Entries by Website Administrator

Behavioral Risk Brief: Arch AUR Repository

The Claim Governance frameworks that treat package adoption as a routine maintenance mechanism create systemic risk when that same mechanism can transfer control of a trusted package name to an attacker. Zero Trust for Code addresses this by requiring a pre-execution trust decision on what a package does after any change in control, rather than extending […]

Behavioral Risk Brief: Joyfill npm Packages

The Claim Governance frameworks that treat install-script restrictions as sufficient protection create systemic risk when malicious code is embedded to execute at import rather than install. Zero Trust for Code addresses this by requiring a pre-execution trust decision on what a package does when it runs, regardless of which lifecycle stage triggers that behavior. The […]

Behavioral Risk Brief: Notepad ++

The Claim Governance frameworks that treat a legitimate, signed application as inherently safe create systemic risk when that application can be paired with malicious components it will execute automatically. Zero Trust for Code addresses this by requiring a pre-execution trust decision on what an application actually loads and runs, rather than extending trust to everything […]

Why Machine-Speed Development Needs Machine-Speed Security Decisions

When Code Installs Itself, Trust Decisions Have to Move Upstream CodeHunter CEO Ken Ammon has a new piece in the Forbes Technology Council, “Supply Chain Attacks Are Forcing Threat Detection To Focus On What Code Can Do.” His argument: the way most enterprises decide whether software should run was built for a slower world, and […]

Stephen McCarney Joins CodeHunter as Chief Strategy Officer

CodeHunter has named Stephen McCarney as Chief Strategy Officer, adding a go-to-market leader with a track record of scaling category-defining security companies to help expand Zero Trust for Code across enterprise and government markets. McCarney will lead corporate strategy, market expansion, strategic partnerships, and go-to-market execution as CodeHunter builds out its footprint across software supply […]

Behavioral Risk Brief: AI Data Thieves

The Claim Governance frameworks that treat marketplace listing or basic scanning as sufficient validation create systemic risk when agentic systems execute functionality without independent behavioral verification. Zero Trust for Code addresses this by enforcing behavioral controls at execution, ensuring that what an AI skill or agent-based artifacts does is verified rather than assumed from where […]

Behavioral Risk Brief: PolinRider Campaign

The Claim Governance frameworks that treat software supply chains as trusted by default create systemic risk when trust can be transferred, inherited, or re-established without independent validation. Zero Trust for Code addresses this by enforcing behavioral controls at execution, ensuring that trust is continuously verified rather than carried forward from prior assumptions. The Incident North […]

Behavioral Risk Brief: New Avalon Framework

The Claim When credential theft, lateral movement, persistence, and ransomware deployment are governed as isolated risks, organizations lose sight into how those activities play into business-impacting outcomes. Zero Trust for Code addresses this by enforcing behavioral policy across execution sequences, ensuring that software actions remain constrained regardless of where they occur within the attack chain. […]