September 8, 2022

U.S., OpenSSF school dev teams on supply chain security

The U.S. government is sending developers back to school with a new document. But, oh my, what a lot of words.
August 31, 2022

LastPass hacked (again): What devs can learn

In the most recent LastPass hack, bad actors stole source code and other secrets from its dev environment. Learn from it.
August 25, 2022

Hyundai devs used sample code signing keys, making updates vulnerable

Developers of the entertainment unit in the Hyundai Ioniq reused a code-signing key pair from an example, rather than generating their own.
August 18, 2022

Just for devs: Best of Black Hat and DEF CON

Hacker summer camp is BACK, baby.
August 11, 2022

DevOps: Fix your dangerous redirects! Amex shows how

DevOps teams are still ignoring the danger of open redirector pages.
August 4, 2022

Post-quantum algo ‘SIKE’ dead: Did math geeks find key-encap back door?

Here’s more on NIST’s search for post-quantum cryptography: This week, is it in trouble?