Loading...

Tag trends are in beta. Feedback? Thoughts? Email me at [email protected]

Color NPM Package Compromised

Npm packages with over 1b weekly downloads, incl. Chalk, have been compromised.

Passkeys and Modern Authentication

Hackers hijack NPM packages with 2B weekly downloads in supply chain attack

Vibe-coded build system NX gets hacked, steals vibe-coders’ crypto

Philips Hue Plans To Make All Your Lights Motion Sensors

Passkeys are incompatible with open-source software

Strategically Holding Back Bugs and Patches

Research found individuals who strongly endorse the values of tradition and security are more likely to show modest associations with certain personality traits that psychologists consider “dark-side” tendencies.

Kernel-hack-drill and exploiting CVE-2024-50264 in the Linux kernel

Subverting code integrity checks to locally backdoor Signal, 1Password, Slack, and more

First AI-Powered 'Self-Composing' Ransomware Was Actually Just a University Research Project

Cookie Chaos: How to bypass __Host and __Secure cookie prefixes

Ever shared a Spotify link on the internet? Someone you don't know can now message you

Show HN: TheAuditor – Offline security scanner for AI-generated code

Cloudflare Stops New World's Largest DDoS Attack Over Labor Day Weekend

Finding vulnerabilities in Python web apps using Claude Code and OpenAI Codex

Trump Social Security Administration Removed Key Metrics, Information from Site

In the rush to adopt hot new tech, security is often forgotten. AI is no exception

Hackers Threaten To Submit Artists' Data To AI Models If Art Site Doesn't Pay Up

Social Security Praises Its New Chatbot. Ex-Officials Say It Was Tested But Shelved Under Biden.

Wolves in the Repository: A Software Engineering Analysis of the XZ Utils Supply Chain Attack

A CA Trusted by Microsoft Mis-issued Certificates for 1.1.1.1 in May 2025, According to Logs

Burger King hacked, attackers 'impressed by the commitment to terrible security practices' — systems described as 'solid as a paper Whopper wrapper in the rain,’ other RBI brands like Tim Hortons and Popeyes also vulnerable

Linux Kernel SMB 0-Day Vulnerability CVE-2025-37899 Uncovered Using ChatGPT o3

Trump’s move of SPACECOM to Alabama has little to do with national security

Scientists map the stress response system in plants, and research suggests that this understanding could help develop crops more resilient to drought, disease, and other stresses, strengthening food security and sustainable farming

Whistle-Blower Sues Meta Over Claims of WhatsApp Security Flaws

What Teddy Bears Reveal About Comfort and Care: Uncovering the Deep Emotional Connections, Psychological Comfort, and Lifelong Sense of Security They Provide Across Childhood, Adulthood…

Plex Suffers Security Incident Exposing User Data and Urging Password Resets

More →