dependency

Dependency Combobulator: Open source toolkit to combat dependency confusion attacks

The open-source toolkit, available on GitHub, allows organizations to safeguard against this newly uncovered type of risk, which has been… Read More

3 years ago

How to use Google's new dependency mapping tool to find security flaws buried in your projects

The experimental dependency exploration tool, dubbed Open Source Insights and available at deps.dev, flags up any unpatched vulnerabilities across millions… Read More

3 years ago

Confused – Tool To Check For Dependency Confusion Vulnerabilities In Multiple Package Management Systems

A tool for checking for lingering free namespaces for private package names referenced in dependency configuration for Python (pypi) requirements.txt,… Read More

3 years ago

Dependency Confusion Exploit Being Used to Create More Copycat Packages

After the release of a proof-of-concept for a new dependency confusion vulnerability by a researcher, hundreds of bogus npm packages… Read More

3 years ago

Hackers Use Malicious NPM packages to Target Amazon, Slack with New Dependency Attacks

Threat actors are targeting Amazon, Zillow, Lyft, and Slack NodeJS apps using a new 'Dependency Confusion' vulnerability to steal Linux/Unix… Read More

3 years ago

Dependency Confusion – Novel Supply Chain Attack Technique

Microsoft warned of a new type of attack technique that can be used to poison the app-building process. The attack… Read More

3 years ago

CDK – Zero Dependency Container Penetration Toolkit

CDK is an open-sourced container penetration toolkit, designed for offering stable exploitation in different slimmed containers without any OS dependency.… Read More

3 years ago

Microsoft’s GitHub adds dependency review to new code submitted from programmers | SC Media

Microsoft subsidiary GitHub will alert programmers about susceptible dependencies at just about every pull ask for, the resource code sharing… Read More

3 years ago