01FBI disrupts massive AI-powered phishing service using a million URLs
02When a Government Pulls an AI Model: What the Fable 5 and Mythos 5 Suspension Means for Security Teams
03152 Chrome Extensions Hide Ad Tracking and Fake Google Search Traffic
04New Agentjacking Attack Hijacks Your AI Coding Agent to Run Code From a Hacker’s Server
05Chinese hackers hijack auth flow, spy on isolated network for a decade
06Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication
07400+ AUR Packages Hijacked: What the “Atomic Arch” Campaign Means for Supply-Chain Security
08Tracing Digital Intent: New MacOS Tahoe 26 Artifact Discovered
09Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit
10Google Sues Chinese Smishing Network Accused of Using Gemini AI in Phishing
11Fancy Bear Hackers Abuse EdgeRouters and Cloud Services to Launch Stealthy Cyberattacks
12[GHSA / CRITICAL] CVE-2026-48150: Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign
13China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade
14Hackers Abuse Legitimate NinjaOne RMM Software to Bypass Traditional Malware Detection
15Ukrainian national pleads guilty to role in Conti ransomware operation
16Over 400 Arch Linux packages compromised to push rootkit, infostealer
17Malicious npm Campaign Steals SSH Keys, API Tokens, Cloud Credentials, and Wallet Secrets
18Early Warning Signs of Supply-Chain Attacks Live in the Dark Web
19Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code
20Rethinking MDR as Attackers and Defenders Embrace AI
21LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution
22INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator
23CISA orders feds to patch actively exploited Ivanti flaw by Sunday
24Over 73,000 French govt employees affected in Tchap messenger breach
25Europol Disrupts AudiA6 Crypto Laundering Service Used by Ransomware Gangs
26ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities
27A tale of two eras
28New Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets
29New GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML Files
30[GHSA / CRITICAL] CVE-2026-48062: CodeIgniter4 has a validation bypass when uploading file extensions via `ext_in` rule
31The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm
32Miasma and Hades Are Spreading Now: Detect Them on Developer Machines with Suspicious Files
33npm v12 delivers one of the biggest security improvements in years
34[GHSA / CRITICAL] CVE-2026-48039: Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token
35Cybersecurity Stars Awards 2026: Winners Announced Across 95 Categories
36AI Broke Vulnerability Management. That's Why CISOs Are Moving Budget to BAS.
37OceanLotus Hits Vietnam Investors With SPECTRALVIPER in FireAnt Attack
38OceanLotus: From external espionage to domestic targeting
39GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks
40CISA KEV: CVE-2026-10520 — Ivanti Sentry OS Command Injection Vulnerability
41[GHSA / CRITICAL] CVE-2026-48063: Baileys has message upsert / hist sync spoofing and app state corruption when using maliciously crafted protocolMessage payload
42Code is being written everywhere, and the device is the only constant
43China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance
44Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities
45Langflow Vulnerability CVE-2026-5027 Exploited for Unauthenticated RCE
46[GHSA / CRITICAL] CVE-2026-48031: Go Restful API Boilerplate: Hardcoded JWT Secret "random" Allows Token Forgery
47Compromised Rust crate onering performs code exfiltration
48Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs
4910 year old critical vulnerability in phpBB affecting tens of millions of users across thousands of forums
50Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows
51[GHSA / CRITICAL] CVE-2026-48030: Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter
52Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility
53[GHSA / CRITICAL] CVE-2026-8467: PhoenixStorybook: Unauthenticated remote code execution via HEEx template injection in phoenix_storybook playground
54Microsoft Patch Tuesday for June 2026 — Snort rules and prominent vulnerabilities
55Pythagora-io/gpt-pilot Compromised on GitHub - Shai-Hulud Credential Stealer Blocked by Python Linter
56Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack Targeting AI Coding Agents
57Meta to Use Off-Site Business Data for Feed and AI Personalization
58Microsoft Restores Some GitHub Repos, Keeps Others Offline as Miasma Probe Continues
59Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Now
60Wait, binding.gyp Can Do What? Exploring npm's Weirdest Build System
61WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine
62Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Models
63New FROST Attack Lets Websites Track What Sites and Apps You Open via SSD Timing
64Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer
65LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE
66CISA KEV: CVE-2026-11645 — Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
67CISA KEV: CVE-2026-7473 — Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability
68CISA KEV: CVE-2026-20245 — Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability
69[GHSA / CRITICAL] CVE-2026-47724: nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation
70[GHSA / CRITICAL] CVE-2026-47252: Anyquery: AppleScript/JXA Code Injection via Unescaped URL in macOS Chrome Plugin
71When “Hi, This Is IT” Comes Through Microsoft Teams
72[GHSA / CRITICAL] CVE-2026-45034: PHPSpreadsheet has a patch bypass for CVE-2026-34084
73One-Character Linux Kernel Flaw Enables Local Root Access, Exploits Now Public
74Meta Blocks NSO Group's New WhatsApp Phishing Attack, Files Contempt Order
75AI brands as bait: How threat actors are using the AI hype in social engineering
76AI Phishing Is Crushing SOCs with Alert Volume: How to Reduce Tier 1 Overload
77[GHSA / CRITICAL] CVE-2026-47430: Cordova Plugin InAppBrowser: iOS: Arbitrary Cordova callback IDs can be dispatched without validation from InAppBrowser WebViews.
78VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliances
79UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign
80CISA KEV: CVE-2026-42271 — BerriAI LiteLLM Command Injection Vulnerability
81CISA KEV: CVE-2026-50751 — Check Point Security Gateway Improper Authentication Vulnerability
82Free Apps Are Quietly Turning Smart TVs Into Web-Scraping Proxies for AI
83[GHSA / CRITICAL] CVE-2026-47744: Shopper: Authorization bypass and RBAC privilege escalation in team settings
84[GHSA / CRITICAL] CVE-2026-47731: NASA AMMOS Instrument Toolkit: Path traversal resulting in arbitrary file append (can be triggered over the network by unauthenticated attacker)
85Securing CI/CD in an agentic world: Claude Code Github action case
86[GHSA / CRITICAL] CVE-2026-47670: Authenticated Remote Code Execution via loadReader functionName code injection in DbGate
87[GHSA / CRITICAL] CVE-2026-47669: DbGate: Zip Slip in archive/unzip allows arbitrary file write leading to RCE
88[GHSA / CRITICAL] CVE-2026-47668: DbGate: Unauthenticated Remote Code Execution via JSON Script Runner
89CISA KEV: CVE-2026-28318 — SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability
90[GHSA / CRITICAL] CVE-2026-47708: MCP-for-Stata: Command injection via log_file_name parameter in Stata command wrapper
91[GHSA / CRITICAL] GHSA-jpvj-wpmj-h7rv: Supply chain compromise via malicious @cap-js/openapi
92[GHSA / CRITICAL] GHSA-8whc-2wmv-ww35: WWBN AVideo: Unauthenticated Stored DOM Cross-Site Scripting via Per-Client Metadata Broadcast in YPTSocket Plugin
93Reporting from Vegas: Networking, AI, and good boys
94Miasma npm Supply Chain Attack: Self-Spreading Worm via Phantom Gyp
95Hypotheses, telemetry, and human judgment: Inside Cisco Talos Threat Hunting
96Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp
97So You Have an AI Security Budget. Now what?
