Subscribe to the Kusari monthly newsletter
Sign UpThe Kusari Edge

March
2026
ICYMI: Noteworthy Headlines 🗞️
Spring is here, and apparently so is every threat actor with a GitHub account. This month's supply chain news reads a bit like a heist movie full of stolen credentials and other trickery. The good news? The community is fighting back with offers of $12.5M in fresh funding and enterprise-grade tooling that's free for open source projects.
- Among the cascade of attacks that hit the software supply chain this month from the Trivy compromise, the LiteLLM incident is a big reminder that transitive dependency exposure is real and avoidable
- The CNCF and OpenSSF communities can secure their open source projects without needing to be security experts — Kusari Inspector available for free - https://kusari.cloud
- A chain of pain: prompt injection, cache poisoning, credential theft
Latest from Kusari

- AI coding assistants supercharge developer velocity; Kusari CTO Mike Lieberman breaks down how that speed comes with a 10x spike in security findings, and what engineering leaders can do before the debt compounds
- Did you know that your last vulnerability scan probably covered just 5% of your real risk surface? Kusari CEO Tim Miller highlights why transitive dependencies are the blind spot most teams miss
- 85% use AI to write code, only 38% use AI to support code review in pull requests; here's where "vibe coding" creates security challenges and how security teams can close them before they reach production
- Get the Kusari Research Report to learn what high-performing orgs do differently to secure their software supply chain
- If you've been curious about our solutions, we just launched a product tour — take two minutes to see what we do in action.
Upcoming Events 📣
- New interview from KubeCon Europe: What's in the SOSS? Podcast #57
- From Noise to Signal - Security Expertise and Kusari Inspector with Mike Lieberman
What’s up with GUAC? 🥑
- Major AI and cloud players have committed $12.5M in grant funding to be managed by Alpha-Omega and OpenSSF, for the purpose of securing open source software
Resource of the Month ⚒️
- This is worth bookmarking — ForkWatch scans forks of any GitHub project to surface fixes and patches that haven't made it back upstream
