{"id":8447,"date":"2021-11-16T17:39:16","date_gmt":"2021-11-16T16:39:16","guid":{"rendered":"https:\/\/www.show.it?p=8447"},"modified":"2021-11-19T11:12:24","modified_gmt":"2021-11-19T10:12:24","slug":"github-confirms-another-major-npm-security-defect","status":"publish","type":"post","link":"https:\/\/www.show.it\/en\/github-confirms-another-major-npm-security-defect\/","title":{"rendered":"GitHub Confirms Another Major NPM Security Defect"},"content":{"rendered":"<div>\n<p><span style=\"font-size: medium;\"><strong><span style='font-family: \"trebuchet ms\", geneva;'>Microsoft-owned GitHub is again flagging major security problems in the npm registry, warning that a pair of newly discovered vulnerabilities continue to expose the soft underbelly of the open-source software supply chain.<\/span><\/strong><\/span><\/p>\n<p><a href=\"https:\/\/www.securityweek.com\/github-confirms-another-major-npm-security-defect\" target=\"_blank\" rel=\"noopener\">read more<\/a><\/p>\n<div class=\"feedflare\">\n<a href=\"http:\/\/feeds.feedburner.com\/~ff\/securityweek?a=RSb5tl-M8V8:oetZw0xqCag:yIl2AUoC8zA\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/securityweek?d=yIl2AUoC8zA\" border=\"0\"><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/securityweek?a=RSb5tl-M8V8:oetZw0xqCag:-BTjWOF_DHI\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/securityweek?i=RSb5tl-M8V8:oetZw0xqCag:-BTjWOF_DHI\" border=\"0\"><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/securityweek?a=RSb5tl-M8V8:oetZw0xqCag:dnMXMwOfBR0\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/securityweek?d=dnMXMwOfBR0\" border=\"0\"><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/securityweek?a=RSb5tl-M8V8:oetZw0xqCag:V_sGLiPBpWU\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/securityweek?i=RSb5tl-M8V8:oetZw0xqCag:V_sGLiPBpWU\" border=\"0\"><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/securityweek?a=RSb5tl-M8V8:oetZw0xqCag:qj6IDK7rITs\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/securityweek?d=qj6IDK7rITs\" border=\"0\"><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/securityweek?a=RSb5tl-M8V8:oetZw0xqCag:gIN9vFwOqvQ\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/securityweek?i=RSb5tl-M8V8:oetZw0xqCag:gIN9vFwOqvQ\" border=\"0\"><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/securityweek?a=RSb5tl-M8V8:oetZw0xqCag:TzevzKxY174\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/securityweek?d=TzevzKxY174\" border=\"0\"><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/securityweek?a=RSb5tl-M8V8:oetZw0xqCag:F7zBnMyn0Lo\"><img decoding=\"async\" src=\"http:\/\/feeds.feedburner.com\/~ff\/securityweek?i=RSb5tl-M8V8:oetZw0xqCag:F7zBnMyn0Lo\" border=\"0\"><\/a>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft-owned GitHub is again flagging major security problems in the npm registry, warning that a pair of newly discovered vulnerabilities continue to expose the soft underbelly of the open-source software supply chain. read more<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[13,20,16,25,14,10,15,21,11,17,12,18,22,19,23,26,24],"tags":[],"class_list":["post-8447","post","type-post","status-publish","format-standard","hentry","category-audits","category-cloud-security","category-compliance","category-data-protection","category-email-security","category-endpoint-security","category-incident-response","category-malware","category-news-industry","category-phishing","category-privacy","category-risk-management","category-security-architecture","category-virus-malware","category-vulnerabilities","category-white-papers","category-whitepapers"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/posts\/8447","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/comments?post=8447"}],"version-history":[{"count":0,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/posts\/8447\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/media?parent=8447"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/categories?post=8447"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/tags?post=8447"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}