Blogs

A Curated Collection of Writings, Research, and Solutions

Application Security

CodeQL Compromised: How Public Secret Exposure Led to an Attack

In March 2025, the cybersecurity community was rocked by a significant supply chain attack targeting a popular third-party GitHub Action, tj-actions/changed-files. This incident, tracked as CVE-2025-30066, has exposed vulnerabilities in up to 23,000 repositories.
April 2, 2025
5 Minutes
Read More
Data Protection

Addressing RBI's Guidelines for Digital Payment Applications with CleanStart

The Reserve Bank of India (RBI) has issued Master Directions on cyber resilience and digital payment system controls emphasizing a "Secure by Design" approach under application security for digital payment systems. This directive underscores the growing importance of robust security measures in India's fast-growing digital payments landscape. It also marks a significant shift toward integrating security at every stage of the software development lifecycle (SDLC). This isn't merely a compliance checkbox; it's a fundamental necessity in today's threat landscape. This blog explores the technical complexities of implementing the framework, addressing key challenges, and presenting CleanStart as a robust solution.
March 4, 2025
6 Minutes
Read More
Cyber Security

Empowering Development: Securing Software Supply Chain with CleanStart

In today's digital world, software supply chains are constantly under attack, which you often hear about in the news. At Triam Security, we believe developers shouldn't have to slow down to make things secure. We're all about finding new ways to make sure software stays safe without getting in the way of getting things done quickly. Whether you're just starting out or you're already deep into development, we're here to help every step of the way, offering support and expertise.
April 30, 2024
5mins read
Read More