98Type Level Security: The future of secure AI code generation?
99[GHSA / CRITICAL] CVE-2026-44182: Jupyter Enterprise Gateway: Kubernetes Manifest Injection in Jinja2 Template Rendering
100[GHSA / CRITICAL] CVE-2026-44181: Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection resulting in Remote Code Execution
101[GHSA / CRITICAL] CVE-2026-44180: Jupyter Enterprise Gateway: ContainerProcessProxy._enforce_prohibited_ids Bypass
102Argamal: Malware hidden in hentai games
103Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign
104The New Security Risks of the Agentic Development Lifecycle
105CISA KEV: CVE-2026-45247 — Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability
106Why EDR and proxy won’t save you from supply chain malware
107The npm Threat Landscape: Attack Surface and Mitigations (Updated June 2)
108Multiple redhat-cloud-services npm Packages compromised
109Laravel-Lang Supply Chain Attack: Every Tag Across Multiple Composer Packages Rewritten to Steal CI Secrets
110Nx Console VS Code Extension Compromised
111Microsoft Build 2026: Securing code, agents, and models across the development lifecycle
112Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor
113Protestware by open source maintainer to hinder agentic coding: The jqwik 1.10.0 Prompt Injection
114CISA KEV: CVE-2022-0492 — Linux Kernel Improper Authentication Vulnerability
115CISA KEV: CVE-2025-48595 — Android Framework Integer Overflow Vulnerability
116[GHSA / CRITICAL] CVE-2026-47413: praisonai-platform: Any workspace member can add arbitrary user as owner via POST /workspaces/{id}/members
117[GHSA / CRITICAL] CVE-2026-47429: When Vitest UI server is listening, arbitrary file can be read and executed
118Containers on fire: from container escapes to supply chain attacks
119Miasma supply chain attack: malicious code found in @redhat-cloud-services npm packages
120CISA KEV: CVE-2024-21182 — Oracle WebLogic Server Unspecified Vulnerability
121Malicious npm packages abuse dependency confusion to profile developer environments
122[GHSA / CRITICAL] CVE-2026-47416: praisonai-platform: Any workspace member can promote themselves or others to owner via PATCH /workspaces/{id}/members/{user_id}
123[GHSA / CRITICAL] CVE-2026-47410: praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing token forgery for any user when PLATFORM_ENV is unset
124[GHSA / CRITICAL] CVE-2026-47407: PraisonAI Platform has a cross-workspace IDOR + member-role privilege escalation
125[GHSA / CRITICAL] CVE-2026-47391: PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution
126[GHSA / CRITICAL] CVE-2026-47392: PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode)
127[GHSA / CRITICAL] CVE-2026-47393: PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default
128[GHSA / CRITICAL] CVE-2026-47140: NodeVM builtin denylist bypass via process and inspector/promises allows host code execution
129[GHSA / CRITICAL] CVE-2026-47210: vm2 sandbox escape via JSPI-backed Promise `.finally()` species bypass
130[GHSA / CRITICAL] CVE-2026-47137: vm2 has a CVE-2023-37903 patch bypass: nesting:true without explicit require still allows full RCE
131[GHSA / CRITICAL] CVE-2026-47208: vm2 is Vulnerable to Sandbox Breakout Through Promise Species
132[GHSA / CRITICAL] CVE-2026-47131: vm2 has a Sandbox Escape issue
133Microsoft is named a Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection
134What’s in the container? Analyzing vulnerabilities, risks and protection with Kaspersky Container Security and the KIRA AI assistant
135How Relay Network Adopted AI Coding Securely and Built the Foundation for Agentic Development
136Fix SCA issues at scale in your terminal with Snyk Remediation Agent in the CLI
137Typosquatted npm packages used to steal cloud and CI/CD secrets
138CISA KEV: CVE-2026-0257 — Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
139Less panic patching, more precision
140What MDM can't protect on developer machines (and what to do about it)
1412026 World Cup: Discussing The World’s Biggest Game’s Attack Surface
142ESET APT Activity Report Q4 2025–Q1 2026
143Pirates in the crosshairs: how one cybercrime gang has been infecting book, movie, and TV show fans for years
144[GHSA / CRITICAL] CVE-2026-46621: Yamcs Vulnerable to Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection
145[GHSA / CRITICAL] CVE-2026-46562: Yamcs Vulnerable to Remote Code Execution via Mission Database algorithm override
146Out of the Crypt: The Evolving Cyber Extortion Economy
147Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens
148[GHSA / CRITICAL] CVE-2026-45618: LiquidJS is Vulnerable to Remote Code Execution
149Continuous Offensive Security: The Line We've Been Walking
150[GHSA / CRITICAL] CVE-2026-44632: Yamcs Vulnerable to Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory`
151CISA KEV: CVE-2026-48027 — Nx Console Embedded Malicious Code Vulnerability
152CISA KEV: CVE-2026-45321 — TanStack Unspecified Vulnerability
153CISA KEV: CVE-2026-8398 — Daemon Tools Lite Embedded Malicious Code Vulnerability
154[GHSA / CRITICAL] CVE-2026-33137: XWiki Platform has an Unauthenticated XAR Import via REST /wikis/{wikiName}
155Why developer machines are now the number one target for supply chain attacks
156BTMOB: A stealthy RAT burrowing deep into Android devices
157CISA KEV: CVE-2026-48172 — LiteSpeed cPanel Plugin Privilege Escalation Vulnerability
158Laravel Lang Supply Chain Advisory
159Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer
160[GHSA / CRITICAL] CVE-2026-46716: Nezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE) via POST /api/v1/cron
161[GHSA / CRITICAL] CVE-2026-48777: FileBrowser Quantum: Path traversal in public share PATCH allows file ops outside shared directory
162Megalodon: Mass GitHub Actions Secret Exfiltration Across 5,500+ Public Repositories
163[GHSA / CRITICAL] CVE-2026-46670: YesWiki: Unauthenticated SQL Injection
164Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns
165Paved With Intent: ROADtools and Nation-State Tactics in the Cloud
166Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload
167Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise
168CISA KEV: CVE-2026-9082 — Drupal Core SQL Injection Vulnerability
169[GHSA / CRITICAL] CVE-2026-46703: Boxlite: Path Traversal Vulnerability Leads to Arbitrary File Write on the Host
170[GHSA / CRITICAL] CVE-2026-46633: Twig: PHP code injection via `{% use %}` template name
171[GHSA / CRITICAL] GHSA-q2f7-m237-v562: @hulumi/policies: GitHub OIDC trust policy bypass via AWS set-qualified condition operators
172[GHSA / CRITICAL] CVE-2026-46614: Fission router exposes /fission-function/<ns>/<name> on its public listener, allowing invocation of any function without an HTTPTrigger
173The art of being ungovernable
1745 Supply Chain Attacks in 48 Hours: Why Securing One Layer Is Not Enough
175Securing The AI Revolution: How Snyk And Our Partners Are Scaling For The Future
176CISA KEV: CVE-2025-34291 — Langflow Origin Validation Error Vulnerability
177CISA KEV: CVE-2026-34926 — Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability
178Dev Machine Guard Now Supports Linux
179[GHSA / CRITICAL] CVE-2026-46421: Supply chain compromise via malicious package versions (@cap-js/sqlite, @cap-js/postgres, @cap-js/db-service)
180The Wild West of VS Code extensions and how a poisoned extension breached GitHub
181Tracking TamperedChef Clusters via Certificate and Code Reuse
182GitHub breached via a malicious VS Code extension: why developer devices are the real target
183Webworm: New burrowing techniques
184A Day in the Life of a Strategy Co-Op in Snyk’s Boston Office
185CISA KEV: CVE-2008-4250 — Microsoft Windows Buffer Overflow Vulnerability
186CISA KEV: CVE-2009-1537 — Microsoft DirectX NULL Byte Overwrite Vulnerability
187CISA KEV: CVE-2009-3459 — Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability
188CISA KEV: CVE-2010-0249 — Microsoft Internet Explorer Use-After-Free Vulnerability
189CISA KEV: CVE-2026-41091 — Microsoft Defender Link Following Vulnerability
190CISA KEV: CVE-2026-45498 — Microsoft Defender Denial of Service Vulnerability
191The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised
192[GHSA / CRITICAL] CVE-2026-46354: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft
193[GHSA / CRITICAL] CVE-2026-46339: 9router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
194[GHSA / CRITICAL] CVE-2026-45695: Kopia: RCE via SSH ProxyCommand Injection
195Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again!
