home.social

#software-security — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #software-security, aggregated by home.social.

fetched live
  1. 🚨BREAKING NEWS🚨: Six "new" #CVEs in #curl, including one that's the digital equivalent of a fossil! 🦖 Congrats to #AISLE for discovering what we've all known since the dawn of time: software is never perfect. 😏 But hey, at least your toaster and Mars rover can now sleep soundly knowing curl is secure. 🌌🔧
    aisle.com/blog/aisle-discovers #BREAKINGNEWS #softwaresecurity #cybersecurity #HackerNews #ngated

  2. 🚨BREAKING NEWS🚨: Six "new" #CVEs in #curl, including one that's the digital equivalent of a fossil! 🦖 Congrats to #AISLE for discovering what we've all known since the dawn of time: software is never perfect. 😏 But hey, at least your toaster and Mars rover can now sleep soundly knowing curl is secure. 🌌🔧
    aisle.com/blog/aisle-discovers #BREAKINGNEWS #softwaresecurity #cybersecurity #HackerNews #ngated

  3. 🚨BREAKING NEWS🚨: Six "new" #CVEs in #curl, including one that's the digital equivalent of a fossil! 🦖 Congrats to #AISLE for discovering what we've all known since the dawn of time: software is never perfect. 😏 But hey, at least your toaster and Mars rover can now sleep soundly knowing curl is secure. 🌌🔧
    aisle.com/blog/aisle-discovers #BREAKINGNEWS #softwaresecurity #cybersecurity #HackerNews #ngated

  4. 🚨BREAKING NEWS🚨: Six "new" #CVEs in #curl, including one that's the digital equivalent of a fossil! 🦖 Congrats to #AISLE for discovering what we've all known since the dawn of time: software is never perfect. 😏 But hey, at least your toaster and Mars rover can now sleep soundly knowing curl is secure. 🌌🔧
    aisle.com/blog/aisle-discovers #BREAKINGNEWS #softwaresecurity #cybersecurity #HackerNews #ngated

  5. 🚨BREAKING NEWS🚨: Six "new" #CVEs in #curl, including one that's the digital equivalent of a fossil! 🦖 Congrats to #AISLE for discovering what we've all known since the dawn of time: software is never perfect. 😏 But hey, at least your toaster and Mars rover can now sleep soundly knowing curl is secure. 🌌🔧
    aisle.com/blog/aisle-discovers #BREAKINGNEWS #softwaresecurity #cybersecurity #HackerNews #ngated

  6. RT @OpenAI: Wir erweitern OpenAI Daybreak, um das Patchen von Software mit Sicherheitslücken zu demokratisieren und dies in maschineller Geschwindigkeit zu ermöglichen:

    mehr auf Arint.info

    #AIPatching #Cybersecurity #Daybreak #InfoSec #OpenAI #SoftwareSecurity #arint_info

    https://x.com/OpenAI/status/2069104283824640023#m

  7. RT @OpenAI: Wir erweitern OpenAI Daybreak, um das Patchen von Software mit Sicherheitslücken zu demokratisieren und dies in maschineller Geschwindigkeit zu ermöglichen:

    mehr auf Arint.info

    #AIPatching #Cybersecurity #Daybreak #InfoSec #OpenAI #SoftwareSecurity #arint_info

    https://x.com/OpenAI/status/2069104283824640023#m

  8. RT @OpenAI: Wir erweitern OpenAI Daybreak, um das Patchen von Software mit Sicherheitslücken zu demokratisieren und dies in maschineller Geschwindigkeit zu ermöglichen:

    mehr auf Arint.info

    #AIPatching #Cybersecurity #Daybreak #InfoSec #OpenAI #SoftwareSecurity #arint_info

    https://x.com/OpenAI/status/2069104283824640023#m

  9. RT @OpenAI: Wir erweitern OpenAI Daybreak, um das Patchen von Software mit Sicherheitslücken zu demokratisieren und dies in maschineller Geschwindigkeit zu ermöglichen:

    mehr auf Arint.info

    #Cybersecurity #GPT #Infosec #OpenAI #PatchManagement #SoftwareSecurity #arint_info

    https://x.com/OpenAI/status/2069104283824640023#m

  10. RT @OpenAI: Wir erweitern OpenAI Daybreak, um das Patchen von Software mit Sicherheitslücken zu demokratisieren und dies in maschineller Geschwindigkeit zu ermöglichen:

