⚠️ Critical Unpatched Flaw Exposes Church Data to Remote Code Execution: Unfixed Bug Remains Fully Exploitable in Popular

#CVE202642288 #ChurchCRMVulnerability #ChurchManagementSystemSecurity #OpenSourceSecurity #RemoteCodeExecutionVulnerability #cve #cybersecurity #iso27001

Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised | Wiz Blog

Detect and mitigate malicious npm packages linked to the latest Mini Shai-Hulud supply chain campaign targeting high-value developer tooling.

wiz.io

I had a chat on #OpenSourceSecurity with Kat Cosgrove about open source being critical infrastructure (neglected critical infrastructure)

Kat has a ton of experience in the world of Kubernetes and had some really interesting things to tell us about both successful projects as well as having to shut down projects that didn't get enough resources

Kat even gives me some optimism at the end, which is in rare supply lately

https://opensourcesecurity.io/2026/2026-05-open-source-infrastructure-kat/

Open source is critical infrastructure with Kat Cosgrove

Josh talks to Kat Cosgrove about a how companies should be treating open source more like their critical infrastructure than free stuff. Kat has a ton of knowledge about how the interactions between companies and open source communities can work well, or not work at all. Kat’s time on the Kubernetes Release Team. We touch on how a project like Kubernetes is super successful, while another, Ingress NGINX, was not. It’s a super insightful discussion with a ton of lessons and advice for everyone.

Open Source Security
We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! https://www.youtube.com/watch?v=52p2WywWq7g
We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! https://www.youtube.com/watch?v=52p2WywWq7g

🔐 COSCUP x UbuCon Asia 2026 CFP closes in 3 days — and today happens to be World Password Day.

📅 CFP Deadline: 2026/5/9 AoE
📨 Submit your proposal: https://pretalx.coscup.org/coscup-2026/cfp
📖 CFP announcement: https://blog.coscup.org/2026/03/coscup-x-ubucon-asia-2026-coscup-x.html

#COSCUP2026 #UbuConAsia #HITCON #CyberResilience #CyberSecurity #OpenSource #OpenSourceSecurity

We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! https://www.youtube.com/watch?v=0GtI0pEWpzI
We're LIVE! Join the Anchore Open Source team now to discuss Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! https://www.youtube.com/watch?v=0GtI0pEWpzI
We're LIVE! Join the Anchore Open Source team and our guest Michael Coté from Broadcom catching up on Bitnami Secure Images, Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! https://www.youtube.com/watch?v=m7RfVrN1TUc
We're LIVE! Join the Anchore Open Source team and our guest Michael Coté from Broadcom catching up on Bitnami Secure Images, Syft, Grype, and the latest in #OpenSourceSecurity. Ask your questions! https://www.youtube.com/watch?v=m7RfVrN1TUc