Entries by Website Administrator

Behavioral Risk Brief: Malicious .git Configs

Governance frameworks that treat workspace-trust prompts and sandboxing as sufficient protection create systemic risk when an agent’s own routine background operations bypass both entirely. Zero Trust for Code addresses this by requiring a pre-execution trust decision on every command a repository can trigger, not only the ones a user’s approval prompt was designed to catch. […]

Behavioral Risk Brief: WEL1DROPPER

The Claim Governance frameworks that rely on manual code review to catch malicious packages create systemic risk when an artifact is deliberately built to survive that review. Zero Trust for Code addresses this by requiring a pre-execution trust decision on what a package does when invoked, rather than solely depending on a reviewer’s judgment of what […]

Behavioral Risk Brief: Arch AUR Repository

The Claim Governance frameworks that treat package adoption as a routine maintenance mechanism create systemic risk when that same mechanism can transfer control of a trusted package name to an attacker. Zero Trust for Code addresses this by requiring a pre-execution trust decision on what a package does after any change in control, rather than extending […]

Behavioral Risk Brief: Joyfill npm Packages

The Claim Governance frameworks that treat install-script restrictions as sufficient protection create systemic risk when malicious code is embedded to execute at import rather than install. Zero Trust for Code addresses this by requiring a pre-execution trust decision on what a package does when it runs, regardless of which lifecycle stage triggers that behavior. The […]

Behavioral Risk Brief: Notepad ++

The Claim Governance frameworks that treat a legitimate, signed application as inherently safe create systemic risk when that application can be paired with malicious components it will execute automatically. Zero Trust for Code addresses this by requiring a pre-execution trust decision on what an application actually loads and runs, rather than extending trust to everything […]

Why Machine-Speed Development Needs Machine-Speed Security Decisions

When Code Installs Itself, Trust Decisions Have to Move Upstream CodeHunter CEO Ken Ammon has a new piece in the Forbes Technology Council, “Supply Chain Attacks Are Forcing Threat Detection To Focus On What Code Can Do.” His argument: the way most enterprises decide whether software should run was built for a slower world, and […]

Stephen McCarney Joins CodeHunter as Chief Strategy Officer

CodeHunter has named Stephen McCarney as Chief Strategy Officer, adding a go-to-market leader with a track record of scaling category-defining security companies to help expand Zero Trust for Code across enterprise and government markets. McCarney will lead corporate strategy, market expansion, strategic partnerships, and go-to-market execution as CodeHunter builds out its footprint across software supply […]