Incidentnpm File Overwrite Flaw: CVE-2019-16775
On December 11, 2019, security researcher Daniel Ruf disclosed a vulnerability that allowed any malicious npm package to overwrite arbitrary files on your system during installation. No exploit code w
Expert perspectives on application security, compliance, and emerging threats
IncidentOn December 11, 2019, security researcher Daniel Ruf disclosed a vulnerability that allowed any malicious npm package to overwrite arbitrary files on your system during installation. No exploit code w
GeneralYour organization just bought an AI code review tool. Now someone in leadership is asking why you still need manual peer review at all. If the AI catches the bugs, why slow down deployment with human
IncidentWhat Happened On February 9, 2021, security researcher Alex Birsan disclosed a dependency confusion attack that compromised build systems at 35 organizations, including major technology companies. The
GeneralYou ve probably heard the pitch: point an AI coding agent at your legacy Spring Boot 2.7 codebase, and watch it handle the upgrade to Spring Boot 3 or 4. No more manual refactoring. No more dependency
Get weekly security insights and compliance updates delivered to your inbox.
IncidentWhat Happened On January 18, 2022, security researchers disclosed CVE-2022-24348 , a directory/path traversal vulnerability in Argo CD, a continuous delivery platform used to automate Kubernetes deplo
GeneralScope This guide focuses on transitioning from traditional line-by-line code reviews to intent verification systems for teams facing AI-generated code bottlenecks. You ll find specific steps for imple
IncidentWhat Happened Socket discovered 19 compromised packages on PyPI, downloaded hundreds of thousands of times, delivering malware designed to steal developer credentials. These packages targeted scientif
GeneralThe Conventional Wisdom Speed wins. Deploy faster, iterate quicker, ship more features. The data seems clear: project deployment rates jumped from 357 per month in 2021 to 988 per month in 2025. AI ad
IncidentOn December 18, 2024, security researchers disclosed a vulnerability in Microsoft Visual Studio Code that allowed attackers to steal GitHub OAuth tokens with a single user click. This attack exploited
IncidentWhat Happened Imperva researchers discovered two command injection vulnerabilities in Snyk s CLI and IDE plugins, both rated CVSSv3 5.8. These flaws allowed attackers to execute arbitrary code when de
IncidentA compromised Red Hat employee GitHub account led to malicious code being published across at least 32 npm packages under the @redhat-cloud-services namespace. These packages, with roughly 80,000 comb
IncidentWhat Happened Between April and May 2026, attackers compromised Red Hat s GitHub credentials and injected malicious code into npm packages maintained by the company. The malware, dubbed Miasma: The Sp
IncidentWhat Happened Three years after Log4Shell was disclosed, 21% of companies still run projects with this critical vulnerability. Spring4Shell fares worse: 35% of companies haven t patched it. This isn t
IncidentOn December 4, 2024, attackers published malicious versions of Ultralytics, a widely-used Python library for YOLO object detection models, to the Python Package Index (PyPI). The attack exploited GitH
IncidentWhat Happened In early 2024, an attacker with write access to the tj-actions/changed-files repository modified the GitHub Action to expose encrypted secrets in plaintext within workflow logs. This Act
ResearchYour build just failed. Someone on the team installed a package that looked legitimate but turned out to be malware. Now you re fielding questions in three different Slack channels while trying to fig