Supply chain attacks against the open source ecosystem soar by 650% – report
Dependency confusion has quickly become the attack technique of choice [...]
Dependency confusion has quickly become the attack technique of choice [...]
DevOps firm slammed for ‘abysmal’ incident response [...]
Email content injection flaws chained to bypass security controls [...]
Implementation bug discovered in certain clients and libraries [...]
Unconfirmed reports suggest Japanese multinational was hit by ransomware [...]
Defendant ordered to pay $30m in restitution to victims [...]
Hacktivists take aim at ‘Heartbeat Act’ with references to The Handmaid’s Tale and Rick-rolling meme [...]
‘Identical’ payload removed from GitHub after researcher’s complaints [...]
Block editor XSS and REST API data exposure issues among now-patched bugs [...]
CPU-level data leak technique still kicking, three years on [...]
The Top 10 list is an acclaimed guide to modern web application security threats [...]
Project maintainers patch integer overflow flaw that has various potentially damaging outcomes [...]
Vendor agrees that XSS bug poses a grave risk, but warns it ‘can’t force users to upgrade’ [...]
Developer reveals error-proofing improvements after delay to rollout of rapid fix [...]
‘Incomplete threat modelling’ blamed for credential forgery vulnerability [...]
Researchers showcase new method for improving the detection of fake websites [...]
Thousands of instances still vulnerable to Apache Struts-like flaw [...]
Server-side image conversion vector laid bare [...]
Nevada-based hospitality firm confirms cyber-attack on its networks [...]
Nationalities, birth dates, and passport numbers among potentially exposed data [...]
Open source project aims to offer ‘unlimited flexibility’ for security researchers [...]
Electronics retailer DNS issued the product recall after a security researcher published their findings last week [...]
Itel, DEXP, Irbis, and F+ mobile devices put under the microscope [...]
Update now to protect against authentication bypass flaw [...]
Attacker promises ‘data was not disseminated or sold to anyone’ [...]