Exposing Common Misconceptions about CVEs, NVD, KEV Catalog, and EPSS
How good are LLMs at patching vulnerabilities? GitHub Artifact Attestations, MegaLinter, Malware distributed via StackOverflow
Stirring the pot, testing the top five AI Chatbots, using GitHub Actions for SOC2 Compliance, The Proactive Software Supply Chain Risk Management Framework
My take on transitive vulnerabilities, Pinning GitHub Actions, Ebury backdoor, Supply Chain Steganography, CVE Enrichment
20% of Docker Hub's repos host malicious content, OWASP Critique, and SCA Marketing Nonsense
Building an AppSec Program, AI Exploiting Vulns, Compliance as Code, Artifact Attestations
Shifting left!, Google lays off Python team, hardened container images, and more!
Korea fears AI supply chain, GitHub hosts malware, Microsoft AD account compromise, EPSS Predicts Exploitability, and DataDog's State of DevSecOps
CISA releases Next-Gen Malware Analysis, Sisense's Security Slip-Up, Debating SAST's Value, Secure Defaults!
Neglecting the National Vulnerability Database: A Flaw We Can't Afford
Top 10 threats for 2030, End-of-life containers can mean 400+ CVEs per year, A review of zero-day in-the-wild exploits, and more!
xz/liblzma backdoor, PyPi suspends user registrations, OSV-Scanner offers guided remediation, and Chief AI Officers