IncidentBackdoored Rust Packages on Crates.io
On August 20, malicious versions of three Rust packages appeared on crates.io . These packages contained backdoors that executed during the build process, before your code ever ran. One of the comprom
Expert perspectives on application security, compliance, and emerging threats
IncidentOn August 20, malicious versions of three Rust packages appeared on crates.io . These packages contained backdoors that executed during the build process, before your code ever ran. One of the comprom
IncidentOn August 20, 2026, Broadcom released 91 CVEs affecting Spring Framework and related projects. Not over a quarter. Not spread across a month. In a single disclosure event. Sonatype s analysis identifi
IncidentRecently, malicious code was pushed to three popular Rust crates with a combined 245 million downloads. The Rust Security Response Team removed them 86 to 107 minutes later. Here s what failed, what w
IncidentOn August 20, 2024, at 01:17 UTC, attackers compromised the maintainer account for arrayref, a Rust crate with over 53 million downloads in the prior 90 days. Within 90 minutes, they published three m
Get weekly security insights and compliance updates delivered to your inbox.
IncidentA web interface that sends commands to spacecraft had no authentication requirement. For nearly a decade, NASA s Advanced Multi-Mission Operations System (AMMOS) Instrument Toolkit Graphical User Inte
IncidentWhat Happened A critical vulnerability in isolated-vm , a widely-used Node.js library designed to run untrusted JavaScript in isolated V8 contexts, allowed sandboxed code to escape containment and cor
IncidentIn June 2024, Adversa researchers discovered a significant vulnerability: they could trick Grok into executing malicious instructions by hiding them inside AES-256-GCM encrypted payloads. The AI model
IncidentOn August 3, 2024, Patchstack disclosed CVE-2026-32475 , a remote code execution vulnerability in Elementor Pro s File Upload module. The flaw affected all versions before 4.2.2. Here s what happened
IncidentIf you re running untrusted code in a JavaScript sandbox, you need to know about a recent vulnerability in one of the most popular isolation libraries. The isolated-vm package, downloaded over 1 milli
IncidentCISA recently added a critical vulnerability in MLflow to its Known Exploited Vulnerabilities catalog. This flaw allows server-side request forgery (SSRF) attacks, enabling attackers to access interna
GeneralYou ve built a fortress. Your most sensitive systems sit behind an air gap, physically isolated from the internet. No inbound connections, no outbound data leaks, no remote attacks. The compliance box
IncidentThe Mabna Institute, an Iranian cybersecurity firm, compromised around 8,000 accounts by targeting over 100,000 university and research accounts worldwide. This wasn t due to a zero-day exploit or sop
IncidentWhat Happened Researchers executed a Spectre attack against Cloudflare Workers, extracting a JSON Web Token (JWT) from a co-located worker process at 12 bits per second. The attack exploited speculati
IncidentWhat Happened Developers using the Ray distributed computing framework locally were targeted by remote code execution attacks via their web browsers. The vulnerability, CVE-2025-62593, exploited Ray s
IncidentOn June 18, Snowflake merged PR#1218 into their GitHub Actions pipeline. This pull request contained a vulnerability that exposed internal Jira credentials. During development, GitHub Copilot reviewed
IncidentWhat Happened Between January and December 2024, software development teams using AI-assisted coding tools saw a significant shift. They reduced their median vulnerability age by 59%. Teams triaged fa