Tim Anderson
Categories
OWASP Top 10: Broken access control still tops app security list
The Open Worldwide Application Security Project (OWASP) just published its…
Forking confusing: Vulnerable Rust crate exposes uv Python packager
A vulnerability in the popular Rust crate async-tar has affected…
Microsoft kills 9.9-rated ASP.NET Core bug – ‘our highest ever’ score
Microsoft has patched an ASP.NET Core vulnerability with a CVSS…
GitHub moves to tighten npm security amid phishing, malware plague
GitHub, which owns the npm registry for JavaScript packages, says…
Cloudflare DDoSed itself with React useEffect hook blunder
Cloudflare has confessed to a coding error using a React…
Anthropic’s Claude Code runs code to test if it is safe – which might be a big mistake
App security outfit Checkmarx says automated reviews in Anthropic's Claude…
Compromised Amazon Q extension told AI to delete everything – and it shipped
The official Amazon Q extension for Visual Studio Code (VS…
Not pretty, not Windows-only: npm phishing attack laces popular packages with malware
The popular npm package "is" was infected with cross-platform malware,…