CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq

Are we self-sovereign PKI yet?

ACME CAA Extensions to Become Mandatory

Megalodon: Mass GitHub Repo Backdooring via CI Workflows

Postmortem: TanStack NPM supply-chain compromise

Dependency cooldowns are unfair; we should use phased rollouts instead

Score by Collisions, Patch by Panic

I Do Not Recommend Bitwarden

Package Manager CWEs

the may 2026 fedi software vulnerability