Destructive malware available in NPM repo went unnoticed for 2 years https://arstechni.ca/xDjo #coderepositories #Security #malware #Biz&IT #npm
Destructive malware available in NPM repo went unnoticed for 2 years

Payloads were set to spontaneously detonate on specific dates with no warning.

Ars Technica
Zapier says someone broke into its code repositories and may have accessed customer data

Zapier is notifying customers about a “security incident,” which involved an unauthorized user gaining access to the company’s code repositories and “certain custom information.”

The Verge
Octopus Scanner Sinks Tentacles into GitHub Repositories

At least 26 different open-source code repositories were found to be infected with an unusual attack on the open-source software supply chain.

Threatpost - English - Global - threatpost.com
How to Get a Handle on Patch Management - As the number vulnerabilities hit a historic high, battle-worn security teams are upping their pat... more: https://threatpost.com/how-to-handle-patch-management/147909/ #criticalinfrastructure #unpatchedvulnerability #coderepositories #vulnerabilities #patchmanagement #cloudsecurity #cve-2019-0708 #websecurity #stagefright #zipslipflaw #devil’sivy #devsecops #bluekeep #patching #videolan #hacks
How to Get a Handle on Patch Management

As the number vulnerabilities hit a historic high, battle-worn security teams are upping their patching game.

Threatpost - English - Global - threatpost.com