software security
21 stories on software security, newest first, from 21 briefings. Each is a plain-language summary written here for Australian business, with a link to the original reporting.
- Google Warns: Attackers Are Targeting Your Software Build Pipelines
- CISA Unveils Plan to Improve Quality of Global Vulnerability Database
- npm Supply Chain Attack Exploits 'Trusted Publishing' to Smuggle Hidden Malware Loader
- AI Bug-Hunters Are Causing Patching Pain Now, But Could Ease the Load by 2027
- Critical GitLab Flaw Under Active Attack: Patch Now or Take Servers Offline
- AI-Powered Bug Hunting Is Flooding Vendors With Vulnerability Reports
- Why Fixing Vulnerabilities in Code Beats Patching in Production
- CISA Alerts Businesses to Actively Exploited Gitea Vulnerability
- OWASP Releases New Security Blueprint to Tackle Risks in AI Skills and Add-ons
- Critical Flaw in 'Isolated-vm' Tool Could Let Attackers Take Over Host Systems
- North Korean Hackers Linked to Malicious Rust Software Package
- Malicious Code Found in Popular Rust Software Libraries Used by Millions
- Critical Flaws Found in NASA Spacecraft Control Software Could Allow Unauthorized Commands
- Critical GitLab Vulnerability Under Active Attack — Patch Immediately
- Supply Chain Attack on LiteLLM Hits Over 2,500 Organizations
- AI-Powered Red Team Uncovers Critical Flaws in Bitcoin Software
- Critical Flaw in Paperclip Software Could Have Let Attackers Seize Admin Control
- AI-Assisted Audit Finds 85 Critical Flaws in Bitcoin Ecosystem Projects
- 77 Fake Extensions Caught Stealing Developer Data from Open VSX Marketplace
- Massive Supply Chain Attack Hits Over 400 NPM Software Packages
- Research Highlights Hidden Risk: How 'Pointer Leaks' Can Undermine Software Security