home.social

#softwaresecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #softwaresecurity, aggregated by home.social.

fetched live
  1. Reward: You've received a Participation Certificate (Compromised Edition). It is non-transferable. Your credentials, however, were.

    #SupplyChainAttack #Malware #npm #SoftwareSecurity #CredentialTheft #WormPropagation (3/3)

  2. Reward: You've received a Participation Certificate (Compromised Edition). It is non-transferable. Your credentials, however, were.

    #SupplyChainAttack #Malware #npm #SoftwareSecurity #CredentialTheft #WormPropagation (3/3)

  3. The nature of cliques - you are either IN or OUT! GitHub is moving it's Bug Bounty program to 2 tiers.

    Public submissions from Joe software dude of basic bugs will get $250, down from between $500 and $1,000 previously.

    In the new invite-only VIP program basic bugs get a $1,000. VIP invitations will be based a proven history of submitting a number of valid reports. theregister.com/devops/2026/07 #GitHub #Software #Security #Bugs #SoftwareBugs #BugBounty #Rewards #Microsoft #AI #SoftwareSecurity #SoftwareBugs #Vulnerability

  4. The nature of cliques - you are either IN or OUT! GitHub is moving it's Bug Bounty program to 2 tiers.

    Public submissions from Joe software dude of basic bugs will get $250, down from between $500 and $1,000 previously.

    In the new invite-only VIP program basic bugs get a $1,000. VIP invitations will be based a proven history of submitting a number of valid reports. theregister.com/devops/2026/07

  5. Microsoft plants its own flag in the agentic security system market.

    Microsoft releases public preview of "Project Perception" a collection of 3 AI Agents >> Red, Blue, Green in a system that coordinates the operation of the agents in a continuous loop by matching the right model to the right task.

    MS claims the system performs 12 points above Anthropic’s Mythos, at half the cost, on CyberGym benchmark. thenextweb.com/news/microsoft- #AI #AISecurity #AgenicAgents #Microsoft #CyberGym #Security #CyberSecurity #Software #SoftwareSecurity #Vulnerabilities #ProjectPerception #Mythos

  6. Microsoft plants its own flag in the agentic security system market.

    Microsoft releases public preview of "Project Perception" a collection of 3 AI Agents >> Red, Blue, Green in a system that coordinates the operation of the agents in a continuous loop by matching the right model to the right task.

    MS claims the system performs 12 points above Anthropic’s Mythos, at half the cost, on CyberGym benchmark. thenextweb.com/news/microsoft-

  7. Reasons you still need a human in the loop:
    "Researcher poisons open-weight AI model for under $100 share.google/6GPUoUdIMJG8EFPWh"

    Besides the occasional hallucinations, the lack of creativity, and an inability to encode certain types of info into the models (at least for now), #security is a huge issue. A #developer experienced in spotting malicious code and exploitable patterns can catch this sort of issue as often as in regular code reviews.

    #softwareDevelopment #AI #softwaresecurity

  8. Reasons you still need a human in the loop:
    "Researcher poisons open-weight AI model for under $100 share.google/6GPUoUdIMJG8EFPWh"

    Besides the occasional hallucinations, the lack of creativity, and an inability to encode certain types of info into the models (at least for now), #security is a huge issue. A #developer experienced in spotting malicious code and exploitable patterns can catch this sort of issue as often as in regular code reviews.

    #softwareDevelopment #AI #softwaresecurity

  9. 🚀 Behold, the unholy grail of software security: a framework so transparent, it makes you wish for the sweet mystery of life again! 🙈 With the enthusiasm of a root canal, #intoto promises to catalog every excruciating detail of your supply chain, so you can finally sleep at night knowing precisely "who farted where" in the codebase. 🥱
    in-toto.io/ #softwaresecurity #transparency #supplychain #codinghumor #developerlife #HackerNews #ngated

  10. 🚀 Behold, the unholy grail of software security: a framework so transparent, it makes you wish for the sweet mystery of life again! 🙈 With the enthusiasm of a root canal, #intoto promises to catalog every excruciating detail of your supply chain, so you can finally sleep at night knowing precisely "who farted where" in the codebase. 🥱
    in-toto.io/ #softwaresecurity #transparency #supplychain #codinghumor #developerlife #HackerNews #ngated

  11. The fingerprinting code went unmentioned in Claude Code's April release notes, only surfacing when a reverse engineer disabled a feature in June. It executed only when users pointed the tool at custom API endpoints outside Anthropic's servers. Questions remain about disclosure practices. implicator.ai/alibaba-bans-cla #TransparencyMatters #SoftwareSecurity

  12. 🚨BREAKING NEWS🚨: Six "new" #CVEs in #curl, including one that's the digital equivalent of a fossil! 🦖 Congrats to #AISLE for discovering what we've all known since the dawn of time: software is never perfect. 😏 But hey, at least your toaster and Mars rover can now sleep soundly knowing curl is secure. 🌌🔧
    aisle.com/blog/aisle-discovers #BREAKINGNEWS #softwaresecurity #cybersecurity #HackerNews #ngated