    mehr auf Arint.info

    #Cybersecurity #GPT #Infosec #OpenAI #PatchManagement #SoftwareSecurity #arint_info

    https://x.com/OpenAI/status/2069104283824640023#m

  11. RT @OpenAI: Wir erweitern OpenAI Daybreak, um das Patchen von Software mit Sicherheitslücken zu demokratisieren und dies in maschineller Geschwindigkeit zu ermöglichen:

    mehr auf Arint.info

    #Cybersecurity #GPT #Infosec #OpenAI #PatchManagement #SoftwareSecurity #arint_info

    https://x.com/OpenAI/status/2069104283824640023#m

  12. RT @OpenAI: Wir erweitern OpenAI Daybreak, um das Patchen von Software mit Sicherheitslücken zu demokratisieren und dies in maschineller Geschwindigkeit zu ermöglichen:

    mehr auf Arint.info

    #Cybersecurity #GPT #Infosec #OpenAI #PatchManagement #SoftwareSecurity #arint_info

    https://x.com/OpenAI/status/2069104283824640023#m

  13. The Website App Edition, has also been joined by a deck to assist with threat modelling mobile app software, and the new Companion Edition. The Companion Edition adds suits with attacks related to Agentic AI, Cloud, Frontend, Large Language Models, DevOps and Automated Threats.

    OWASP Cornucopia is open source, free to download/use.

    2/2

    #threatmodelling #threatmodeling #appsec #devops #softwaresecurity #owasp #owasp25thanniversary #cornucopia

    @owasp
    @adamshostack

  14. The Website App Edition, has also been joined by a deck to assist with threat modelling mobile app software, and the new Companion Edition. The Companion Edition adds suits with attacks related to Agentic AI, Cloud, Frontend, Large Language Models, DevOps and Automated Threats.

    OWASP Cornucopia is open source, free to download/use.

    2/2

    #threatmodelling #threatmodeling #appsec #devops #softwaresecurity #owasp #owasp25thanniversary #cornucopia

    @owasp
    @adamshostack

  15. The Website App Edition, has also been joined by a deck to assist with threat modelling mobile app software, and the new Companion Edition. The Companion Edition adds suits with attacks related to Agentic AI, Cloud, Frontend, Large Language Models, DevOps and Automated Threats.

    OWASP Cornucopia is open source, free to download/use.

    2/2

    #threatmodelling #threatmodeling #appsec #devops #softwaresecurity #owasp #owasp25thanniversary #cornucopia

    @owasp
    @adamshostack

  16. The Website App Edition, has also been joined by a deck to assist with threat modelling mobile app software, and the new Companion Edition. The Companion Edition adds suits with attacks related to Agentic AI, Cloud, Frontend, Large Language Models, DevOps and Automated Threats.

    OWASP Cornucopia is open source, free to download/use.

    2/2

    #threatmodelling #threatmodeling #appsec #devops #softwaresecurity #owasp #owasp25thanniversary #cornucopia

    @owasp
    @adamshostack

  17. The Website App Edition, has also been joined by a deck to assist with threat modelling mobile app software, and the new Companion Edition. The Companion Edition adds suits with attacks related to Agentic AI, Cloud, Frontend, Large Language Models, DevOps and Automated Threats.

    OWASP Cornucopia is open source, free to download/use.

    2/2

    #threatmodelling #threatmodeling #appsec #devops #softwaresecurity #owasp #owasp25thanniversary #cornucopia

    @owasp
    @adamshostack

  18. Security Tip: Lock down your software builds by pinning dependencies. 🛡️ Relying on "latest" or loose version ranges is a security risk. Use lockfiles with cryptographic checksums to ensure that the code you tested is exactly what goes into production. This simple step helps prevent dependency confusion and malicious injections. Stay ahead of emerging threats and track vulnerabilities at cvedatabase.com #CyberSecurity #InfoSec #DevSecOps #CVE #SoftwareSecurity

  19. Security Tip: Lock down your software builds by pinning dependencies. 🛡️ Relying on "latest" or loose version ranges is a security risk. Use lockfiles with cryptographic checksums to ensure that the code you tested is exactly what goes into production. This simple step helps prevent dependency confusion and malicious injections. Stay ahead of emerging threats and track vulnerabilities at cvedatabase.com #CyberSecurity #InfoSec #DevSecOps #CVE #SoftwareSecurity

