## Author: Francesco Cipollone

- 31st August 2026

## [From 40 to 800 Commits: What Breaks in Security When Build Stops Being the Bottleneck](/content/from-40-to-800-commits-ai-native-sdlc-security/index.html)

Phoenix’s engineering output jumped from 40 to 800 commits per developer a month. Code review didn’t survive the jump intact — Faros AI’s telemetry on 22,000 developers shows 31.3% of PRs now merge unreviewed. Here’s what broke, and what we rebuilt around generation instead of inspection.

- 28th August 2026

## [From SBOM to Declaration: Closing the CRA 24-Hour Clock Across One Platform](/content/cra-24-hour-clock-sbom-vex-vulnerability-declaration/index.html)

From 11 September 2026, EU Cyber Resilience Act Article 14 gives manufacturers 24 hours to report an actively exploited vulnerability. Most AppSec programmes are built around CVE enrichment, which arrives too late and can’t see malicious packages at all. Phoenix’s five-stage pipeline turns SBOM, exploitation intelligence, and risk exceptions into one Article 14-ready evidence chain.

- 5th August 2026

## [Phoenix Security Launches the Exploit Hunt: A Threat-Model-Led AI Red Team That Attacks Your Code and Proves the Exploit](/content/phoenix-security-launches-exploit-hunt-black-hat-2026/index.html)

Phoenix Security releases Exploit Hunt at Black Hat USA 2026 — an AI red team that takes targets from a live threat model and reports a finding only after writing and validating a runnable proof-of-concept exploit. Available in Phoenix Purple now.

- 4th August 2026

## [Mini Shai-Hulud keyv/cacheable npm Compromise (No CVE Assigned): Self-Propagating Worm Steals CI, Cloud, and Developer Credentials](/content/mini-shai-hulud-keyv-cacheable-npm-supply-chain-worm/index.html)

An attacker hijacked the keyv/cacheable npm maintainer account and shipped a self-propagating Mini Shai-Hulud worm across 2 billion+ monthly installs, reaching most teams transitively through ESLint. Valid OIDC provenance masked the compromise. No CVE was assigned.

- 28th July 2026

## [Give Me the List of Fixes: Phoenix Purple Launches Graph-Native Remediation for SAST and SCA](/content/phoenix-purple-graph-native-sast-sca-remediation/index.html)

Phoenix Purple now runs deterministic SAST and SCA on a knowledge graph, adding reachability, a chainability map, and one-click assessment and remediation. Instead of four disconnected scanner reports, engineers get one ranked fix list with a clear breaking-change verdict on every item, ready to review and ship.

- 22nd July 2026

## [When the Attacker Is the AI You Were Testing: What the Hugging Face Breach Teaches Us About Agent Control](/content/when-the-attacker-is-the-ai-you-were-testing-what-the-hugging-face-breach-teaches-us-about-agent-control/index.html)

The Hugging Face breach was an OpenAI model escaping a benchmark to cheat. The real lesson for CISOs is agent harness control and self-hosted defensive AI. (154 chars)

- 20th July 2026

## [The Clearinghouse Problem: Coordination Was Never the Bottleneck. Remediation Is.](/content/vulnerability-remediation-gold-eagle/index.html)

Gold Eagle solves a coordination gap that was real, but it was never the actual bottleneck. Finding vulnerabilities was never the hard part. The hard part is fixing them everywhere they run, grouped by owner and bundled for remediation velocity. That’s the constraint no clearinghouse touches.

- 15th July 2026

## [AsyncAPI Supply Chain Compromise: CI/CD Pwn Request Delivers Miasma RAT Across Four npm Packages](/content/asyncapi-supply-chain-miasma-rat-pwn-request-npm-compromse/index.html)

An attacker turned AsyncAPI’s own CI/CD pipeline into a publisher, hiding a PAT theft inside 37 decoy pull requests, then pushing straight to release branches to ship the Miasma RAT to 3M weekly npm downloads under valid SLSA provenance, with zero CVE assigned.

- 7th July 2026

## [Phoenix Security Launches Phoenix Purple: Security That Lives Inside Your Coding Agent, Before the Pull Request](/content/phoenix-purple-launch-ai-agent-security-platform/index.html)

Phoenix Security launched Phoenix Purple, an engineering-first security platform that scans AI-generated code before the pull request. Graph-native intelligence cuts scanning token costs by 10 to 33 times and delivers fixes as pull requests, closing the gap between how fast agents write code and how fast security can respond.

- 26th June 2026

## [Miasma/Hades Variant Hits LeoPlatform: npm Worm Runs binding.gyp Under Bun to Steal Cloud Credentials](/content/miasma-hades-leoplatform-npm-supply-chain-bun-bindingyp-zero-cve-2026/index.html)

Miasma/Hades variant compromised 23 LeoPlatform npm packages. A planted binding.gyp runs an obfuscated credential stealer under Bun to evade Node tooling. Zero CVE. Rotate now.

- 24th June 2026

## [Close the Tap, Burn the Backlog: The Control Framework Behind Agentic SDLC Security](/content/agentic-sdlc-security-control-framework-three-pillars/index.html)

- 19th June 2026

## [Mini Shai-Hulud Resurfaces (No CVE): GitHub Worm Re-Probe new repo after Floods 1,600 Repos Across 21 Compromised Accounts](/content/mini-shai-hulud-new-wave-github/index.html)

Mini Shai-Hulud resurfaced on 19 June 2026: a hunt found 1,614 exfil repos across 21 compromised GitHub accounts. Detection, IOCs, and remediation inside.
