
SamHouston (Veracode) asked a question.
How a Fintech Startup Secured its CI/CD Pipeline
During a massive npm spam flood, a trojanized logging utility nearly compromised a fintech startup’s CI/CD pipeline. Discover how Veracode blocked the malicious dependency pre-download, helping the team avoid a catastrophic breach and restore developer velocity in a single sprint.
-- Check out the Case Study here
How a Crypto Exchange Prevented a Targeted Supply Chain Attack
A major cryptocurrency exchange was targeted by a malicious PyPI “job scanner” tool designed to steal credentials and wallets. Learn how Veracode’s upstream controls and policy enforcement blocked the threat before it could be downloaded, protecting hiring workflows and preventing a costly breach.
How a SaaS Firm Prevented a Novel Ransomware Attack
An attacker published a malicious npm package masquerading as a legitimate AWS tool, using an image file to hide C2 instructions. Learn how Veracode’s multi-layered defense stopped the ransomware attack at the source, preventing widespread data encryption and service disruptions.
-- https://www.veracode.com/resources/case-studies/saas-firm-prevented-ransomware-attack/
How an E-commerce Giant Avoided a Trojanized Dependency Attack
Attackers published a typosquatted, trojanized version of a core UI library to steal session cookies and payment information from a major e-commerce platform. Find out how Veracode’s upstream controls blocked the attack, preventing a massive data breach and protecting revenue.
-- https://www.veracode.com/resources/case-studies/ecommerce-giant-avoided-typosquatting-attack/
.png)