  20. Security Tip: Lock down your software builds by pinning dependencies. 🛡️ Relying on "latest" or loose version ranges is a security risk. Use lockfiles with cryptographic checksums to ensure that the code you tested is exactly what goes into production. This simple step helps prevent dependency confusion and malicious injections. Stay ahead of emerging threats and track vulnerabilities at cvedatabase.com

  21. Breaking news! 🚨 #Notepad++ is apparently the Kryptonite of software, now with a zero-click #attack so sneaky, it’s like a ninja in a text editor. 🥷 Meanwhile, GitHub’s #AI #Copilot is standing by, ready to save us from the horrors of traversed paths, because clearly, humans can’t be trusted to code without breaking the universe. 🌌
    github.com/notepad-plus-plus/n #ZeroClick #Cybersecurity #SoftwareSecurity #HackerNews #ngated

  22. Breaking news! 🚨 #Notepad++ is apparently the Kryptonite of software, now with a zero-click #attack so sneaky, it’s like a ninja in a text editor. 🥷 Meanwhile, GitHub’s #AI #Copilot is standing by, ready to save us from the horrors of traversed paths, because clearly, humans can’t be trusted to code without breaking the universe. 🌌
    github.com/notepad-plus-plus/n #ZeroClick #Cybersecurity #SoftwareSecurity #HackerNews #ngated

  23. Breaking news! 🚨 #Notepad++ is apparently the Kryptonite of software, now with a zero-click #attack so sneaky, it’s like a ninja in a text editor. 🥷 Meanwhile, GitHub’s #AI #Copilot is standing by, ready to save us from the horrors of traversed paths, because clearly, humans can’t be trusted to code without breaking the universe. 🌌
    github.com/notepad-plus-plus/n #ZeroClick #Cybersecurity #SoftwareSecurity #HackerNews #ngated

  24. Breaking news! 🚨 #Notepad++ is apparently the Kryptonite of software, now with a zero-click #attack so sneaky, it’s like a ninja in a text editor. 🥷 Meanwhile, GitHub’s #AI #Copilot is standing by, ready to save us from the horrors of traversed paths, because clearly, humans can’t be trusted to code without breaking the universe. 🌌
    github.com/notepad-plus-plus/n #ZeroClick #Cybersecurity #SoftwareSecurity #HackerNews #ngated

  25. Breaking news! 🚨 #Notepad++ is apparently the Kryptonite of software, now with a zero-click #attack so sneaky, it’s like a ninja in a text editor. 🥷 Meanwhile, GitHub’s #AI #Copilot is standing by, ready to save us from the horrors of traversed paths, because clearly, humans can’t be trusted to code without breaking the universe. 🌌
    github.com/notepad-plus-plus/n #ZeroClick #Cybersecurity #SoftwareSecurity #HackerNews #ngated

  26. Microsoft Unveils AI-Powered Red Teaming Tools to Bolster Software Security

    Microsoft is shifting the conversation around AI safety from philosophical debates to hands-on action, empowering developers to build more secure software with innovative tools. With the launch of Rampart, a cutting-edge red-teaming tool, the company is putting AI-powered security into practice, helping developers…

    osintsights.com/microsoft-unve

    #AipoweredSecurity #RedTeaming #SoftwareSecurity #Microsoft #GenerativeAi

  27. Measuring AI Security Effectiveness Proves Elusive

    Measuring AI security effectiveness is a complex challenge that can't be reduced to a single score or benchmark. Relying on benchmarks alone simply doesn't work when it comes to safeguarding AI systems.

    osintsights.com/measuring-ai-s

    #AiSecurity #ArtificialIntelligence #Benchmarking #SecurityEffectiveness #SoftwareSecurity

  28. AI-assisted code does not move the outage, the audit, or the liability to the model vendor. It moves authorship faster than it moves responsibility.

    I wrote about the verification gap, provenance, EU liability pressure, and why enterprise Java teams sit in an awkward middle. the-main-thread.com/p/ai-code- #AIAssistedDevelopment #SoftwareSecurity #Java

  29. AI-assisted code does not move the outage, the audit, or the liability to the model vendor. It moves authorship faster than it moves responsibility.

    I wrote about the verification gap, provenance, EU liability pressure, and why enterprise Java teams sit in an awkward middle. the-main-thread.com/p/ai-code- #AIAssistedDevelopment #SoftwareSecurity #Java

  30. AI-assisted code does not move the outage, the audit, or the liability to the model vendor. It moves authorship faster than it moves responsibility.

