Thursday, 18 February 2021

Lesson from supply chain attacks: Beware 'dependency confusion' - TechBeacon

After Alex Birsan’s $130,000 bug-bounty haul last week, hundreds of bogus npm packages have popped up out of nowhere. They appear to have been published by copycat researchers—some of whom have less-than-pure intentions.

The moral of the story? Make sure the code you’re importing really is the code you think you’re importing.

Monday, 15 February 2021

Internal Leak of 4,887 Users: Yandex Employee Fate Unknown - Security Boulevard

$YNDX Stays Schtum

Friday, 12 February 2021

Thursday, 11 February 2021

There are no good app stores. Not iOS nor Android. Change my mind - TechBeacon

The moral of the story? Watch out for scam clones of your app, and for bad reviews targeting similarly named apps.

Tuesday, 9 February 2021

Water Supply Poisoned by Hacker in Oldsmar, Fla. - Security Boulevard

TeamViewer Vulnerability Probed