npm Supply-Chain Worm and AI Agents Hacking Agents Put Open Source Security to the Test
Today’s panel tackles open source supply-chain security as its top story. Mike Vizard hosts Techstrong Gang with guests Jack Gold, Drew Gutstein, and Robert Reeves. The panel also covers cyber resilience and LinkedIn social engineering. Each topic carries real consequences for security teams this week.
Open Source Supply-Chain Security Under Fire
A fast-moving worm called Shai-Hulud has infected npm packages with 2 billion monthly downloads. It spreads by stealing publish credentials and republishing itself downstream. Amazon researchers also linked a North Korea-backed group to multiple open source supply-chain attacks. Nation-states now treat package ecosystems as a primary attack surface. Researchers separately documented the first known case of one AI agent hacking another AI agent. This previews what agent-to-agent trust failures look like in production. RapidFort now extends open source security coverage into runtime environments, not just build-time scans. Open source security faces a hard question: can the ecosystem save itself, or has the trust model already broken?
The Trouble With Cyber Resilience
A new analysis argues it’s past time to rethink cyber resilience as a continuous operating posture. Teams should stop treating it as a periodic checklist. Vendors are racing to close that gap. Commvault now taps into Google threat intelligence to fuse backup and recovery data with real-time threat signals. The panel weighs whether bolting intelligence feeds onto existing platforms actually improves resilience. Or does it just add another dashboard nobody has time to watch?
Loose LinkedIn Lips and Social Engineering
Researchers revisited the original Robin Sage experiment two decades later. They found LinkedIn still wide open to impersonation. The new writeup, Robin Sage 2.0: How LinkedIn Became a Counterintelligence Battlefield, shows how AI-generated personas evade detection. These fake connection requests are far harder to spot than the original 2010 test. Security teams need to treat professional network reconnaissance as a real threat vector, not a nuisance.
These three threads land in the same place: trust is breaking down faster than governance can keep up. That holds true whether it’s a software package, a security agent, or a LinkedIn connection request. Open source security, cyber resilience, and social engineering all demand the same discipline. Watch the full conversation for the panel’s take on what actually holds up next.