June 1, 2022

It’s not a secret if you publish it on PyPI

Python packages can contain sensitive information. Here's how software development teams can keep secrets secret.
July 21, 2021

Groundhog day: NPM package caught stealing browser passwords

Today almost everyone knows that they need to protect their publicly exposed services and applications against the potential attacks from the outside
July 7, 2021

Third-party code comes with some baggage

Recognize risks introduced by statically linked third-party libraries.
May 7, 2021

It only takes one line of code to ruin your day

Much like SolarWinds before it, this incident shows we need to take a more critical look at the software we are using and trusting to be good.
December 16, 2020

SunBurst: The next level of stealth

SolarWinds compromise exploited through sophistication and patience
April 16, 2020

Mining for malicious Ruby gems

Typosquatting barrage on RubyGems software repository users