<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Open-Source-Security on CuraSec</title><link>https://curasec.metacog.co.kr/tags/open-source-security/</link><description>Recent content in Open-Source-Security on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 27 Aug 2026 21:01:55 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/open-source-security/index.xml" rel="self" type="application/rss+xml"/><item><title>TeamPCP Supply Chain Hackers Charged in Australia</title><link>https://curasec.metacog.co.kr/insights/2026-08-27-alleged-teampcp-hackers-charged-in-australia-over-major-supp/</link><pubDate>Thu, 27 Aug 2026 21:01:55 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-27-alleged-teampcp-hackers-charged-in-australia-over-major-supp/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> The underlying March 2026 compromise of Trivy, Checkmarx KICS, and LiteLLM should have already triggered audits; this arrest adds no new technical detail, but serves as a reminder to verify those security scanner pipelines were cleaned and dependency provenance checked at the time.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> An arrest announcement with no new IOCs or TTPs published; useful as campaign context if the March supply chain incident is already in your threat intel library, but yields no new detection or hunt work today.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Confirms attribution and partial closure of a supply chain attack on widely-used DevSecOps tooling — a useful case study for board or risk-committee discussions on open-source software supply chain risk and the adequacy of your vendor/tooling provenance controls.&lt;/li>
&lt;/ul></description></item><item><title>Strip Mining Era of OSS Security: Supply Chain Risk Commentary</title><link>https://curasec.metacog.co.kr/insights/2026-07-13-welcome-to-the-strip-mining-era-of-oss-security/</link><pubDate>Mon, 13 Jul 2026 13:18:50 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-13-welcome-to-the-strip-mining-era-of-oss-security/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Opinion piece on how the OSS ecosystem is being systematically exploited — worth reading to frame dependency risk philosophy, but the thin summary offers no specific vulnerability, package, or hardening action to take today.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> The &amp;lsquo;strip mining&amp;rsquo; framing — extraction of value from OSS without reciprocal investment in its security — is useful context for board or risk-committee discussions about software supply chain posture, though no specific incident or regulatory trigger is present.&lt;/li>
&lt;/ul></description></item></channel></rss>