Articles
The polyfill.io Supply-Chain Attack — Every Script Tag Is a Trust Decision
The polyfill.io CDN is injecting malicious code into 100,000+ sites. What happened, why SRI didn't save anyone, and how to defend against the next one.
The xz Backdoor: A Multi-Year Con Caught by Half a Second of Latency
A backdoor in xz-utils 5.6.0 and 5.6.1 targeted sshd on Linux. What we know three days in, how to check your systems, and why a slow login mattered.
Kaseya VSA: When the Tool That Manages Everything Gets Hit
Ransomware pushed through Kaseya VSA over a holiday weekend reached businesses via their IT providers. What agencies and small teams should check now.
SolarWinds Orion: When the Monitoring Tool Is the Way In
A trojanized Orion update reached thousands of networks. What we know so far, and what it means for any tool that holds the keys to your infrastructure.
left-pad and the Fragility of Your Dependency Graph
Eleven lines of JavaScript vanished from npm last week and broke builds worldwide. What left-pad teaches about dependencies, pinning and build pipelines.
More topics
Get notified when CompleteStatus opens
New accounts are closed while we're in private beta. Leave your email and we'll send one message the moment sign-ups open — nothing else.