Upwind’s Runtime Vulnerability Management
Contents
Further Reading

Keyv Supply Chain Compromise: An npm Worm That Takes Its Orders From an Ethereum Smart Contract
Executive Summary On August 4, 2026 at 09:35 UTC, [email protected] was published to npm carrying a credential stealer, an npm worm, and a persistence mechanism designed to detonate during incident response. Keyv ranks #274 by npm reach and is present in 84,759 customer environments, and the release shipped with valid GitHub OIDC provenance and a…

Upwind Code Brings Cloud Security Into the Development Control Plane
Cloud applications begin long before they reach the cloud. Source code, open-source dependencies, infrastructure definitions, container images and pull requests all shape what will eventually run in production. Yet these layers are often secured separately. Software Composition Analysis (SCA) tools inspect dependencies, Infrastructure as Code (IaC) scanners inspect configuration files, container scanners inspect artifacts and…

Building Autonomous Cloud & AI Security
How Upwind’s Agentic Pack uses NVIDIA Nemotron 3 Super and NVIDIA garak agent breaker probe to continuously validate cloud posture, attack surfaces, and AI applications. By: Avital Harel, Alon Saban, Yuval Elarat (Upwind). Eliya Cohen, Shiri Hochhauser, Orel Hazai (NVIDIA) Executive Summary AI-generated code, autonomous agents, MCP servers, and cloud-native architectures are transforming how software is…