Loading...

Tag trends are in beta. Feedback? Thoughts? Email me at [email protected]

I almost got hacked by a 'job interview'

Date bug in Rust-based coreutils affects Ubuntu 25.10 automatic updates

Foreign hackers breached a US nuclear weapons plant via SharePoint flaws

First Self-Propagating Worm Using Invisible Code Hits OpenVSX and VS Code

CamoLeak: Critical GitHub Copilot Vulnerability Leaks Private Source Code

A modern approach to preventing CSRF in Go

A Retrospective Survey of 2024/2025 Open Source Supply Chain Compromises

Nine HTTP Edge Cases

Email bombs exploit lax authentication in Zendesk

Rubygems.org AWS Root Access Event – September 2025

1Password CLI Vulnerability (2023)

Element: setHTML() method

Red Hat Investigating Breach Impacting as Many as 28,000 Customers, Including the Navy and Congress

F5 Says Hackers Stole Undisclosed BIG-IP Flaws, Source Code

How Minecraft servers can track you across accounts and IPs using resource packs

F5 Says Nation-State Hackers Stole Source Code and Vulnerability Data

I spent a year making an ASN.1 compiler in D

TARmageddon (CVE-2025-62518) highlights the challenges of open source abandonware

Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]

A major evolution of Apple Security Bounty

Ksmbd – Exploiting CVE-2025-37947

Mouse Sensors Can Pick Up Speech From Surface Vibrations, Researchers Show

I Cheated At Poker By Hacking A Casino Card Shuffling Machine

Redis Warns of Critical Flaw Impacting Thousands of Instances

What’s the problem with pipe-curl-into-sh?

Pointer leaks through pointer-keyed data structures

Pwning the Nix ecosystem

Secure Boot Bypass Risk Threatens Nearly 200,000 Linux Framework Laptops

CI/CD components to generate and verify provenance attestation

What’s your go-to strategy for giving engineers access to production?

More →