security
TeamPCP deploys CanisterWorm on NPM following Trivy compromise
https://www.aikido.dev/blog/teampcp-deploys-worm-npm-trivy-compromise
Added 22 hours ago
Switzerland built an alternative to BGP. Nobody noticed • The Register
https://www.theregister.com/2026/03/17/switzerland_bgp_alternative/
Added 2 days ago
VulHunt: Open-source vulnerability detection framework - Help Net Security
https://www.helpnetsecurity.com/2026/03/16/vulhunt-open-source-vulnerability-detection-framework/
Added 4 days ago
I found 39 Algolia admin keys exposed across open source documentation sites
https://benzimmermann.dev/blog/algolia-docsearch-admin-keys
Added 1 week ago
Bucketsquatting is (finally) dead
https://onecloudplease.com/blog/bucketsquatting-is-finally-dead
Added 1 week ago
Google closes deal to acquire Wiz
https://www.wiz.io/blog/google-closes-deal-to-acquire-wiz
Added 1 week ago
Wikipedia was in read-only mode following mass admin account compromise
https://www.wikimediastatus.net
Added 2 weeks ago
A GitHub Issue Title Compromised 4k Developer Machines
https://grith.ai/blog/clinejection-when-your-ai-tool-installs-another
Added 2 weeks ago
The Israeli Spyware Firm That Accidentally Just Exposed Itself
https://ahmedeldin.substack.com/p/the-israeli-spyware-firm-that-accidentally
Added 1 month ago
Sandwich Bill of Materials
https://nesbitt.io/2026/02/08/sandwich-bill-of-materials.html
Added 1 month ago
Windows Notepad App Remote Code Execution Vulnerability
https://www.cve.org/CVERecord?id=CVE-2026-20841
Added 1 month ago
The Day the Telnet Died
https://www.labs.greynoise.io/grimoire/2026-02-10-telnet-falls-silent/
Added 1 month ago
Microsoft open-sources LiteBox, a security-focused library OS
https://github.com/microsoft/litebox
Added 1 month ago
Opus 4.6 uncovers 500 zero-day flaws in open-source code
https://www.axios.com/2026/02/05/anthropic-claude-opus-46-software-hunting
Added 1 month ago
Show HN: Fence – Sandbox CLI commands with network/filesystem restrictions
https://github.com/Use-Tusk/fence
Added 1 month ago
Supply Chain Vuln Compromised Core AWS GitHub Repos & Threatened the AWS Console
https://www.wiz.io/blog/wiz-research-codebreach-vulnerability-aws-codebuild
Added 2 months ago
Ansible battle tested hardening for Linux, SSH, Nginx, MySQL
https://github.com/dev-sec/ansible-collection-hardening
Added 2 months ago
Years-old bugs in open source took out major clouds at risk • The Register
https://www.theregister.com/2025/11/24/fluent_bit_cves/
Added 3 months ago