software-security
31 articles with this tag
CRITICAL
INFO
INFO
MEDIUM
INFO
INFO
INFO
INFO
CRITICAL
INFO
INFO
INFO
MEDIUM
HIGH
INFO
INFO
HIGH
INFO
INFO
HIGH
INFO
HIGH
CRITICAL
LOW
LOW
MEDIUM
INFO
CRITICAL
INFO
INFO
INFO
npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks
pnpm 11 Might Finally Be a Better Default Than npm
Securing The AI Revolution How Snyk And Our Partners Are Scaling For The Future
[NEU] [mittel] Adobe Creative Cloud Applikationen: Mehrere Schwachstellen
Postmortem: TanStack npm supply-chain compromise
Securing CI/CD for an open source project: lessons from Cilium
Boost Security acquires 2 startups, raises $4 million for AI defense platform
Project Glasswing Proved AI Can Find the Bugs. Who's Going to Fix Them?
Oracle Critical Patch Update, April 2026 Security Update Review
AI Hype vs. Reality: Is AI Really Rewriting the Vulnerability Equation?
Nasa CFITSIO Fuzzing: Memory Corruptions and a Codex-Assisted Pipeline
Fracturing Software Security With Frontier AI Models
[NEU] [mittel] Sparx Systems Enterprise Architect: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and More
A new initiative that brings together Amazon Web Services, Anthropic, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks in an effort to secure the world’s most critical software.
Year in Review: Vulnerabilities old and new and something React2
Software supply chain hacks trigger wave of intrusions, data theft
The Next Era of AppSec: Why AI-Generated Code Needs Offensive Dynamic Testing
Google Paid Out $17 Million in Bug Bounty Rewards in 2025
Vulnérabilité dans GLPI (12 mars 2026)
If consequences matter, they should apply to vendors, too
We (at Tachyon) found an auth bypass in MLflow
Patch, track, repeat: The 2025 CVE retrospective
Security debt is becoming a governance issue for CISOs
Your dependencies are 278 days out of date and your pipelines aren’t protected
I used MCP Ghidra and Claude Code to find 9 kernel driver vulnerabilities on my gaming laptop
Claude Code Security Shows Promise, Not Perfection
CISA Confirms Active Exploitation of FileZen CVE-2026-25108 Vulnerability
Black Duck expands Polaris platform with unified, automated security across all major SCMs
White House Scraps ‘Burdensome’ Software Security Rules
We moved fast and broke things. It’s time for a change.