Shai-Hulud, Axios, Keyv — the endless supply chain incidents kept SOC teams busy. This post steps back to look at npm supply chain attacks through a SOC lens: where a poisoned package actually lands, the TTPs behind the campaigns, and what you can realistically detect with the telemetry you already collect.
AI coding agents run with broad system privileges and generate a stream of EDR telemetry that is hard to interpret. This post maps each agent tool call to its host-level footprint — process, file, and network — across Claude Code and OpenCode, and explains where EDR visibility holds up and where it breaks down.
I am taking 18351: Full-Stack Software Development for Engineers, offered by Prof. Hakan Erdogmus this semester. The course project involves developing a web application named YACA (Yet Another Chat App). This application allows users to register, login, manage a friend list, invite other friends, and engage in group chats.