196[GHSA / CRITICAL] CVE-2026-45758: Malicious code in guardrails-ai 0.10.1 (supply chain compromise)
197[GHSA / CRITICAL] CVE-2026-2587: GlassFish's gadget handler is vulnerable to RCE
198[GHSA / CRITICAL] CVE-2026-47323: Camel-CXF and Camel-Knative Message Header are Vulnerable to Injection via Missing Inbound Filtering
199[GHSA / CRITICAL] CVE-2026-45568: rok Python ProxyShare can be used as an SSRF proxy through absolute URL paths
200[GHSA / CRITICAL] CVE-2026-46395: HAXcms: Private Key Disclosure via Broken HMAC Implementation
201[GHSA / CRITICAL] CVE-2026-45721: Algernon: handler.lua discovery walks parent directories above the server root
202[GHSA / CRITICAL] GHSA-27f5-xjrr-q9ff: Malware in @opensearch-project/opensearch
203[GHSA / CRITICAL] CVE-2026-2611: MLflow: Improper Origin Validation in MLflow Assistant /ajax-api Endpoints Enables Browser-Mediated Local Command Execution
204From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat
205Mini Shai-Hulud strikes again: npm worm compromises hundreds of @antv packages
206actions-cool/issues-helper GitHub Action Compromised: All Tags Point to Imposter Commit That Exfiltrates CI/CD Credentials
207Active Supply Chain Attack: Malicious node-ipc Versions Published to npm
208Mini Shai-Hulud Hits AntV: 300+ Malicious npm Packages Published via Compromised Maintainer Account
209[GHSA / CRITICAL] CVE-2026-45829: ChromaDB Python project has a pre-authentication code injection vulnerability
210[GHSA / CRITICAL] GHSA-wx9m-wx4f-4cmg: Malicious dropper in mistralai 2.4.6 PyPI package
211[GHSA / CRITICAL] CVE-2026-45697: Formie: Pre-authenticated server-side template injection in Hidden fields
212[GHSA / CRITICAL] CVE-2026-45625: Arcane Backend: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps confi
213[GHSA / CRITICAL] CVE-2026-7302: SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability
214[GHSA / CRITICAL] CVE-2026-7301: SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket
215[GHSA / CRITICAL] CVE-2026-7304: SGLang: Unauthenticated RCE via --enable-custom-logit-processor
216IT threat evolution in Q1 2026. Mobile statistics
217[GHSA / CRITICAL] GHSA-6626-79jh-5ccr: Duplicate Advisory: phpMyFAQ enables unauthenticated 2FA brute-force attack via /admin/check acceptance of arbitrary user-id
218Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files
219Malicious node-ipc versions published to npm in suspected maintainer account compromise
220CISA KEV: CVE-2026-42897 — Microsoft Exchange Server Cross-Site Scripting Vulnerability
221[GHSA / CRITICAL] CVE-2026-45411: vm2 Has a Sandbox Breakout Using Async Generator
222[GHSA / CRITICAL] CVE-2026-45369: utcp-cli Vulnerable to Command Injection via Unsanitized Argument Substitution in CLI Communication Protocol
223[GHSA / CRITICAL] CVE-2026-45288: Marten has an injection vulnerability in its full-text search regConfig parameter
224[GHSA / CRITICAL] GHSA-wf8q-wvv8-p8jf: @samanhappy/mcphub: SSE Endpoint Accepts Arbitrary Username from URL Path Without Authentication, Enabling User Impersonation
225[GHSA / CRITICAL] CVE-2026-45374: DeepSeek TUI: task_create Insecure Defaults Enable RCE via Prompt Injection in Project Files
226[GHSA / CRITICAL] CVE-2026-45311: DeepSeek TUI: run_tests Tool Enables RCE via Malicious Repository Without Approval
227[GHSA / CRITICAL] CVE-2026-44990: Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`
228The time of much patching is coming
229[GHSA / CRITICAL] CVE-2026-44849: Portainer has an endpoint security bypass via Swarm service create/update
230[GHSA / CRITICAL] CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints, which allows host RCE
231[GHSA / CRITICAL] CVE-2026-44791: n8n Has an XML Node Prototype Pollution Patch Bypass
232[GHSA / CRITICAL] CVE-2026-44789: n8n: HTTP Request Node Pagination Prototype Pollution to RCE
233Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities
234[GHSA / CRITICAL] CVE-2026-46442: FlowiseAI: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape
235[GHSA / CRITICAL] CVE-2026-27886: Strapi may leak sensitive data via relational filtering due to lack of query sanitization
236[GHSA / CRITICAL] CVE-2026-8178: Amazon Redshift Vulnerable to Remote Code Execution via Unsafe Class Loading
237Kimsuky targets organizations with PebbleDash-based tools
238FrostyNeighbor: Fresh mischief and digital shenanigans
239CISA KEV: CVE-2026-20182 — Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
240TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply Chain Attack Compromises TanStack npm Packages
241Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack
242Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools
243TanStack Npm Packages Compromised Inside The Mini Shai Hulud Supply Chain Attack
244CISA KEV: CVE-2026-42208 — BerriAI LiteLLM SQL Injection Vulnerability
245PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale
246Fake call logs, real payments: How CallPhantom tricks Android users
247Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution
248CISA KEV: CVE-2026-6973 — Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability
249EasterBunny: advanced espionage artifacts attributed to APT29
250CISA KEV: CVE-2026-0300 — Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability
251Security metamorphosis: a Mythos-ready architecture checklist for autonomous AI attacks
252A rigged game: ScarCruft compromises gaming platform in a supply-chain attack
253Shai-Hulud Worm Pivots to Multi-Cloud: intercom-client@7.0.4 Hijacked — 361,000 Weekly Downloads, AWS, GCP, and Azure Credentials Now in Scope
254elementary-data Compromised on PyPI and GHCR: Forged Release Pushed via GitHub Actions Script Injection
255Bitwarden CLI Hijacked on npm: Bun-Staged Credential Stealer Targets Developers, GitHub Actions, and AI Tools
256CanisterSprawl: pgserve Compromised on npm: Malicious Versions Harvest Credentials and Exfiltrate to a Decentralized ICP Canister
257CISA KEV: CVE-2026-31431 — Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
258Popular PyTorch Lightning Package Compromised by Mini Shai-Hulud
259lightning PyPI Compromise: A Bun-Based Credential Stealer in Python
260CISA KEV: CVE-2026-41940 — WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability
261Mini Shai-Hulud Targets SAP npm Packages With a Bun-Based Secret Stealer
262Someone published four versions of a fake "tanstack" package in 27 minutes to steal your .env files
263Bridging the Gap to Autonomous Fixes: Snyk and Atlassian Unveil Intelligent Remediation for Jira
264"A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages
265Don't Panic: The Thymeleaf Template Injection That Only Hurts If You Let It (CVE-2026-40478)
266CISA KEV: CVE-2024-1708 — ConnectWise ScreenConnect Path Traversal Vulnerability
267CISA KEV: CVE-2026-32202 — Microsoft Windows Protection Mechanism Failure Vulnerability
268Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers
269Qinglong task scheduler RCE vulnerabilities exploited in the wild for cryptomining
270It's time to treat browser extensions like supply chain attack vectors
271CISA KEV: CVE-2025-29635 — D-Link DIR-823X Command Injection Vulnerability
272CISA KEV: CVE-2024-7399 — Samsung MagicINFO 9 Server Path Traversal Vulnerability
273CISA KEV: CVE-2024-57728 — SimpleHelp Path Traversal Vulnerability
274CISA KEV: CVE-2024-57726 — SimpleHelp Missing Authorization Vulnerability
275fast16 | Mystery Shadow Brokers Reference Reveals High-Precision Software Sabotage 5 Years Before Stuxnet
276Is Shai-Hulud Back? Compromised Bitwarden CLI Contains a Self-Propagating npm Worm
277GopherWhisper: A burrow full of malware
278Hardcoding Security into Every Commit: The Future of Snyk Secrets
279JPMorgan Just Published a Cyber To-Do List and Snyk Covers 8 of the 10 Items. How do you stack up?
