惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Recent Announcements
Recent Announcements
人人都是产品经理
人人都是产品经理
月光博客
月光博客
博客园 - 三生石上(FineUI控件)
GbyAI
GbyAI
博客园 - 司徒正美
美团技术团队
Vercel News
Vercel News
IT之家
IT之家
U
Unit 42
Y
Y Combinator Blog
罗磊的独立博客
Microsoft Security Blog
Microsoft Security Blog
MongoDB | Blog
MongoDB | Blog
Jina AI
Jina AI
V
Visual Studio Blog
B
Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
MyScale Blog
MyScale Blog
博客园 - 叶小钗
A
About on SuperTechFans
WordPress大学
WordPress大学
Hugging Face - Blog
Hugging Face - Blog
B
Blog RSS Feed

Help Net Security

ChatGPT advanced account security adds passkeys and hardware keys Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for months Automating Pentest Delivery: A Step-by-Step Guide - PlexTrac Open-source privacy proxy masks PII before prompts reach external AI services Shadow AI risks deepen as 31% of users get no employer training Identity is the control plane for distributed infrastructure AI traffic is getting bigger, louder, and less predictable New infosec products of the month: April 2026 cPanel zero-day exploited for months before patch release (CVE-2026-41940) Cisco releases open-source toolkit for verifying AI model lineage Met Police face criticism for using AI to spy on their own officers Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431) Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security IP Fabric MCP server adds governance and control to enterprise AIOps workflows - Help Net Security Aqua Compass MCP server enables real-time investigation and containment of runtime threats - Help Net Security Google brings instant email verification to Android, no OTP needed - Help Net Security If cyber espionage via HDMI worries you, NCSC built a device to stop it - Help Net Security Apple fixes iPhone bug that let FBI retrieve deleted Signal messages(CVE-2026-28950) - Help Net Security GopherWhisper APT group hides command and control traffic in Slack and Discord - Help Net Security OpenAI tackles a bad habit people have when interacting with AI - Help Net Security A year in, Zoom's CISO reflects on balancing security and business - Help Net Security Scenario: Open-source framework for automated AI app red-teaming - Help Net Security GDPR works, but only where someone enforces it - Help Net Security Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks - Help Net Security Google’s Workspace Intelligence promises privacy while running on your data - Help Net Security Cyberattack on French government agency triggers phishing alert - Help Net Security Claude Mythos finds 271 Firefox flaws, Mozilla believes zero-days are numbered - Help Net Security Prove Identity Platform connects verification, authentication, and fraud prevention - Help Net Security New Mirai variants target routers and DVRs in parallel campaigns - Help Net Security Acronis GenAI Protection gives MSPs control over AI usage and data risks - Help Net Security
depthfirst adds pre-install protection against malicious ...
Industry News · 2026-06-01 · via Help Net Security

depthfirst has introduced Dependency Firewall, a product that reviews every open-source package being downloaded anywhere in a company and blocks the malicious ones before they reach the person or system that requested them. Developers, AI agents, and any employee using Claude, Codex, or other AI tools keep installing exactly as they do today, and nothing dangerous makes it through. Security teams can ensure that AI is rolled out safely across the company.

depthfirst Dependency Firewall

Modern software runs on open source, and attackers exploit that trust by publishing packages that mimic popular libraries and hide malicious code inside install scripts. The breach can happen on a first install, even before production: malicious scripts can execute the moment a package is pulled down, so a single developer machine or coding agent installing a malicious dependency can leak credentials, plant a backdoor, or exfiltrate source code before anything has been reviewed, built, or deployed.

Verizon reported that 48% of data breaches analyzed in its 2026 DBIR involved ransomware. And malware attacks have surged in recent months. They cost almost nothing to launch, and the people pulling in dependencies now include business users running AI assistants and autonomous coding agents, not only security-conscious engineers.

Dependency Firewall inspects every package being downloaded in a company, regardless of who is installing it, and returns a verdict before it is installed. Approved packages pass through with negligible latency, packages that warrant review are quarantined, and anything malicious is blocked with the supporting evidence attached. Engineers use the same install commands, CI pipelines run unchanged, and AI agents keep operating normally.

Because Dependency Firewall analyzes packages the moment they are published rather than at install time, every package has already been assessed by the time anyone requests it. The analysis runs on depthfirst’s agentic defense platform, the same system that discovered NGINX Rift, a critical 18-year-old vulnerability affecting a significant portion of global web traffic. For every new package version, it:

  • Runs proprietary analysis on code and install scripts
  • Performs runtime analysis to detect malicious package behavior
  • Reasons about package intent and investigates unknown behavior
  • Flags publisher and maintainer anomalies
  • Maps dependency and transitive risk
  • Checks against public and private threat and data feeds

Every verdict ships with the evidence behind it, so any decision can be audited back to the underlying signals. Beyond blocking what is clearly malicious, Dependency Firewall gives teams a programmable enforcement layer: requiring a minimum package age, restricting acceptable dependency trees, enforcing license policies across direct and transitive dependencies, and quarantining packages pending manual review. Verdicts route into the tools teams already use, and when the firewall calls something wrong, a team can override the decision in seconds, with every override logged automatically.

“We recently had an incident where an internal vibecoded app inadvertently pulled in a malicious package that put our company at risk. depthfirst’s Dependency Firewall is a game changer as it enables us to safely leverage AI across the company,” said a CISO at a Fortune 100 company.