  13. 🚨BREAKING NEWS🚨: Six "new" #CVEs in #curl, including one that's the digital equivalent of a fossil! 🦖 Congrats to #AISLE for discovering what we've all known since the dawn of time: software is never perfect. 😏 But hey, at least your toaster and Mars rover can now sleep soundly knowing curl is secure. 🌌🔧
    aisle.com/blog/aisle-discovers #BREAKINGNEWS #softwaresecurity #cybersecurity #HackerNews #ngated

  14. RT @OpenAI: Wir erweitern OpenAI Daybreak, um das Patchen von Software mit Sicherheitslücken zu demokratisieren und dies in maschineller Geschwindigkeit zu ermöglichen:

    mehr auf Arint.info

    #AIPatching #Cybersecurity #Daybreak #InfoSec #OpenAI #SoftwareSecurity #arint_info

    https://x.com/OpenAI/status/2069104283824640023#m

  15. RT @OpenAI: Wir erweitern OpenAI Daybreak, um das Patchen von Software mit Sicherheitslücken zu demokratisieren und dies in maschineller Geschwindigkeit zu ermöglichen:

    mehr auf Arint.info

    #Cybersecurity #GPT #Infosec #OpenAI #PatchManagement #SoftwareSecurity #arint_info

    https://x.com/OpenAI/status/2069104283824640023#m

  16. The Website App Edition, has also been joined by a deck to assist with threat modelling mobile app software, and the new Companion Edition. The Companion Edition adds suits with attacks related to Agentic AI, Cloud, Frontend, Large Language Models, DevOps and Automated Threats.

    OWASP Cornucopia is open source, free to download/use.

    2/2

    #threatmodelling #threatmodeling #appsec #devops #softwaresecurity #owasp #owasp25thanniversary #cornucopia

    @owasp
    @adamshostack

  17. The Website App Edition, has also been joined by a deck to assist with threat modelling mobile app software, and the new Companion Edition. The Companion Edition adds suits with attacks related to Agentic AI, Cloud, Frontend, Large Language Models, DevOps and Automated Threats.

    OWASP Cornucopia is open source, free to download/use.

    2/2

    #threatmodelling #threatmodeling #appsec #devops #softwaresecurity #owasp #owasp25thanniversary #cornucopia

    @owasp
    @adamshostack

  18. Security Tip: Lock down your software builds by pinning dependencies. 🛡️ Relying on "latest" or loose version ranges is a security risk. Use lockfiles with cryptographic checksums to ensure that the code you tested is exactly what goes into production. This simple step helps prevent dependency confusion and malicious injections. Stay ahead of emerging threats and track vulnerabilities at cvedatabase.com

  19. Breaking news! 🚨 #Notepad++ is apparently the Kryptonite of software, now with a zero-click #attack so sneaky, it’s like a ninja in a text editor. 🥷 Meanwhile, GitHub’s #AI #Copilot is standing by, ready to save us from the horrors of traversed paths, because clearly, humans can’t be trusted to code without breaking the universe. 🌌
    github.com/notepad-plus-plus/n #ZeroClick #Cybersecurity #SoftwareSecurity #HackerNews #ngated

  20. Breaking news! 🚨 #Notepad++ is apparently the Kryptonite of software, now with a zero-click #attack so sneaky, it’s like a ninja in a text editor. 🥷 Meanwhile, GitHub’s #AI #Copilot is standing by, ready to save us from the horrors of traversed paths, because clearly, humans can’t be trusted to code without breaking the universe. 🌌
    github.com/notepad-plus-plus/n #ZeroClick #Cybersecurity #SoftwareSecurity #HackerNews #ngated

  21. Microsoft Unveils AI-Powered Red Teaming Tools to Bolster Software Security

    Microsoft is shifting the conversation around AI safety from philosophical debates to hands-on action, empowering developers to build more secure software with innovative tools. With the launch of Rampart, a cutting-edge red-teaming tool, the company is putting AI-powered security into practice, helping developers…

    osintsights.com/microsoft-unve

    #AipoweredSecurity #RedTeaming #SoftwareSecurity #Microsoft #GenerativeAi

  22. Measuring AI Security Effectiveness Proves Elusive

    Measuring AI security effectiveness is a complex challenge that can't be reduced to a single score or benchmark. Relying on benchmarks alone simply doesn't work when it comes to safeguarding AI systems.

    osintsights.com/measuring-ai-s

    #AiSecurity #ArtificialIntelligence #Benchmarking #SecurityEffectiveness #SoftwareSecurity

  23. AI-assisted code does not move the outage, the audit, or the liability to the model vendor. It moves authorship faster than it moves responsibility.

    I wrote about the verification gap, provenance, EU liability pressure, and why enterprise Java teams sit in an awkward middle. the-main-thread.com/p/ai-code- #AIAssistedDevelopment #SoftwareSecurity #Java

  24. AI-assisted code does not move the outage, the audit, or the liability to the model vendor. It moves authorship faster than it moves responsibility.

