GitHub this week introduced NPM package provenance and deployment protection rules and announced general availability of private vulnerability reporting.
The post GitHub Announces New Security Improvements appeared first on SecurityWeek.
GitHub this week introduced NPM package provenance and deployment protection rules and announced general availability of private vulnerability reporting.
The post GitHub Announces New Security Improvements appeared first on SecurityWeek.
VMware warns of two critical vulnerabilities — CVE-2023-20864 and CVE-2023-20865 — in the VMware Aria Operations for Logs product.
The post VMware Patches Pre-Auth Code Execution Flaw in Logging Product appeared first on SecurityWeek.
Boston-based Mobb has raised $5.4 million in seed funding for a product that automatically fixes vulnerabilities found in applications developed by customers.
The post Mobb Raises $5.4 Million in Seed Funding for Automatic Vulnerability Fixing Tool appeared first on SecurityWeek.
Adobe documents 56 security defects in multiple products, some serious enough to expose Windows and macOS users to code execution attacks.
The post Adobe Plugs Gaping Security Holes in Reader, Acrobat appeared first on SecurityWeek.
Consulting giant KPMG spins out a startup building technology to secure AI (artificial intelligence) applications and deployments.
The post KPMG Tackles AI Security With Cranium Spinout appeared first on SecurityWeek.
OpenSSL 1.1.1 will reach EoL in six months and users are instructed to either upgrade to a newer version or pay for extended support to continue receiving security patches.
The post OpenSSL 1.1.1 Nears End of Life: Security Updates Only Until September 2023 appeared first on SecurityWeek.
Twitter sent a copyright notice to code hosting service GitHub to request the removal of a repository that contained Twitter source code.
The post GitHub Suspends Repository Containing Leaked Twitter Source Code appeared first on SecurityWeek.
Backslash Security banks seed-stage capital to build new technology to identify and mitigate “toxic code flows” in cloud-native applications.
The post Backslash Snags $8M Seed Financing for AppSec Tech appeared first on SecurityWeek.
Black Lantern Security introduces Badsecrets, an open source tool for identifying known or weak cryptographic secrets across multiple platforms.
The post ‘Badsecrets’ Open Source Tool Detects Secrets in Many Web Frameworks appeared first on SecurityWeek.
GitHub this week made secret scanning generally available and free for all public repositories.
The post GitHub Secret Scanning Now Generally Available appeared first on SecurityWeek.