Loading...

Tag trends are in beta. Feedback? Thoughts? Email me at [email protected]

Supply-chain attack using invisible code hits GitHub and other repositories

Ubuntu 26.04 Ends 46 Years of Silent sudo Passwords

Security Advisory for Cargo

Android developer verification: Balancing openness and choice with safety

ACME device attestation, smallstep and pkcs11: attezt

OpenClaw Is a Security Nightmare Dressed Up as a Daydream

CVE-2026-3888: Important Snap Flaw Enables Local Privilege Escalation to Root

Iran-backed hackers claim wiper attack on medtech firm Stryker

Companies House vulnerability enabled company hijacking

Trivy Supply Chain Attack Spreads, Triggers Self-Spreading CanisterWorm Across 47 npm Packages

Google details new 24-hour process to sideload unverified Android apps

Deprecate confusing APIs like “os.path.commonprefix()”

Try not to get scammed while looking for work

Root from the parking lot: OpenWRT XSS through SSID scanning (CVE-2026-32721)

Fooling Go's X.509 Certificate Verification

Felix "fx" Lindner has died

Dependency Tracking Is Hard

Exploring Maturity Models For Security

Blog: Mitigating URL-based Exfiltration in Gemini

Pocket ID: Easy Passkey Authentication

building a software protection system from first principles

CrackArmor: Multiple vulnerabilities in AppArmor

WebPKI and You

oss-security - Re: Multiple vulnerabilities in AppArmor

Bucketsquatting is finally dead

US Cybersecurity Adds Exploited VMware Aria Operations To KEV Catalog

First (?) hacked Emacs package

Trivy Compromised a Second Time - Malicious v0.69.4 Release

Attempts to post the latest Trivy security incident have been marked [dead]

SSH Certificates and Git Signing

More →