3A Sloppy Interface Is a Security Liability  blog.jim-nielsen.comc/security · by codeinabox@programming.dev · 14h · 0 comments
-2How to Read a Security Advisory: CVE, GHSA, CWE, and CVSS in Plain Words agustinbarrientos.comc/security · by codeinabox@programming.dev · 3d · 0 comments
14Terabytes of credentials leaked in massive supply-chain attack arstechnica.comc/security · by schnurrito@discuss.tchncs.de · 10d · 0 comments
7AI-generated vulnerability patches require human review 1password.comc/security · by codeinabox@programming.dev · 15d · 1 comments
5An improved attack on 7-round AES 00f.netc/security · by codeinabox@programming.dev · 20d · 1 comments
4Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery microsoft.comc/security · by codeinabox@programming.dev · 29d · 0 comments
6Cursor 0day: When Full Disclosure Becomes the Only Protection Left - Mindgard mindgard.aic/security · by Kissaki@programming.dev · 32d · 1 comments
21Russian satellites linked to mysterious GPS disruptions across several countries techxplore.comc/security · by Innerworld@lemmy.world · 72d · 2 comments
-117 bugs in 10 weeks from AI security scanning lalitm.comc/security · by codeinabox@programming.dev · 75d · 0 comments
3Why Hardened Images are Suddenly Everywhere redmonk.comc/security · by codeinabox@programming.dev · 81d · 2 comments
6Typosquatted npm packages used to steal cloud and CI/CD secrets microsoft.comc/security · by codeinabox@programming.dev · 85d · 0 comments
4The approval prompt is lying: a critical coding agent security flaw adversa.aic/security · by codeinabox@programming.dev · 86d · 0 comments
28GitHub Actions Cache Poisoning is eating open source neciudan.devc/security · by codeinabox@programming.dev · 97d · 7 comments
11Mythos finds a curl vulnerability daniel.haxx.sec/security · by codeinabox@programming.dev · 103d · 1 comments
4Why “Trusted Publishing” Can’t Save Us from Social Engineering adventures.nodeland.devc/security · by codeinabox@programming.dev · 107d · 0 comments
28Your Container Is Not a Sandbox emirb.github.ioc/security · by codeinabox@programming.dev · 108d · 7 comments
8Arbitrary code execution and Claude Code CLI: How Claude executed code before you click 'trust' sonarsource.comc/security · by codeinabox@programming.dev · 114d · 1 comments
20Open source package with 1 million monthly downloads stole user credentials arstechnica.comc/security · by schnurrito@discuss.tchncs.de · 117d · 1 comments
0Npm Slop & Wonky Software Supply Chains simonramstedt.comc/security · by codeinabox@programming.dev · 118d · 0 comments