    I wrote about the verification gap, provenance, EU liability pressure, and why enterprise Java teams sit in an awkward middle. the-main-thread.com/p/ai-code- #AIAssistedDevelopment #SoftwareSecurity #Java

  31. AI-assisted code does not move the outage, the audit, or the liability to the model vendor. It moves authorship faster than it moves responsibility.

    I wrote about the verification gap, provenance, EU liability pressure, and why enterprise Java teams sit in an awkward middle. the-main-thread.com/p/ai-code- #AIAssistedDevelopment #SoftwareSecurity #Java

  32. AI-assisted code does not move the outage, the audit, or the liability to the model vendor. It moves authorship faster than it moves responsibility.

    I wrote about the verification gap, provenance, EU liability pressure, and why enterprise Java teams sit in an awkward middle. the-main-thread.com/p/ai-code- #AIAssistedDevelopment #SoftwareSecurity #Java

  33. Pi's control layer is now the question. A May 9 research packet documents 2,369 catalog entries, provider routing, and package-trust issues that matter beyond personal use. Who owns the harness? What can change the agent? Teams considering deployment need answers before trust it.

    #AIagents #softwaresecurity #opendev

    implicator.ai/pi-the-coding-ag

  34. Pi's control layer is now the question. A May 9 research packet documents 2,369 catalog entries, provider routing, and package-trust issues that matter beyond personal use. Who owns the harness? What can change the agent? Teams considering deployment need answers before trust it.

    #AIagents #softwaresecurity #opendev

    implicator.ai/pi-the-coding-ag

  35. Die Cyberagentur hat die Ausschreibung für 3S veröffentlicht. Gesucht werden Ansätze, die Softwaresicherheit nachvollziehbar, messbar und vergleichbar machen. Statt bloßer Siegel braucht es belastbare Bewertungen für den digitalen Alltag.
    Bewerbungen bis 15.06.2026. t1p.de/5q5gg
    #Cyberagentur #Cybersicherheit #SoftwareSecurity #3S #Ausschreibung

  36. Die Cyberagentur hat die Ausschreibung für 3S veröffentlicht. Gesucht werden Ansätze, die Softwaresicherheit nachvollziehbar, messbar und vergleichbar machen. Statt bloßer Siegel braucht es belastbare Bewertungen für den digitalen Alltag.
    Bewerbungen bis 15.06.2026. t1p.de/5q5gg
    #Cyberagentur #Cybersicherheit #SoftwareSecurity #3S #Ausschreibung

  37. Die Cyberagentur hat die Ausschreibung für 3S veröffentlicht. Gesucht werden Ansätze, die Softwaresicherheit nachvollziehbar, messbar und vergleichbar machen. Statt bloßer Siegel braucht es belastbare Bewertungen für den digitalen Alltag.
    Bewerbungen bis 15.06.2026. t1p.de/5q5gg
    #Cyberagentur #Cybersicherheit #SoftwareSecurity #3S #Ausschreibung

  38. Die Cyberagentur hat die Ausschreibung für 3S veröffentlicht. Gesucht werden Ansätze, die Softwaresicherheit nachvollziehbar, messbar und vergleichbar machen. Statt bloßer Siegel braucht es belastbare Bewertungen für den digitalen Alltag.
    Bewerbungen bis 15.06.2026. t1p.de/5q5gg
    #Cyberagentur #Cybersicherheit #SoftwareSecurity #3S #Ausschreibung

  39. Die Cyberagentur hat die Ausschreibung für 3S veröffentlicht. Gesucht werden Ansätze, die Softwaresicherheit nachvollziehbar, messbar und vergleichbar machen. Statt bloßer Siegel braucht es belastbare Bewertungen für den digitalen Alltag.
    Bewerbungen bis 15.06.2026. t1p.de/5q5gg
    #Cyberagentur #Cybersicherheit #SoftwareSecurity #3S #Ausschreibung

  40. 3S has launched: The Cyberagentur is seeking approaches that make software security measurable and comparable. Applications due by June 11, 2026. [Link to e-procurement]
    t1p.de/m85ce
    #3S #Cybersecurity #SoftwareSecurity
    nachrichten.idw-online.de/2026

