Showing posts with label Secure Software Blogwatch. Show all posts
Showing posts with label Secure Software Blogwatch. Show all posts

Tuesday, 15 August 2023

AI coding helpers get FAILing grade - ReversingLabs

Fools rush in:

Tuesday, 25 July 2023

No net for some, no root for devs — Google pilot walls off staff internet, access for ‘safety’ - ReversingLabs

The future of zero trust?

Tuesday, 11 July 2023

EU-US data transfers back in hotseat: Security of user data adds to privacy concerns - ReversingLabs

EU and US try yet again:

Wednesday, 5 July 2023

Here’s MITRE’s top-25 CWE list — with your old vulnerability category favorites - ReversingLabs

It’s not rocket surgery:

Tuesday, 27 June 2023

Hackers breached UPS data for SMS phish spree - ReversingLabs

UPS SMS oops:

Wednesday, 21 June 2023

Passkeys standard: Time to add it to your dev plans? - ReversingLabs

Momentum is building:

Tuesday, 6 June 2023

PyPI hackers code sneaky new tactic. Researchers caught 'em red handed - ReversingLabs

AST/SCA FAIL — RL FTW:

Wednesday, 31 May 2023

‘Extinction risk’: Could AI wipe out humans via software backdoors? - ReversingLabs

Generative, schmenerative:

Tuesday, 23 May 2023

PyPI paused as automated attack overwhelms admins - ReversingLabs

Python team needs a rest:

Wednesday, 17 May 2023

MSI UEFI key breach: How safe are YOUR secrets?

OEM OMG: No HSM

Tuesday, 9 May 2023

Red teamers take on AI at DEF CON 31 - ReversingLabs

Near the Tannhäuser Gate:

Wednesday, 3 May 2023

SolarWinds hack: Did DoJ know 6 months earlier? - ReversingLabs

DoJ on down-low for half a year:

Wednesday, 26 April 2023

#RSAC is bustling — AI + security is huge: #StrongerTogether? - ReversingLabs

#RSAC #AI snacks #StrongerTogether:

Tuesday, 18 April 2023

EU cyber laws ‘will’ make FOSS devs liable - ReversingLabs

The Python Software Foundation is very, very unhappy with the draft Cyber Resilience Act (CRA) and Product Liability Act (PLA).


European lawmakers want all software makers to be liable for security holes. Even non-profit or hobbyist developers could be sued for negligence.

The EU’s draft Cyber Resilience Act (CRA) and Product Liability Act (PLA) would “create a chilling effect” and do “irreparable harm,” according to the organization behind Python and PyPI. When replicated across other parts of the software supply chain ecosystem, we risk the whole house of cards crashing down — as devs race to limit their liability.

The goal might be laudable, but some aspects need a major rethink. In this week’s Secure Software Blogwatch, we fear unintended consequences.


Read more: EU cyber laws ‘will’ make FOSS devs liable

Tuesday, 11 April 2023

Has public USB ‘juice jacking’ made it into the wild? - ReversingLabs

Déjà vu, but carry protection:

Wednesday, 5 April 2023

With Twitter code in the wild, DevSecOps doubts surface - ReversingLabs

Blue bird b0rked:

Wednesday, 29 March 2023

Do you trust AI to find app sec holes while you sleep? - ReversingLabs

Purr-fect? Or cat-astrophe?
Microsoft has turned OpenAI’s LLM onto cybersecurity. “Security Copilot” is its name for conversational, ChatGPT security analysis and monitoring.

Tuesday, 7 March 2023

White House cyber strategy: A love/hate story - ReversingLabs

A thin line: The Biden administration’s new cybersecurity strategy will, among other things, punish big software developers for failing to follow best practices. And, for the first time, it will make them liable.

Wednesday, 1 March 2023

LastPass revelations: BIG lessons for DevSecOps teams - ReversingLabs

Yearnings for learnings: LastPass has revealed a little more about the vault breach that occurred during August last year. And there are big, big lessons to be learned for Dev(Sec)Ops.