280CISA KEV: CVE-2026-39987 — Marimo Remote Code Execution Vulnerability
281GPT-Proxy Backdoor in npm and PyPI turns Servers into Chinese LLM Relays
282CISA KEV: CVE-2026-33825 — Microsoft Defender Insufficient Granularity of Access Control Vulnerability
283New NGate variant hides in a trojanized NFC payment app
284What the ransom note won’t say
285CISA KEV: CVE-2026-20122 — Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability
286CISA KEV: CVE-2026-20133 — Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
287CISA KEV: CVE-2025-2749 — Kentico Xperience Path Traversal Vulnerability
288CISA KEV: CVE-2023-27351 — PaperCut NG/MF Improper Authentication Vulnerability
289CISA KEV: CVE-2025-48700 — Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability
290CISA KEV: CVE-2026-20128 — Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability
291CISA KEV: CVE-2025-32975 — Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability
292CISA KEV: CVE-2024-27199 — JetBrains TeamCity Relative Path Traversal Vulnerability
293Multiple Cross-Site Scripting (XSS) Vulnerabilities in Mailcow
294CISA KEV: CVE-2026-34197 — Apache ActiveMQ Improper Input Validation Vulnerability
295CISA KEV: CVE-2009-0238 — Microsoft Office Remote Code Execution
296CISA KEV: CVE-2026-32201 — Microsoft SharePoint Server Improper Input Validation Vulnerability
297CISA KEV: CVE-2012-1854 — Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability
298CISA KEV: CVE-2025-60710 — Microsoft Windows Link Following Vulnerability
299CISA KEV: CVE-2023-21529 — Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability
300CISA KEV: CVE-2023-36424 — Microsoft Windows Out-of-Bounds Read Vulnerability
301CISA KEV: CVE-2020-9715 — Adobe Acrobat Use-After-Free Vulnerability
302CISA KEV: CVE-2026-21643 — Fortinet FortiClient EMS SQL Injection Vulnerability
303CISA KEV: CVE-2026-34621 — Adobe Acrobat and Reader Prototype Pollution Vulnerability
304Securing Vibe Coding and AI Coding Agents: An End-to-End Approach with StepSecurity
305Governing Security in the Age of Infinite Signal – From Discovery to Control
306@velora-dex/sdk Compromised on npm: Malicious Version Drops macOS Backdoor via launchctl Persistence
307Behind the Scenes: How StepSecurity Detected and Helped Remediate the Largest npm Supply Chain Attack
308axios Compromised on npm - Malicious Versions Drop Remote Access Trojan
309Dev Machine Guard Is Now Open Source: See What's Really Running on Your Developer Machine
310hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions - Microsoft, DataDog, and CNCF Projects Hit So Far
311Cline Supply Chain Attack Detected: cline@2.3.0 Silently Installs OpenClaw
312GlassWorm goes native: New Zig dropper infects every IDE on your machine
313Aikido Attack finds multiple 0-days in Hoppscotch
314CISA KEV: CVE-2026-1340 — Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
315As breakout time accelerates, prevention-first cybersecurity takes center stage
316Secure What Matters: Scaling Effortless Container Security for the AI Era
317The cybersecurity doomerism around Mythos doesn't match what we see on the ground
318CISA KEV: CVE-2026-35616 — Fortinet FortiClient EMS Improper Access Control Vulnerability
319Malicious IoliteLabs VSCode Extensions Target Solidity Developers on Windows, macOS, and Linux with Backdoor
320TeamPCP Plants WAV Steganography Credential Stealer in telnyx PyPI Package
321You Patched LiteLLM, But Do You Know Your AI Blast Radius?
322CISA KEV: CVE-2026-3502 — TrueConf Client Download of Code Without Integrity Check Vulnerability
323Building AI Security with Our Customers: 5 Lessons from Evo’s Design Partner Program
324CISA KEV: CVE-2026-5281 — Google Dawn Use-After-Free Vulnerability
325Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT
326axios compromised on npm: maintainer account hijacked, RAT deployed
327CISA KEV: CVE-2026-3055 — Citrix NetScaler Out-of-Bounds Read Vulnerability
328litellm: Credential Stealer Hidden in PyPI Wheel
329Popular telnyx package compromised on PyPI by TeamPCP
330A cunning predator: How Silver Fox preys on Japanese firms this tax season
331CISA KEV: CVE-2025-53521 — F5 BIG-IP Stack-Based Buffer Overflow Vulnerability
332Checkmarx KICS GitHub Action Compromised: Malware Injected in All Git Tags
333CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Ecosystem
334Trivy Compromised a Second Time - Malicious v0.69.4 Release, aquasecurity/setup-trivy, aquasecurity/trivy-action GitHub Actions Compromised
335bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys
336Malicious npm Releases Found in Popular React Native Packages - 130K+ Monthly Downloads Compromised
337Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wallet Keys
338ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push
339xygeni-action Compromised: C2 Reverse Shell Backdoor Injected via Tag Poisoning
340The 5 Principles of Snyk’s Developer Experience
341CISA KEV: CVE-2026-33634 — Aquasecurity Trivy Embedded Malicious Code Vulnerability
342From Discovery to Defense: Why AI Red Teaming Is the Next Step After AI-SPM
343CISA KEV: CVE-2026-33017 — Langflow Code Injection Vulnerability
344Cloud workload security: Mind the gaps
345How a Poisoned Security Scanner Became the Key to Backdooring LiteLLM
346CanisterWorm Gets Teeth: TeamPCP's Kubernetes Wiper Targets Iran
347TeamPCP deploys CanisterWorm on NPM following Trivy compromise
348The Next Era of AppSec: Why AI-Generated Code Needs Offensive Dynamic Testing
349CISA KEV: CVE-2025-32432 — Craft CMS Code Injection Vulnerability
350CISA KEV: CVE-2025-54068 — Laravel Livewire Code Injection Vulnerability
351CISA KEV: CVE-2025-43510 — Apple Multiple Products Improper Locking Vulnerability
352CISA KEV: CVE-2025-43520 — Apple Multiple Products Classic Buffer Overflow Vulnerability
353EDR killers explained: Beyond the drivers
354AI Is Building Your Attack Surface. Are You Testing It?
