Tag: SupplyChainSecurity

  • Topics Everyone Is Talking About No414

    Bun 1.4: Enhanced Compatibility and Leaner JavaScript Tooling • OpenPubkey SSH: Bringing Single Sign-On to SSH Authentication • Rust Supply Chain Attack Compromises Arrayref Releases • From Rust to Zig: A Systems Developers First Impressions • Aaron Swartz, Data Scraping, and Unequal Tech Accountability…

  • Vulnerability Watch No24

    Brace Expansion Bypass Enables Memory Exhaustion • Angular i18n Flaw Turns Translations into JavaScript • Angular Server Rendering Exposes High-Severity XSS • Angular Cache-Key Collision Can Return the Wrong Data • OpenEMR OAuth Flow Bypasses Multi-Factor Authentication…

  • Vulnerability Watch No23

    Hashi Vault JS Flaw Enables Path and Query Injection • Defaults Deep Library Vulnerable to Prototype Pollution • DSSRF DNS Handling Bug Reopens SSRF Paths • Vault Webhook Flaw Can Leak Kubernetes Service Account Tokens • cPanel Database Rename Flaw Enables Root-Context SQL Execution…

  • Topics Everyone Is Talking About No376

    Data Centers Have Added 23B to Consumers Electricity Bills • How FSF Sysadmins Defend Against Botnets with reaction • TS-2026-009: Insecure Argument Handling in Tailscale SSH Permitted Root Access • The Tower Keeps Rising • Keys, Essence, and Database Performance…

  • Topics Everyone Is Talking About No322

    Beginning January 2026, all ACM publications will be made open access • We Pwned X, Vercel, Cursor, and Discord Through a Supply-Chain Attack • Texas Sues Major TV Makers for Spying on Viewers • Please Just Try HTMX • Classical Statues Were Not Painted Horribly…

  • Topics Everyone Is Talking About No221

    Shai-Hulud Returns: Over 300 NPM Packages Infected • Japans Big Bet: Turning Hokkaido into a Global Chip Powerhouse • Why I Still Love Linux