Google Announces Vulnerability Scanner for Open Source Developers

google-announces-vulnerability-scanner-for-open-source-developers

Google this week announced OSV-Scanner, a free scanner that open source developers can use to receive vulnerability details relevant to their projects.

The high number of dependencies that software projects rely on increases the risk of falling victim to a supply chain attack or to the exploitation of unknown vulnerabilities.

read more

HackerOne Surpasses $230 Million in Paid Bug Bounties

hackerone-surpasses-$230-million-in-paid-bug-bounties

Bug bounty platform HackerOne says ethical hackers have identified and reported more than 65,000 software vulnerabilities in 2022.

The popular hacker-powered platform, which hosts bug bounty programs for both private and public organizations, including government agencies, has paid out a total of $230 million in bug bounties since its inception.

read more

Adobe Patches 38 Flaws in Enterprise Software Products

adobe-patches-38-flaws-in-enterprise-software-products

After skipping last month, Adobe returned to its scheduled Patch Tuesday cadence with the release of fixes for at least 38 vulnerabilities in multiple enterprise-facing products.

The San Jose, California software maker said the flaws could expose users to code execution and privilege escalation attacks across all computer platforms.

read more