TechReaderDaily.com
TechReaderDaily
Live
Magnus Subramani
Home  /  Newsroom  /  Magnus Subramani

Magnus Subramani

Security Correspondent

Magnus Subramani covers cybersecurity for TechReaderDaily — the breaches, the disclosures, and the long tail of footguns that nobody reads about. Oslo-based. He is the reason your CISO has read TRD this morning.

19 articles published Oslo, Norway
  • supply-chain attacks (npm, PyPI, container-base images)
  • appsec and the SAST/DAST/runtime triad
  • ransomware economics and disclosure practices
  • identity and the post-password landscape (passkeys, WebAuthn)
  • the AI-prompt-injection threat surface

Latest from this reporter

Diagram illustrating how the Shai-Hulud worm propagates through npm package dependencies and build pipelines. Security · Supply Chain

Open-Source Supply Chain Attack Sweeps npm, PyPI, Docker in 48 Hours

In May 2026, a worm named Mini Shai-Hulud poisoned npm, PyPI, and Docker Hub packages, stole 3,800 GitHub repositories, and exposed the open-source supply chain's biggest vulnerability: real signing keys can belong to fake publishers.

Jun 23, 2026 · 9 min
Software · Application Security

SAST, DAST, and Runtime Testing Converge in AI-Powered Pipeline

Within eight weeks, Anthropic and OpenAI released free AI reasoning scanners, Invicti introduced DAST-to-SAST correlation, and Waratek embedded runtime verification in IDEs, converging the three pillars of application security testing at pipeline speed.

Jun 8, 2026 · 10 min
Application Security · Testing

Invicti DAST-to-SAST Correlation Signals AppSec Triad Shift

As vendors race to connect static, dynamic, and runtime security into a single application security triad, Invicti’s new DAST-to-SAST correlation aims to trace vulnerabilities to source code and test whether these integrations hold up under real workload pressure.

May 24, 2026 · 10 min
Diagram illustrating the agentic AI attack surface inside an enterprise network, showing multiple entry vectors including prompt injection, tool misuse, and identity compromise. Security · Threat Surface

Prompt Injection Attacks 3 Coding Agents; System Card Predicted It

The new threat surface moves from guardrails to agent actions, as a single prompt injection can hijack coding agents to exfiltrate secrets, push malicious code, and delete databases, yet the disclosure machinery lags behind.

May 14, 2026 · 9 min
Infographic showing the top 10 ransomware attacks of 2025 with attack vectors and affected sectors highlighted. Security · Threat Economy

Ransomware Payments Drop 35% as Threat Economy Shifts

Fewer ransomware victims are paying, but groups are now targeting industrial sectors and running fraud operations, creating new disclosure gaps in industries that have never faced cyber reporting rules.

May 14, 2026 · 8 min
Screenshot of the Xint Code AI platform interface showing vulnerability analysis results across a large codebase. Software · Application Security

SAST-DAST Gap Finally Closes with AI and Pipeline Correlation

After two decades of separate vulnerability findings from static and dynamic testing, three 2026 announcements from Invicti, Anthropic, OpenAI, and Theori use AI and pipeline-speed correlation to finally reconcile them.

May 13, 2026 · 9 min
Infographic illustrating data center infrastructure defense strategies against ransomware attacks Security · Disclosure

Ransomware Economy Costs Rise as Victims Stay Silent

Ransomware-as-a-service platforms lower the barrier to entry as a negotiator pleads guilty to colluding with BlackCat, exposing the growing chasm between breach detection and public disclosure.

May 13, 2026 · 9 min
A diagram illustrating how static application security testing fits into the software development lifecycle from code through build, test, and deployment stages Application Security · Testing

Invicti Launches DAST-to-SAST Correlation as AI Reshapes AppSec

With Invicti's April 2026 release and free LLM code scanners from Anthropic and OpenAI, a decade of frustration over disjointed application security testing is giving way to rapid integration, making runtime-to-source correlation a likely industry standard.

May 12, 2026 · 9 min
Diagram illustrating how a prompt injection attack is carried out against an AI agent, showing the attacker embedding malicious instructions within content the agent retrieves. Security · AI Threat Surface

Prompt Injection Attacks Now Hit AI Agents in the Wild

Google's security team scanned billions of web pages and found active payloads targeting enterprise AI agents, revealing a vast attack surface of crude but effective threats that defenders are racing to secure.

May 11, 2026 · 9 min
New Era of Supply Chain Attacks: Python Developers Hacked Security · Supply Chain

Supply Chain Attacks Target Developer Workstations in 2026

From a backdoored Daemon Tools installer to a Linux RAT that steals SSH keys, attackers are now targeting developer workstations to steal code-signing credentials and push trusted updates.

May 10, 2026 · 8 min
CVE-2026-21520 | Copilot Studio Information Disclosure Vulnerability Security · Threat Surface

Prompt Injection Bypasses Patched CVE-2026-21520 in Copilot Agents

Capsule Security's retest of a Microsoft-patched Copilot Studio agent proved that prompt injection still exfiltrates data, exposing the same attack surface across AI coding agents, autonomous SOC tools, and web-navigating assistants.

May 9, 2026 · 4 min