355CISA KEV: CVE-2026-20131 — Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability
356GlassWorm Hides a RAT Inside a Malicious Chrome Extension
357fast-draft Open VSX Extension Compromised by BlokTrooper
358Snyk Opens San Francisco Innovation Hub
359CISA KEV: CVE-2025-66376 — Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability
360CISA KEV: CVE-2026-20963 — Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
361I Read Cursor's Security Agent Prompts, So You Don't Have To
362Securing the Agent Skills Registry: How Snyk and Tessl Are Setting the Standard
363Glassworm Strikes Popular React Native Phone Number Packages
364CISA KEV: CVE-2025-47813 — Wing FTP Server Information Disclosure Vulnerability
365Glassworm Is Back: A New Wave of Invisible Unicode Attacks Hits Hundreds of Repositories
366Face value: What it takes to fool facial recognition
367DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear
368CISA KEV: CVE-2026-3910 — Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability
369CISA KEV: CVE-2026-3909 — Google Skia Out-of-Bounds Write Vulnerability
370Cyber fallout from the Iran war: What to have on your radar
371kubernetes-el Compromised: How a Pwn Request Exploited a Popular Emacs Package
372CISA KEV: CVE-2025-68613 — n8n Improper Control of Dynamically-Managed Code Resources Vulnerability
373Sednit reloaded: Back in the trenches
374CISA KEV: CVE-2021-22054 — Omnissa Workspace ONE Server-Side Request Forgery
375CISA KEV: CVE-2025-26399 — SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
376CISA KEV: CVE-2026-1603 — Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability
377How SMBs use threat research and MDR to build a defensive edge
378CISA KEV: CVE-2017-7921 — Hikvision Multiple Products Improper Authentication Vulnerability
379CISA KEV: CVE-2021-22681 — Rockwell Multiple Products Insufficient Protected Credentials Vulnerability
380CISA KEV: CVE-2023-43000 — Apple Multiple products Use-After-Free Vulnerability
381CISA KEV: CVE-2021-30952 — Apple Multiple Products Integer Overflow or Wraparound Vulnerability
382Protecting education: How MDR can tip the balance in favor of schools
383The 89% Problem: How LLMs Are Resurrecting the "Dormant Majority" of Open Source
384Persistent XSS/RCE using WebSockets in Storybook’s dev server
385CISA KEV: CVE-2026-22719 — Broadcom VMware Aria Operations Command Injection Vulnerability
386CISA KEV: CVE-2026-21385 — Qualcomm Multiple Chipsets Memory Corruption Vulnerability
387How StepSecurity Caught a Release Storm in Microsoft’s @types Packages
388Harden Runner Now Supports Windows and macOS GitHub Actions Runners
389PlugX Meeting Invitation via MSBuild and GDATA
390CISA KEV: CVE-2022-20775 — Cisco SD-WAN Path Traversal Vulnerability
391CISA KEV: CVE-2026-20127 — Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability
392The Rise of the AI Security Engineer: A New Discipline for an AI-Native World
393Snyk and uv, Better Together
394CISA KEV: CVE-2026-25108 — Soliton Systems K.K FileZen OS Command Injection Vulnerability
395Astro Full-Read SSRF via Host Header Injection
396Fetch the Flag CTF 2026: Official Challenge Write-Ups & Community Highlights
397Claude Code Security: A Welcome Evolution in the Remediation Loop
398CISA KEV: CVE-2025-49113 — RoundCube Webmail Deserialization of Untrusted Data Vulnerability
399CISA KEV: CVE-2025-68461 — RoundCube Webmail Cross-site Scripting Vulnerability
400SvelteSpill: A Cache Deception Bug in SvelteKit + Vercel
401PromptSpy ushers in the era of Android threats using GenAI
402How “Clinejection” Turned an AI Bot into a Supply Chain Attack
403Snyk and Cline: Securing the Future of Autonomous Coding
404CISA KEV: CVE-2021-22175 — GitLab Server-Side Request Forgery (SSRF) Vulnerability
405CISA KEV: CVE-2026-22769 — Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability
406Aikido recognized as Platform Leader in Latio Tech's 2026 Application Security Report
407Weaving Security into the Flow: New Snyk Studio Capabilities Power the AI Security Fabric
408Securing the Agent Skill Ecosystem: How Snyk and Vercel Are Locking Down the New Software Supply Chain
409CISA KEV: CVE-2020-7796 — Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability
410CISA KEV: CVE-2024-7694 — TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability
411CISA KEV: CVE-2008-0015 — Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability
412CISA KEV: CVE-2026-2441 — Google Chromium CSS Use-After-Free Vulnerability
413From detection to prevention: How Zen stops IDOR vulnerabilities at runtime
414npm backdoor lets hackers hijack gambling outcomes
41510,000 Open-Source Projects Now Secured by Harden-Runner Community-Tier: A Milestone Three Years in the Making
41620+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...)
4172024 in Review: The Evolution of CI/CD Security & What's Next
418Operation MacroMaze: new APT28 campaign using basic tooling and legit infrastructure
419CISA KEV: CVE-2026-1731 — BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability
420Naming and shaming: How ransomware groups tighten the screws on victims
421From Acceleration to Exposure: Why AI Demands Mature AppSec
422Exploitability Isn’t the Answer. Breakability Is.
