<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Supply-Chain-Security on Cloud Native &amp; Open Source: A Team Lead’s Working Journal</title>
    <link>https://www.msbiro.net/tags/supply-chain-security/</link>
    <description>Recent content in Supply-Chain-Security on Cloud Native &amp; Open Source: A Team Lead’s Working Journal</description>
    <image>
      <title>Cloud Native &amp; Open Source: A Team Lead’s Working Journal</title>
      <url>https://www.msbiro.net/%3Clink%20or%20path%20of%20image%20for%20opengraph,%20twitter-cards%3E</url>
      <link>https://www.msbiro.net/%3Clink%20or%20path%20of%20image%20for%20opengraph,%20twitter-cards%3E</link>
    </image>
    <generator>Hugo -- 0.164.0</generator>
    <language>en-us</language>
    <lastBuildDate>Mon, 27 Jul 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://www.msbiro.net/tags/supply-chain-security/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Shadow AI in CI/CD: Threat-Modelling Laptop to Kubernetes</title>
      <link>https://www.msbiro.net/posts/shadow-ai-cicd-kubernetes-threat-model/</link>
      <pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/shadow-ai-cicd-kubernetes-threat-model/</guid>
      <description>Shadow AI turns ungoverned coding assistants and agents into a live threat across CI/CD. A stage-by-stage threat model from developer laptop to Kubernetes pod, with the executive controls and tooling that contain the risk.</description>
    </item>
    <item>
      <title>In 2026 I Am Still Asked Why You Need a Hardened Container Image Catalog</title>
      <link>https://www.msbiro.net/posts/hardened-images-catalog-2026-non-negotiable/</link>
      <pubDate>Wed, 24 Jun 2026 09:30:00 +0100</pubDate>
      <guid>https://www.msbiro.net/posts/hardened-images-catalog-2026-non-negotiable/</guid>
      <description>Why hardened container image catalogs are non-negotiable in 2026: the technological case, the DORA mandate, and the NIS2 obligations explained.</description>
    </item>
    <item>
      <title>Athena Coalition: Coordinated Open Source Defense in the AI Vulnerability Era</title>
      <link>https://www.msbiro.net/posts/athena-coalition-open-source-security/</link>
      <pubDate>Tue, 16 Jun 2026 10:14:00 +0100</pubDate>
      <guid>https://www.msbiro.net/posts/athena-coalition-open-source-security/</guid>
      <description>Athena is a new industry coalition for coordinated open source vulnerability defense. Here is what it means for DevSecOps teams and security leaders.</description>
    </item>
    <item>
      <title>Lazarus Group Hides Malware in Git Hooks to Target Developers</title>
      <link>https://www.msbiro.net/posts/lazarus-group-git-hooks-malware-developers/</link>
      <pubDate>Wed, 06 May 2026 09:00:00 +0100</pubDate>
      <guid>https://www.msbiro.net/posts/lazarus-group-git-hooks-malware-developers/</guid>
      <description>North Korea&amp;#39;s Lazarus Group embeds malware in git hooks to compromise developers through fake job interviews. Attack breakdown and five practical defences.</description>
    </item>
    <item>
      <title>Supply Chain Attacks Won&#39;t Stop: 8 Controls to Reduce Your Exposure</title>
      <link>https://www.msbiro.net/posts/supply-chain-attack-prevention-8-controls/</link>
      <pubDate>Sun, 26 Apr 2026 12:00:00 +0100</pubDate>
      <guid>https://www.msbiro.net/posts/supply-chain-attack-prevention-8-controls/</guid>
      <description>Bitwarden CLI, Trivy, and Axios compromised in three weeks. Your EDR won&amp;#39;t catch postinstall scripts. 8 practical controls to reduce the blast radius.</description>
    </item>
    <item>
      <title>Testing GSD: From a Docs-Only Repo to Working Go Code in One Session</title>
      <link>https://www.msbiro.net/posts/gsd-sbom-drift-spec-driven-development/</link>
      <pubDate>Mon, 13 Apr 2026 05:32:00 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/gsd-sbom-drift-spec-driven-development/</guid>
      <description>Another SDD experiment: using GSD (Get Shit Done) v1.34.2 with GitHub Copilot and GPT-5.4 to bootstrap sbom-drift from a docs-only repo to working Go code. Installation, project initialization, Phase 1 execution, and honest lessons from the session.</description>
    </item>
    <item>
      <title>ClawdBot → MoltBot → OpenClaw: A Case Study in Confusion Attacks and Security Risks</title>
      <link>https://www.msbiro.net/posts/openclaw-security-analysis/</link>
      <pubDate>Sat, 31 Jan 2026 01:44:33 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/openclaw-security-analysis/</guid>
      <description>A comprehensive security analysis of the OpenClaw AI assistant project. Examining three name changes in 10 days as a confusion attack pattern, exposed cloud instances due to misconfiguration, the fake VS Code plugin incident, and the hidden costs of running AI agents on your own API keys. Why I can&amp;#39;t use this tool with my real accounts despite being an AI enthusiast.</description>
    </item>
    <item>
      <title>Evaluating Oss Security Fresh Editor s2c2f</title>
      <link>https://www.msbiro.net/posts/evaluating-oss-security-fresh-editor-s2c2f/</link>
      <pubDate>Sat, 27 Dec 2025 16:37:11 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/evaluating-oss-security-fresh-editor-s2c2f/</guid>
      <description>Holiday hacking from the couch: evaluating Fresh editor&amp;#39;s security using OpenSSF Scorecard, Semgrep, and cargo audit. A practical guide to applying the S2C2F framework for secure OSS adoption without killing developer productivity. Learn how to vet unknown open-source tools in an afternoon before bringing them to corporate environments.</description>
    </item>
    <item>
      <title>Kubernetes Security: 2025 Stable Features &amp; 2026 preview</title>
      <link>https://www.msbiro.net/posts/k8s-security-2025-graduates-2026-preview/</link>
      <pubDate>Mon, 08 Dec 2025 10:05:05 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/k8s-security-2025-graduates-2026-preview/</guid>
      <description>Recap of Kubernetes security features that reached stable in 2025 &#43; predictions for 2026 graduates. DevSecOps guide to production hardening.</description>
    </item>
    <item>
      <title>Beyond CVE Scanning: The Case for a Hardened Container Image Catalog</title>
      <link>https://www.msbiro.net/posts/the-case-for-hardened-container-image-catalogs/</link>
      <pubDate>Sat, 29 Nov 2025 10:00:00 +0000</pubDate>
      <guid>https://www.msbiro.net/posts/the-case-for-hardened-container-image-catalogs/</guid>
      <description>Why traditional vulnerability scanning isn&amp;#39;t enough and how a hardened image catalog is essential for modern enterprise security and regulatory compliance.</description>
    </item>
  </channel>
</rss>
