Vulnerability InsightsAn unintimidating introduction to the dark arts of C/C++ vulnerabilitiesApril 15, 2022
Open Source SecuritySpring4Shell extends to Glassfish and Payara: same vulnerability, new exploitApril 8, 2022
Vulnerability InsightsAlert: LaughTilYouCry ransomware sabotages npm package (with puns)April 1, 2022
Open Source SecurityUsing the Snyk Vulnerability Database to find projects for The Big FixMarch 30, 2022
Vulnerability InsightsProtestware is trending in open source: 4 different types and their impactMarch 22, 2022
Vulnerability Insightsdompdf security alert: RCE vulnerability found in popular PHP PDF libraryMarch 18, 2022
Open Source SecurityBuild a software bill of materials (SBOM) for open source supply chain securityMarch 14, 2022
Open Source SecurityVisibly invisible malicious Node.js packages: When configuration niche meets invisible charactersFebruary 28, 2022
Vulnerability InsightsJoin The Big Fix: a 24-hour livestream dedicated to fixing security vulnerabilities in your projectsFebruary 21, 2022
Open Source SecurityUsing the Snyk Vulnerability database to identify projects for The Big FixFebruary 16, 2022
Vulnerability InsightsTeaming up with Sysdig to deliver developer and runtime Kubernetes securityFebruary 16, 2022
Vulnerability InsightsOpen source maintainer pulls the plug on npm packages colors and faker, now what?January 9, 2022