    I wrote about the verification gap, provenance, EU liability pressure, and why enterprise Java teams sit in an awkward middle. the-main-thread.com/p/ai-code- #AIAssistedDevelopment #SoftwareSecurity #Java

  25. Pi's control layer is now the question. A May 9 research packet documents 2,369 catalog entries, provider routing, and package-trust issues that matter beyond personal use. Who owns the harness? What can change the agent? Teams considering deployment need answers before trust it.

    #AIagents #softwaresecurity #opendev

    implicator.ai/pi-the-coding-ag

  26. Die Cyberagentur hat die Ausschreibung für 3S veröffentlicht. Gesucht werden Ansätze, die Softwaresicherheit nachvollziehbar, messbar und vergleichbar machen. Statt bloßer Siegel braucht es belastbare Bewertungen für den digitalen Alltag.
    Bewerbungen bis 15.06.2026. t1p.de/5q5gg
    #Cyberagentur #Cybersicherheit #SoftwareSecurity #3S #Ausschreibung

  27. Die Cyberagentur hat die Ausschreibung für 3S veröffentlicht. Gesucht werden Ansätze, die Softwaresicherheit nachvollziehbar, messbar und vergleichbar machen. Statt bloßer Siegel braucht es belastbare Bewertungen für den digitalen Alltag.
    Bewerbungen bis 15.06.2026. t1p.de/5q5gg
    #Cyberagentur #Cybersicherheit #SoftwareSecurity #3S #Ausschreibung

  28. 3S has launched: The Cyberagentur is seeking approaches that make software security measurable and comparable. Applications due by June 11, 2026. [Link to e-procurement]
    t1p.de/m85ce
    #3S #Cybersecurity #SoftwareSecurity
    nachrichten.idw-online.de/2026

  29. 3S has launched: The Cyberagentur is seeking approaches that make software security measurable and comparable. Applications due by June 11, 2026. [Link to e-procurement]
    t1p.de/m85ce
    #3S #Cybersecurity #SoftwareSecurity
    nachrichten.idw-online.de/2026

  30. 3S has launched: The Cyberagentur is seeking approaches that make software security measurable and comparable. Applications due by June 11, 2026. [Link to e-procurement]
    t1p.de/m85ce
    #3S #Cybersecurity #SoftwareSecurity
    nachrichten.idw-online.de/2026

  31. Security Tip: Your security is only as strong as your deepest dependency. 🛡️

    While auditing direct libraries is standard, transitive dependencies (libraries your dependencies rely on) are often overlooked. Regularly generate dependency trees to visualize these hidden layers and identify vulnerable sub-components.

    Stay ahead of emerging threats at cvedatabase.com

  32. SAP unter Beschuss: Lieferkettenangriff auf npm-Pakete! Gestern, am 29. April 2026, traf ein gezielter Supply-Chain-Angriff – intern "Mini Shai-Hulud" genannt – die SAP-Entwicklungslandschaft. Angreifer schleusten bösartige Versionen dieser Pakete ein, mutmaßlich über einen kompromittierten Entwickleraccount. Dieser Vorfall zeigt einmal mehr: Software-Lieferketten sind kritische Angriffsflächen. #Cybersecurity #SupplyChain #SAP #npm #SoftwareSecurity #Cybercrime

  33. Warning: CVE-2025-40739 (CWEs: ['CWE-125']) found no CAPEC relationships.
    Warning: CVE-2025-40741 (CWEs: ['CWE-121']) found no CAPEC relationships.

    #SoftwareSecurity #MemorySafety #CWE #ADBE
    2/2

  34. Warning: CVE-2025-40739 (CWEs: ['CWE-125']) found no CAPEC relationships.
    Warning: CVE-2025-40741 (CWEs: ['CWE-121']) found no CAPEC relationships.

    #SoftwareSecurity #MemorySafety #CWE #ADBE
    2/2

  35. The EU’s Cyber Resilience Act (CRA) is a “GDPR moment” for #SoftwareSecurity.

    In this #InfoQ #podcast, Viktor Peterson explores how the CRA is reshaping expectations for software producers & supply chain compliance.

    Key highlights:
    ✅ Why SBOMs are operational assets
    ✅ The danger of "weaponized code" in your security tools
    ✅ The shift toward vendor-neutral discovery

    🎧 Listen now: bit.ly/429icwC

    📄 #transcript included

    #CyberSecurity #SBOM #SoftwareSupplyChain #Compliance

  36. AI that codes can also break systems 🔓 — so Anthropic launched Project Glasswing to find vulnerabilities before hackers do. With partners like NVIDIA, Apple, and Google, their AI model has already flagged thousands of serious bugs in major browsers and operating systems. Read the article to learn how this defensive approach could reshape software security ⚡

    #ProjectGlasswing #Anthropic #Cybersecurity #AI #SoftwareSecurity

    true-tech.net/project-glasswin

  37. I’ve been thinking a lot about where AI coding tools stop being “helpful” and start becoming part of the runtime risk model.

    This piece is about that line.

    For Java teams, the real issue is not bad generated code. It’s excessive agency: shell access, secrets, MCP tools, and autonomous actions without enough containment.

    the-main-thread.com/p/ai-codin

    #Java #Quarkus #DevSecOps #AICoding #SoftwareSecurity #EnterpriseJava