Cover story
supply chain security
Bitwarden's npm incident was a publish-path compromise
Analysis of how a malicious Bitwarden CLI package bypassed source controls through npm registry compromise.
· Cantina
Cantina editorial
April 2026 65 stories
Intelligence for the new security frontier
Research, perspectives, and field notes from the people closing the loop on security.
Latest storiesDispatches
Analysis / Research / News
Application Security
05Production deployment context helps security teams prioritize alerts based on actual operational risk rather than severity alone.
Cantina
AI security
06Auto-approval settings for coding agents shift execution control boundaries and require careful policy definition before rollout.
Cantina
AI security
07GitHub's MCP server push protection now blocks secrets within agent sessions rather than at repository commit.
Cantina
MCP security
08Analysis of how untrusted input reaching MCP stdio configuration can enable local code execution attacks.
Cantina
OAuth
09Analysis of how Vercel's April 2026 security breach leveraged compromised third-party OAuth access through Google Workspace to reach deployment control-plane configuration.
Cantina
healthtech security
10Security incidents in healthtech are now judged like operational failures, making continuity protection equally important as data protection.
Cantina
OpenSSH
11OpenSSH 10.3p1 fixes two vulnerabilities rooted in decades-old trust assumptions from Berkeley rcp.
Cantina
AI governance
12Framework for assessing AI agent governance readiness across inventory, permissions, approvals, logging, and incident response.
Cantina
Page 4 of 6 · 65 stories