A companion to our incident postmortem: what we are changing across the org so the May 11 supply-chain attack cannot happen the same way again. Changes include hardened CI/CD, improved secret management, and enhanced package publishing controls.
From TanStack Blog
By
May 12, 2026

A companion to our incident postmortem: what we are changing across the org so the May 11 supply-chain attack cannot happen the same way again. Changes include hardened CI/CD, improved secret management, and enhanced package publishing controls.

Prompt injection ranks No. 1 with OWASP and No. 12 in the incident record. The attack itself is invisible to a scan.
A CISO who sees a low CVE count and deprioritizes prompt injection is reading the scoreboard wrong. Prompt injection has held the No. 1 spot on the OWASP Top 10 for LLM Applications for three consecutive years. When two leaders of that list checked it against 6,639 labeled real-world incidents, it c
Aug 25, 2026

The fix for the AI agent that hijacked a company's DNS: it can propose the change, but it can't approve it
A security agent read a Cloudflare log, found an attacker’s prompt-injection payload sitting inside it, and rewrote the company’s DNS. The firewall had already blocked that payload, and blocking it is what wrote it into the log. That chain is GhostJacking, which Tenet Security demonstrated on the DE
Aug 26, 2026

Socket lands a fresh $40M to scan software for security flaws
The software supply chain, which comprises the components and processes used to develop software, has become precarious. According to one recent survey, 88% of companies believe poor software supply chain security presents an “enterprise-wide risk” to their organizations. Open source supply chain components are especially fraught, thanks to the logistical hurdles in keeping each component well-maintained. Security firm Synopsys found in its 2023 report that 89% of businesses’ codebases containe
Oct 22, 2024
Fig Security emerges from stealth with $38M to help security teams deal with change
Fig traces data flows in the security stack and then alerts security teams when changes at any point affect detection or response capabilities.
Mar 3, 2026