  41. 3S has launched: The Cyberagentur is seeking approaches that make software security measurable and comparable. Applications due by June 11, 2026. [Link to e-procurement]
    t1p.de/m85ce
    #3S #Cybersecurity #SoftwareSecurity
    nachrichten.idw-online.de/2026

  42. 3S has launched: The Cyberagentur is seeking approaches that make software security measurable and comparable. Applications due by June 11, 2026. [Link to e-procurement]
    t1p.de/m85ce
    #3S #Cybersecurity #SoftwareSecurity
    nachrichten.idw-online.de/2026

  43. 3S has launched: The Cyberagentur is seeking approaches that make software security measurable and comparable. Applications due by June 11, 2026. [Link to e-procurement]
    t1p.de/m85ce
    #3S #Cybersecurity #SoftwareSecurity
    nachrichten.idw-online.de/2026

  44. 3S has launched: The Cyberagentur is seeking approaches that make software security measurable and comparable. Applications due by June 11, 2026. [Link to e-procurement]
    t1p.de/m85ce
    #3S #Cybersecurity #SoftwareSecurity
    nachrichten.idw-online.de/2026

  45. 3S has launched: The Cyberagentur is seeking approaches that make software security measurable and comparable. Applications due by June 11, 2026. [Link to e-procurement]
    t1p.de/m85ce
    #3S #Cybersecurity #SoftwareSecurity
    nachrichten.idw-online.de/2026

  46. 3S has launched: The Cyberagentur is seeking approaches that make software security measurable and comparable. Applications due by June 11, 2026. [Link to e-procurement]
    t1p.de/m85ce
    #3S #Cybersecurity #SoftwareSecurity
    nachrichten.idw-online.de/2026

  47. 3S has launched: The Cyberagentur is seeking approaches that make software security measurable and comparable. Applications due by June 11, 2026. [Link to e-procurement]
    t1p.de/m85ce
    #3S #Cybersecurity #SoftwareSecurity
    nachrichten.idw-online.de/2026

  48. 3S has launched: The Cyberagentur is seeking approaches that make software security measurable and comparable. Applications due by June 11, 2026. [Link to e-procurement]
    t1p.de/m85ce
    #3S #Cybersecurity #SoftwareSecurity
    nachrichten.idw-online.de/2026

  49. Security Tip: Your security is only as strong as your deepest dependency. 🛡️

    While auditing direct libraries is standard, transitive dependencies (libraries your dependencies rely on) are often overlooked. Regularly generate dependency trees to visualize these hidden layers and identify vulnerable sub-components.

    Stay ahead of emerging threats at cvedatabase.com

    #InfoSec #CyberSecurity #AppSec #SoftwareSecurity #CVE

  50. Security Tip: Your security is only as strong as your deepest dependency. 🛡️

    While auditing direct libraries is standard, transitive dependencies (libraries your dependencies rely on) are often overlooked. Regularly generate dependency trees to visualize these hidden layers and identify vulnerable sub-components.

    Stay ahead of emerging threats at cvedatabase.com

  51. SAP unter Beschuss: Lieferkettenangriff auf npm-Pakete! Gestern, am 29. April 2026, traf ein gezielter Supply-Chain-Angriff – intern "Mini Shai-Hulud" genannt – die SAP-Entwicklungslandschaft. Angreifer schleusten bösartige Versionen dieser Pakete ein, mutmaßlich über einen kompromittierten Entwickleraccount. Dieser Vorfall zeigt einmal mehr: Software-Lieferketten sind kritische Angriffsflächen. #Cybersecurity #SupplyChain #SAP #npm #SoftwareSecurity #Cybercrime

  52. SAP unter Beschuss: Lieferkettenangriff auf npm-Pakete! Gestern, am 29. April 2026, traf ein gezielter Supply-Chain-Angriff – intern "Mini Shai-Hulud" genannt – die SAP-Entwicklungslandschaft. Angreifer schleusten bösartige Versionen dieser Pakete ein, mutmaßlich über einen kompromittierten Entwickleraccount. Dieser Vorfall zeigt einmal mehr: Software-Lieferketten sind kritische Angriffsflächen. #Cybersecurity #SupplyChain #SAP #npm #SoftwareSecurity #Cybercrime

  53. Warning: CVE-2025-40739 (CWEs: ['CWE-125']) found no CAPEC relationships.
    Warning: CVE-2025-40741 (CWEs: ['CWE-121']) found no CAPEC relationships.

    #SoftwareSecurity #MemorySafety #CWE #ADBE
    2/2