423The Future of AI Agent Security Is Guardrails
424CISA KEV: CVE-2026-20700 — Apple Multiple Buffer Overflow Vulnerability
425CISA KEV: CVE-2024-43468 — Microsoft Configuration Manager SQL Injection Vulnerability
426CISA KEV: CVE-2025-15556 — Notepad++ Download of Code Without Integrity Check Vulnerability
427CISA KEV: CVE-2025-40536 — SolarWinds Web Help Desk Security Control Bypass Vulnerability
428StepSecurity Detects Early Supply Chain Risk Signals in kilocode npm
429Another npm Supply Chain Attack: The 'is' Package Compromise
430Harden-Runner detection: tj-actions/changed-files action is compromised
431Why Your “Skill Scanner” Is Just False Security (and Maybe Malware)
432How a Malicious Google Skill on ClawHub Tricks Users Into Installing Malware
433CISA KEV: CVE-2026-21513 — Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability
434CISA KEV: CVE-2026-21525 — Microsoft Windows NULL Pointer Dereference Vulnerability
435CISA KEV: CVE-2026-21533 — Microsoft Windows Improper Privilege Management Vulnerability
436CISA KEV: CVE-2026-21519 — Microsoft Windows Type Confusion Vulnerability
437CISA KEV: CVE-2026-21514 — Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability
438The GRU illegals
439280+ Leaky Skills: How OpenClaw & ClawHub Are Exposing API Keys and PII
440Snyk Finds Prompt Injection in 36%, 1467 Malicious Payloads in a ToxicSkills Study of Agent Skills Supply Chain Compromise
441CISA KEV: CVE-2025-11953 — React Native Community CLI OS Command Injection Vulnerability
442CISA KEV: CVE-2026-24423 — SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability
443npx Confusion: Packages That Forgot to Claim Their Own Name
444The Prescriptive Path to Operationalizing AI Security
445CISA KEV: CVE-2021-39935 — GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability
446CISA KEV: CVE-2025-64328 — Sangoma FreePBX OS Command Injection Vulnerability
447CISA KEV: CVE-2019-19006 — Sangoma FreePBX Improper Authentication Vulnerability
448CISA KEV: CVE-2025-40551 — SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
449Snyk Advisor is Reshaping Package Intelligence on Snyk Security Database
450DynoWiper update: Technical analysis and attribution
451CISA KEV: CVE-2026-1281 — Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
452Love? Actually: Fake dating app used as lure in targeted spyware campaign in Pakistan
453Fake Clawdbot VS Code Extension Installs ScreenConnect RAT
4544 Reasons Why CTFs Are One of the Best Ways to Grow in Cybersecurity
455CISA KEV: CVE-2026-24858 — Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability
456CISA KEV: CVE-2018-14634 — Linux Kernel Integer Overflow Vulnerability
457CISA KEV: CVE-2025-52691 — SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability
458CISA KEV: CVE-2026-23760 — SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability
459CISA KEV: CVE-2026-24061 — GNU InetUtils Argument Injection Vulnerability
460CISA KEV: CVE-2026-21509 — Microsoft Office Security Feature Bypass Vulnerability
461ESET Research: Sandworm behind cyberattack on Poland’s power grid in late 2025
462G_Wagon: npm Package Deploys Python Stealer Targeting 100+ Crypto Wallets
463Gone Phishin': npm Packages Serving Custom Credential Harvesting Pages
464CISA KEV: CVE-2024-37079 — Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability
465Malicious PyPI Packages spellcheckpy and spellcheckerpy Deliver Python RAT
466CISA KEV: CVE-2025-68645 — Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability
467CISA KEV: CVE-2025-34026 — Versa Concerto Improper Authentication Vulnerability
468CISA KEV: CVE-2025-31125 — Vite Vitejs Improper Access Control Vulnerability
469CISA KEV: CVE-2025-54313 — Prettier eslint-config-prettier Embedded Malicious Code Vulnerability
470CISA KEV: CVE-2026-20045 — Cisco Unified Communications Products Code Injection Vulnerability
471Live From Davos: The End of Human-Speed Security
472ServiceNow's Virtual Agent Vulnerability Shows Why AI Security Needs Traditional AppSec Foundations
473CISA KEV: CVE-2026-20805 — Microsoft Windows Information Disclosure Vulnerability
474CISA KEV: CVE-2025-8110 — Gogs Path Traversal Vulnerability
475Beyond Detection: Building a Resilient Software Supply Chain (Lessons from the Shai-Hulud Post-Mortem)
476Secure by Default: Why Snyk and Augment Code are the New Standard for AI Development
477CISA KEV: CVE-2009-0556 — Microsoft Office PowerPoint Code Injection Vulnerability
478CISA KEV: CVE-2025-37164 — Hewlett Packard Enterprise (HPE) OneView Code Injection Vulnerability
4792025 in Review: The Evolution of Supply Chain Security & What's Next
480The Holiday Whisper: Shai-Hulud 3.0
481CISA KEV: CVE-2025-14847 — MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability
482Revisiting CVE-2025-50165: A critical flaw in Windows Imaging Component
483CISA KEV: CVE-2023-52163 — Digiever DS-2105 Pro Missing Authorization Vulnerability
484Evo Adds CycloneDX Support to Give Full AI Visibility
485CISA KEV: CVE-2025-14733 — WatchGuard Firebox Out of Bounds Write Vulnerability
486LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan
487CISA KEV: CVE-2025-59374 — ASUS Live Update Embedded Malicious Code Vulnerability
488CISA KEV: CVE-2025-40602 — SonicWall SMA1000 Missing Authorization Vulnerability
489CISA KEV: CVE-2025-20393 — Cisco Multiple Products Improper Input Validation Vulnerability
490ESET Threat Report H2 2025
491Old AI Security vs Evo: Watch Agentic Security Replace Weeks of Manual Work
492CISA KEV: CVE-2025-59718 — Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability
493Critical Remote Code Execution Vulnerabilities Discovered in React Server Components and Next.js
494How Harden Runner Detected the Sha1-Hulud Supply Chain Attack in CNCF's Backstage Repository
495Sha1-Hulud: The Second Coming - Zapier, ENS Domains, and Other Prominent NPM Packages Compromised
496Supply Chain Security Alert: eslint-config-prettier Package Shows Signs of Compromise
497CISA KEV: CVE-2025-14611 — Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability
498CISA KEV: CVE-2025-43529 — Apple Multiple Products Use-After-Free WebKit Vulnerability
499CISA KEV: CVE-2018-4063 — Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability
500CISA KEV: CVE-2025-14174 — Google Chromium Out of Bounds Memory Access Vulnerability
501Black Hat Europe 2025: Reputation matters – even in the ransomware economy
502Locks, SOCs and a cat in a box: What Schrödinger can teach us about cybersecurity
503CISA KEV: CVE-2025-58360 — OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability
504How Snyk Helps Federal Agencies Prepare for the Genesis Mission Era of AI-Driven Science
505CISA KEV: CVE-2025-6218 — RARLAB WinRAR Path Traversal Vulnerability
506CISA KEV: CVE-2025-62221 — Microsoft Windows Use After Free Vulnerability
507CISA KEV: CVE-2022-37055 — D-Link Routers Buffer Overflow Vulnerability
508CISA KEV: CVE-2025-66644 — Array Networks ArrayOS AG OS Command Injection Vulnerability
509CISA KEV: CVE-2025-55182 — Meta React Server Components Remote Code Execution Vulnerability
510Accelerating innovation with AWS: Snyk selected as an AWS Pattern Partner
511Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)
