
- Osmond van Hemert — Senior Software Engineer/
- Blog Categories: AI, Security, Development & Infrastructure/
- Security/
Security


The Proof-of-Concept That Became Real — AI Worms and the Autonomous Threat Landscape
·2333 words·11 mins
Researchers at the University of Toronto have demonstrated a working proof-of-concept: an AI worm that autonomously reasons about its environment, generates attack strategies, and replicates itself without human intervention. It operates entirely on open-weight local models. This is no longer theoretical.

Anthropic's AI Vulnerability Discovery Framework — Automating Security at Code Level
·1742 words·9 mins
Anthropic released an open-source framework for automated vulnerability discovery powered by AI. This represents a fundamental shift in how security analysis can scale — from manual expert review to AI-assisted code hardening at development time.

TanStack NPM Supply Chain Compromise — Postmortem, Attack Vectors, and How to Protect Your Projects
·2143 words·11 mins
A massive npm supply chain attack compromised TanStack, Mistral AI’s client library, and over 170 packages. Here’s what happened, how the attack worked, and the practical steps you should take today to protect your projects.

Supply Chain Malware in PyTorch Lightning — When AI Infrastructure Becomes the Attack Surface
·1190 words·6 mins
A Dune-themed malware campaign targeting the PyTorch Lightning library highlights how AI/ML supply chains are becoming prime targets for sophisticated attacks.

The xz Utils Aftermath — One Year Later, What Have We Actually Fixed?
·1213 words·6 mins
Nearly two years after the xz Utils backdoor shocked the open source world, the supply chain security landscape has changed — but not enough.

Software Supply Chain Security Gets Serious — SLSA and SBOM Adoption Accelerates
·1231 words·6 mins
Supply chain security frameworks like SLSA and SBOM requirements are moving from recommendations to mandates. Here’s what developers need to know about the shifting landscape.

Post-Quantum Cryptography — The Migration Clock Is Ticking
·841 words·4 mins
NIST’s post-quantum cryptography standards are finalized, and the migration timeline is no longer theoretical — it’s operational.

Ultralytics Supply Chain Attack — When Your Dependencies Bite Back
·969 words·5 mins
A supply chain attack on the popular Ultralytics YOLO package highlights the persistent vulnerability of the Python ecosystem’s distribution pipeline.

The Zero-Day Treadmill — Why Patch Tuesday Still Matters in 2025
·888 words·5 mins
November’s Patch Tuesday brought critical zero-days being actively exploited, reminding us that patch management is still the unglamorous foundation of security.

Secure by Design — CISA's Push Is Finally Gaining Real Traction
·843 words·4 mins
CISA’s Secure by Design initiative is moving from voluntary pledges to measurable industry impact, and software vendors are starting to feel the pressure.

EU ChatControl Is Back — And It's Still a Terrible Idea for Encryption
·1074 words·6 mins
The EU’s latest push to scan encrypted messages reignites the fundamental debate about whether governments can mandate backdoors without destroying security for everyone.