026: Expert tested and reviewed The best HP laptops of 2026: Expert tested and reviewed After using Lenovo's new Yoga laptop, I'm wondering if Windows makers are running out of ideas Samsung S95H vs. Samsung S95F: I compared the OLED TVs and wasn't prepared for the upset
Perplexity launches Bumblebee: How its new read-only dev scanner differs from Chainguard
Written by · 2026-05-29 · via Latest news
lapscan-screenshot-2026-05-28-120036
dem10/ iStock / Getty Images Plus via Getty Images

Follow ZDNET: Add us as a preferred source on Google.


ZDNET's key takeaways

  • Perplexity Bumblebee is an open-source developer security program.
  • Bumblebee doesn't require AI or a subscription.
  • The program aims to spot problems on programmers' laptops. 

If you're a programmer, you're painfully aware that there's been a flood of successful malicious attacks on your software supply chain. These attacks include the Axios npm package compromise, the PyPI LiteLLM AI attack, and the CanisterSprawl npm assault

What's a programmer to do when they can't even trust the very building blocks of their program? Well, there are several approaches, and the latest comes from Perplexity

According to the AI company, Bumblebee is a "read‑only scanner we use to check developer machines for risky packages, extensions, and AI tool configs during supply‑chain incidents." The company said in its announcement that the program is one of "the internal tools we use to protect the developer systems behind Perplexity, Comet, and Computer."

Also: How I got my business emails through spam filters with SPF, DKIM, and DMARC

The security question Bumblebee is built to answer

The tool is built to answer the first question that pops up in your mind after a new supply‑chain advisory: Do any of our programmers have this thing installed? 

Bumblebee runs on MacOS and Linux developer machines and is available now as an open-source Go project. You can plug the tool's results into whatever security system you're already using.

Instead of targeting code or runtime behavior, Bumblebee focuses on four specific surfaces. Perplexity claimed existing open‑source tools tend to cover one or two of these surfaces, while Bumblebee can handle all four at once:

  • Language package managers: npm, pnpm, Yarn, Bun, PyPI, Go modules, RubyGems, and Composer
  • AI agent configs: Model Context Protocol (MCP)
  • Editor extensions: VS Code‑family (i.e., VS Code, Cursor, Windsurf, VSCodium)
  • Browser extensions: Chromium‑family (Chrome, Comet, Edge, Brave, Arc) and Firefox

Also: The patching treadmill: Why traditional application security is no longer enough

In other words, this tool is for people running JavaScript/TypeScript, Python, Go, Ruby, and PHP; programmers experimenting with AI MCP configurations; and developers living inside VS Code‑style editors and Chromium‑style browsers.

How Bumblebee integrates into your internal workflow  

Bumblebee is part of a larger internal workflow, which Perplexity outlines as follows:

  1. A threat signal is identified through public disclosures, third‑party intel feeds, or internal research.
  2. Perplexity Computer drafts a catalog update. It enters the signal into a structured entry (ecosystem, name, version), and then opens a GitHub pull request (PR) with source links.
  3. The detection is sent to human review, after which the PR is merged.
  4. Bumblebee runs on endpoints with the updated catalog.
  5. Findings are shared with the security team.

You don't have to use Perplexity's JSON catalog; you can now run Bumblebee with your own catalogs and review process. Each detection is "traceable, showing which catalog entry triggered the filing, when it was added, and any evidence," Perplexity noted.

You can use the open‑source Bumblebee catalog on GitHub. You'll find it in the threat_intel/ directory, which "holds maintained exposure catalogs built from public threat-intelligence reporting on recent supply-chain campaigns." Each file in that directory is a catalog in the standard JSON format (schema_version + entries). The README there explains the current catalog list and review guidance. To use the catalogs, you clone the repo and pass that directory to the scanner. For more on that step, see Bumblebee's Threat Intelligence Exposure Catalogs.

Also: Best VPN services: Expert tested and recommended

Alternatively, you can build your own Bumblebee catalog as a simple JSON file listing exact matches for the risky components you care about, such as ecosystem, package name, and affected versions. Bumblebee then compares local machine inventory against that catalog and flags only exact (ecosystem, name, version) matches, so the catalog is intentionally narrow and deterministic.

The scanner supports three profiles that map pretty cleanly to how developers and security teams think about scope:

  • Baseline profile: Routine scan of standard laptop locations. Teams schedule the scan through their own systems.
  • Project profile: Targeted scan of specific repos or workspaces.
  • Deep profile: Response sweep for active incidents.

Perplexity positions this tool squarely in the "developer surface" tier: Software Bill of Materials (SBOM) and vulnerability scanners handle repositories and build artifacts. Endpoint inventory products cover installed applications. Bumblebee runs on the developer laptop. The key output is: "It tells you whether that machine has a specific package, version, extension, or MCP configuration installed when a supply‑chain advisory lands."

Read-only avoids risky scans

The company leans hard into "read‑only" as a security property, not just an implementation detail. In their words, "Bumblebee is read‑only. It reads metadata files directly and never lets potentially compromised tooling run, which prevents the scan from becoming a risk." They added: "Making Bumblebee read‑only helps avoid issues with install‑time code execution."

Also: 5 ways to fortify your network against the new speed of AI attacks

The post called out npm‑style postinstall attacks directly: "npm packages can carry postinstall scripts that run automatically the moment npm install touches them. That's how the most recent supply‑chain worms have spread." The warning for developer‑side scanners is blunt: "A scanner that invokes npm to check for exposure has already triggered the attack it was looking for."

Bumblebee's safety guarantees follow from what it refuses to do, said Perplexity:

  • It never runs install scripts or lifecycle hooks.
  • It never runs your package manager.
  • Bumblebee never reads application source files; it reads metadata such as lockfiles, manifests, and installed package metadata.
  • Bumblebee is not an Endpoint Detection and Response (EDR) program.

Framed this way, Bumblebee is not trying to replace endpoint detection tools or build‑time scanners. It's more of a targeted inventory probe focused on the specific metadata that spots when a particular programmer's PC is using vulnerable code.

Also: Stopping bugs before they ship: The shift to preventative security

Bumblebee is also not like Chainguard, where the focus is entirely on securing your software supply chain by hardening containers and pipelines rather than developer laptops. The guidance centers on concepts such as minimal, hardened base images, automated rebuilds when vulnerabilities are disclosed, and a policy that blocks non‑compliant artifacts from being shipped.

How Bumblebee compares to Chainguard

Bumblebee lives a step earlier in the lifecycle and a step closer to where developers actually work. Perplexity wrote that "security starts at the local developer surface," and that "the integrity of our products has to begin further up the supply‑chain than production." Where Chainguard's controls surround containers and build outputs, Perplexity said Bumblebee "runs on the developer laptop" and is used "to check developer machines for risky packages, extensions, and AI tool configs during supply‑chain incidents."

For developers, that approach translates into different touchpoints. Chainguard shows up as base images, policies, and SBOM requirements in your pipelines. Bumblebee is a program your security team runs on your laptop to see which packages, extensions, and MCP configs you currently have installed, and to note which are vulnerable. 

Also: My new favorite Windows app made my PC safer and more reliable - and it's free

Both approaches have their advantages. Personally, I prefer Chainguard's approach, which has been expanded to AI tools and code, but I can see how Bumblebee could be useful as well. The tool also has the advantage of being both free and open-source under the Apache 2.0 license. 

Security