512Run AutoMCP To Supercharge Your AI Agent with Libraries MCP Servers
513CISA KEV: CVE-2021-26828 — OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability
514MuddyWater: Snakes by the riverbank
515CISA KEV: CVE-2025-48633 — Android Framework Information Disclosure Vulnerability
516CISA KEV: CVE-2025-48572 — Android Framework Privilege Escalation Vulnerability
517When Speed Meets Security: Snyk Studio for Kiro
518CISA KEV: CVE-2021-26829 — OpenPLC ScadaBR Cross-site Scripting Vulnerability
519Snyk Log Sniffer: AI-Powered Audit Log Insights for Security Leaders
520SHA1-Hulud, npm supply chain incident
521Scaling AI Security: How Evo Complements New Agentic Tools
522Shai-Hulud: Self-Replicating Worm Compromises 500+ NPM Packages
523How Snyk Studio for Qodo Is Closing the AI Security Gap
524CISA KEV: CVE-2025-61757 — Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability
525Why Threat Modeling Is Now Even More Critical for AI-Native Applications
526PlushDaemon compromises network devices for adversary-in-the-middle attacks
527Beyond Automation: Securing Low-Code Agentic AI with MCP Guardrails
528Anthem Awards 2025: Snyk Learn Recognized for Commitment to Secure AI Development
529CISA KEV: CVE-2025-13223 — Google Chromium V8 Type Confusion Vulnerability
530Snyk and Continue Partner to Embed AI-Powered Security into Every Step of the Developer Workflow
531CISA KEV: CVE-2025-58034 — Fortinet FortiWeb OS Command Injection Vulnerability
532CISA KEV: CVE-2025-64446 — Fortinet FortiWeb Path Traversal Vulnerability
533Automated Package-Publication Incident IndonesianFoods in the NPM Ecosystem Linked to Crypto Reward-Farming Scam
534Organizations Achieve 288% ROI with The Snyk AI Trust Platform, According to New Forrester TEI Study
535CISA KEV: CVE-2025-12480 — Gladinet Triofox Improper Access Control Vulnerability
536CISA KEV: CVE-2025-62215 — Microsoft Windows Race Condition Vulnerability
537CISA KEV: CVE-2025-9242 — WatchGuard Firebox Out-of-Bounds Write Vulnerability
538Secure by Design: The Future of Threat Modeling for AI-Native Applications
539The Agentic OODA Loop: How AI and Humans Learn to Defend Together
540CISA KEV: CVE-2025-21042 — Samsung Mobile Devices Out-of-Bounds Write Vulnerability
541In memoriam: David Harley
542The who, where, and how of APT attacks in Q2 2025–Q3 2025
543ESET APT Activity Report Q2 2025–Q3 2025
544Sharing is scaring: The WhatsApp scam you didn’t see coming
545Snyk Studio brings security scanning and automated fixes to Factory's Droids
546Beyond the Scan: The Future of Snyk Container
547Snyk Studio: Now for All Customers, Powering Secure AI Development at Scale
548CISA KEV: CVE-2025-48703 — CWP Control Web Panel OS Command Injection Vulnerability
549CISA KEV: CVE-2025-11371 — Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerability
550Ground zero: 5 things to do after discovering a cyberattack
551CISA KEV: CVE-2025-41244 — Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability
552CISA KEV: CVE-2025-24893 — XWiki Platform Eval Injection Vulnerability
553CISA KEV: CVE-2025-6204 — Dassault Systèmes DELMIA Apriso Code Injection Vulnerability
554How MDR can give MSPs the edge in a competitive market
555CISA KEV: CVE-2025-54236 — Adobe Commerce and Magento Improper Input Validation Vulnerability
556CISA KEV: CVE-2025-59287 — Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability
557Gotta fly: Lazarus targets the UAV sector
558SnakeStealer: How it preys on personal data – and how you can protect yourself
559Why We Built Evo — From My Heart
560CISA KEV: CVE-2025-61932 — Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability
561CISA KEV: CVE-2022-48503 — Apple Multiple Products Unspecified Vulnerability
562CISA KEV: CVE-2025-2746 — Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability
563CISA KEV: CVE-2025-33073 — Microsoft Windows SMB Client Improper Access Control Vulnerability
564CISA KEV: CVE-2025-61884 — Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability
565Increasing Agility & Flexibility: How Mercato Solutions tackles the application security vs. flexibility conundrum with Snyk
566Snyk and Cognition partner to enhance security for AI-native development
567CISA KEV: CVE-2025-54253 — Adobe Experience Manager Forms Code Execution Vulnerability
568Beyond the Hype: 5 Major Reasons to Attend DevSecCon 2025
569Snyk Named a Leader in the 2025 Gartner® Magic Quadrant™ for Application Security Testing
570CISA KEV: CVE-2025-47827 — IGEL OS Use of a Key Past its Expiration Date Vulnerability
571CISA KEV: CVE-2025-24990 — Microsoft Windows Untrusted Pointer Dereference Vulnerability
572CISA KEV: CVE-2025-59230 — Microsoft Windows Improper Access Control Vulnerability
573CISA KEV: CVE-2016-7836 — SKYSEA Client View Improper Authentication Vulnerability
574Phishing Campaign Leveraging the NPM Ecosystem
575CISA KEV: CVE-2021-43798 — Grafana Path Traversal Vulnerability
576CISA KEV: CVE-2025-27915 — Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability
577CISA KEV: CVE-2021-22555 — Linux Kernel Heap Out-of-Bounds Write Vulnerability
578CISA KEV: CVE-2010-3962 — Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability
579CISA KEV: CVE-2021-43226 — Microsoft Windows Privilege Escalation Vulnerability
580CISA KEV: CVE-2013-3918 — Microsoft Windows Out-of-Bounds Write Vulnerability
581CISA KEV: CVE-2011-3402 — Microsoft Windows Remote Code Execution Vulnerability
582CISA KEV: CVE-2010-3765 — Mozilla Multiple Products Remote Code Execution Vulnerability
583CISA KEV: CVE-2025-61882 — Oracle E-Business Suite Unspecified Vulnerability
584CISA KEV: CVE-2014-6278 — GNU Bash OS Command Injection Vulnerability
585CISA KEV: CVE-2017-1000353 — Jenkins Remote Code Execution Vulnerability
586CISA KEV: CVE-2015-7755 — Juniper ScreenOS Improper Authentication Vulnerability
587CISA KEV: CVE-2025-21043 — Samsung Mobile Devices Out-of-Bounds Write Vulnerability
588CISA KEV: CVE-2025-4008 — Smartbedded Meteobridge Command Injection Vulnerability
589CISA KEV: CVE-2025-32463 — Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability
590CISA KEV: CVE-2025-59689 — Libraesva Email Security Gateway Command Injection Vulnerability
591CISA KEV: CVE-2025-10035 — Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability
592CISA KEV: CVE-2025-20352 — Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability
593CISA KEV: CVE-2021-21311 — Adminer Server-Side Request Forgery Vulnerability
594Malicious MCP Server on npm postmark-mcp Harvests Emails
595CISA KEV: CVE-2025-20362 — Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability
596s1ngularity: Popular Nx Build System Package Compromised with Data-Stealing Malware
597How Snyk Learn Helps You Meet PCI DSS v4.0 Developer Training Requirements
598CISA KEV: CVE-2025-10585 — Google Chromium V8 Type Confusion Vulnerability
599Snyk Ranked #51 on 2025 Forbes Cloud 100 List
600GhostAction Campaign: Over 3,000 Secrets Stolen Through Malicious GitHub Workflows
601Secure Your AI Workflows: New Governance & Visibility Features from Snyk
602From Two Years to Two Weeks: How Labelbox Erased Its Security Debt with Snyk's AI-Accelerated Remediation
603Speaking Different Languages: How to Align Dev and Sec Teams Effectively
