Loading...

Tag trends are in beta. Feedback? Thoughts? Email me at [email protected]

Upcoming breaking changes for npm v12

For the 2nd time in weeks, Microsoft packages laced with credential stealer

Did Claude increase bugs in rsync?

Pwnd Blaster: Hacking your PC using your speaker without ever touching it

Reuse Less Software

The Quiet Numbers Station: Decoding Nineteen Years of GPS Cryptography

Twenty One Zero-Days in FFmpeg

1-Click GitHub Token Stealing via a VSCode Bug

Arbitrary code execution in objdump -g

The Quiet Numbers Station: Decoding Nineteen Years of GPS Cryptography

Over 900 Arch Linux Packages Infected with infostealers and rootkits

A Human in Control

Full Disclosure: 1-Click GitHub Token Stealing via a VSCode Bug

Red Hat npm Packages Compromised to Spread a Credential-Stealing Worm

Codex Discovered a Hidden HTTP/2 Bomb

Config Files That Run Code: Supply Chain Security Blindspot

Arch Linux Now Believes Malware Incident Under Control: More Than 1,500 Packages

AI Worm

New IronWorm malware hits 36 packages in NPM supply-chain attack

Malicious Packages Spreading in AUR

TrustZone Intermezzo: Broken OP-TEE Memory Isolation on i.MX 8M

Unicode composition for filenames (2008)

AI Worm

Running Python code in a sandbox with MicroPython and WASM

Microsoft Defender 'RoguePlanet' Zero-Day Grants SYSTEM Privileges

Vulnerability and malware checks in uv

On Reading SRAMs in IR Images, and Establishing Bounds on Trust

Dancing mad with sandboxing

CVE-2026-45257: LPE in FreeBSD via kTLS-RX

WhatsApp Catches Spyware Firm NSO Defying No-Hacking Court Order

More →