open source security
21 stories on open source security, newest first, from 23 briefings. Each is a plain-language summary written here for Australian business, with a link to the original reporting. Where several outlets covered the same event, the rest sit under it as extra coverage.
- Malicious Terraform Providers and Go Modules Used to Spread North Korea-Linked Malware
- Fake 'Twilio Bug Bounty' npm Package Caught Stealing Developer Credentials
- Malicious npm Package Skips Install Scripts, Hides Malware in Application Code Instead
- New 'WeaselBiscuit' Malware Found Hidden in 13 npm Packages Targeting Developers
- Malicious Packagist Packages Found Targeting Unpatched iPhones to Steal Crypto Wallet Data
- Two Australians Charged Over Alleged TeamPCP Supply Chain Hacking Attacks
- Two Australian Men Arrested Over 'TeamPCP' Software Supply Chain Attacks
- Two Alleged Members of 'TeamPCP' Hacking Group Arrested in Australia
- AI-Powered Backdoor Hidden in Fake npm Packages Targets Linux Systems
- AI Model Update Boosts Automated Vulnerability Scanning for Businesses
- Critical Flaw Found in Popular JavaScript Sandbox Tool 'isolated-vm'
- Fake RubyGems Packages Caught Stealing Browser Data and Crypto Wallets
- Brief but Dangerous: Malicious LiteLLM Package May Have Hit 2,100+ Organisations
-
BTCPay Server Backers Offer 3 BTC Bounty Following Critical Exploit
Also covered by The Block
- Nearly 800 Fake npm Packages Caught Spreading Malware Across Windows, Mac and Linux
- Volunteer Hackers Uncover Nearly 5,000 Flaws in Bitcoin Software After Wallet Hack
-
Bitcoin Ecosystem Audit Uncovers Nearly 5,000 Security Flaws
Also covered by Cointribune
- Volunteer Security Sweep Uncovers Nearly 5,000 Issues in Bitcoin Software
- Bitcoin Red Team Uncovers 85 Critical Bugs Across 390 Open Source Projects
- AI-Powered Scanning Uncovers Over 14,000 Hidden Flaws in Open-Source Software
- PipeWire Flaw Lets Attackers Escape Linux Sandboxes via Audio Access