604Zero-day Extensive NPM Package Compromise - Shai Hulud Supply Chain Attack
605CISA KEV: CVE-2025-5086 — Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data Vulnerability
606Snyk Named a Leader in the 2025 Forrester SAST Wave: SAST Solutions, Q3 2025
607npm Supply Chain Attack via Open Source maintainer compromise
608How StepSecurity Harden Runner Detected Unexpected Microsoft Defender Installation on GitHub-hosted Ubuntu Runners
609What an 'Aha' Moment with an Org Admin Token Taught One DevSecCon Speaker About AI Security
610CISA KEV: CVE-2025-38352 — Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability
611CISA KEV: CVE-2025-48543 — Android Runtime Use-After-Free Vulnerability
612CISA KEV: CVE-2025-53690 — Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability
613CISA KEV: CVE-2023-50224 — TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability
614CISA KEV: CVE-2025-9377 — TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability
615CISA KEV: CVE-2020-24363 — TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability
616CISA KEV: CVE-2025-55177 — Meta Platforms WhatsApp Incorrect Authorization Vulnerability
617CISA KEV: CVE-2025-57819 — Sangoma FreePBX Authentication Bypass Vulnerability
618Weaponizing AI Coding Agents for Malware in the Nx Malicious Package Security Incident
619CISA KEV: CVE-2025-7775 — Citrix NetScaler Memory Overflow Vulnerability
620CISA KEV: CVE-2025-48384 — Git Link Following Vulnerability
621CISA KEV: CVE-2024-8068 — Citrix Session Recording Improper Privilege Management Vulnerability
622CISA KEV: CVE-2024-8069 — Citrix Session Recording Deserialization of Untrusted Data Vulnerability
623CISA KEV: CVE-2025-43300 — Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability
624Prioritize with Snyk’s Open Source Vulnerability Experience
625CISA KEV: CVE-2025-54948 — Trend Micro Apex One OS Command Injection Vulnerability
626Suspicious Tag Movement in AWS’s GitHub Action: What Happened and Why It Matters
627When 'Changed Files' Changed Everything: Our Black Hat 2025 Presentation on the tj-actions Supply Chain Breach
628AI Agents in Cybersecurity: Revolutionizing AppSec
629Agentic Container Security with Snyk MCP Server
630CISA KEV: CVE-2025-8876 — N-able N-Central Command Injection Vulnerability
631CISA KEV: CVE-2025-8875 — N-able N-Central Insecure Deserialization Vulnerability
632CISA KEV: CVE-2025-8088 — RARLAB WinRAR Path Traversal Vulnerability
633CISA KEV: CVE-2007-0671 — Microsoft Office Excel Remote Code Execution Vulnerability
634CISA KEV: CVE-2013-3893 — Microsoft Internet Explorer Resource Management Errors Vulnerability
635Lessons from AWS CodeBuild’s Memory-Dump Incident (CVE-2025-8217)
636Supply Chain Security Alert: num2words PyPI Package Shows Signs of Compromise
637Meeting the AI Mandates with Confidence: Why Federal Teams Trust Snyk
638From Ideas to Impact: How the Bay Area Is Shaping the Future of Secure AI
639Snyk Supercharges API Discovery with New Akamai Integration
640Snyk Joins CISA's Secure by Design Pledge
641The Hidden Costs of False Positives in Healthtech Security
642CISA KEV: CVE-2020-25078 — D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability
643CISA KEV: CVE-2022-40799 — D-Link DNR-322L Download of Code Without Integrity Check Vulnerability
644Secure at Inception: Introducing New Tools for Securing AI-Native Development
645When “Private" Isn't: The Security Risk of GPT Chats Leaking to Search Engines
646Fend Off AI Fatigue with the Snyk AI Trust Platform
647CISA KEV: CVE-2023-2533 — PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerability
648CISA KEV: CVE-2025-20337 — Cisco Identity Services Engine Injection Vulnerability
649Maintainers of ESLint Prettier Plugin Attacked via npm Supply Chain Malware
650CISA KEV: CVE-2025-2775 — SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability
651CISA KEV: CVE-2025-6558 — Google Chromium ANGLE and GPU Improper Input Validation Vulnerability
652CISA KEV: CVE-2025-54309 — CrushFTP Unprotected Alternate Channel Vulnerability
653CISA KEV: CVE-2025-49704 — Microsoft SharePoint Code Injection Vulnerability
654Cursor IDE Malware Extension Compromise in $500k Crypto Heist
655Navigating Enterprise AI Implementation: Risks, Rewards, and Where to Start
656CISA KEV: CVE-2025-53770 — Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
657CISA KEV: CVE-2025-25257 — Fortinet FortiWeb SQL Injection Vulnerability
658Human + AI: The Next Era of Snyk's Vulnerability Curation
659CISA KEV: CVE-2025-47812 — Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability
660CISA KEV: CVE-2025-5777 — Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability
661CISA KEV: CVE-2019-9621 — Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability
662CISA KEV: CVE-2019-5418 — Rails Ruby on Rails Path Traversal Vulnerability
663CISA KEV: CVE-2016-10033 — PHPMailer Command Injection Vulnerability
664CISA KEV: CVE-2014-3931 — Multi-Router Looking Glass (MRLG) Buffer Overflow Vulnerability
665CISA KEV: CVE-2025-6554 — Google Chromium V8 Type Confusion Vulnerability
666Minimizing False Positives: Enhancing Security Efficiency
667CISA KEV: CVE-2025-48928 — TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerability
668CISA KEV: CVE-2025-48927 — TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability
669Fixing Fix Fatigue: Building Developer Trust for Secure AI Code
670CISA KEV: CVE-2025-6543 — Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability
671Understanding CRA Compliance: Overcoming Challenges with an Integrated Security Testing Approach
672CISA KEV: CVE-2019-6693 — Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability
673CISA KEV: CVE-2024-0769 — D-Link DIR-859 Router Path Traversal Vulnerability
674CISA KEV: CVE-2024-54085 — AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability
675Why AI Trust Will Shape Your Next Decade of Software Development
676Scan your AI-generated code from Cursor using Model Context Protocol (MCP)
677Building AI Trust with Snyk Code and Snyk Agent Fix
678The New Threat Landscape: AI-Native Apps and Agentic Workflows
679CISA KEV: CVE-2023-0386 — Linux Kernel Improper Ownership Management Vulnerability
680CISA KEV: CVE-2023-33538 — TP-Link Multiple Routers Command Injection Vulnerability
681CISA KEV: CVE-2025-43200 — Apple Multiple Products Unspecified Vulnerability
682Why ANZ Technology Leaders Are Rethinking How AI, Speed, and Security Intersect
683Finding Software Flaws Early in the Development Process Provides Clear ROI
684Transform Your AppSec Program With the Power of Snyk Analytics
685Build Fast, Stay Secure: Guardrails for AI Coding Assistants
686CISA KEV: CVE-2025-33053 — Microsoft Windows External Control of File Name or Path Vulnerability
687CISA KEV: CVE-2025-24016 — Wazuh Server Deserialization of Untrusted Data Vulnerability
688CISA KEV: CVE-2024-42009 — RoundCube Webmail Cross-Site Scripting Vulnerability
689CISA KEV: CVE-2025-32433 — Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability
690Snyk for Government Achieves FedRAMP Moderate Authorization: A Milestone for Secure Government Software
691Humans at the Center: Redefining the Role of Developers in an AI-Powered Future
692CISA KEV: CVE-2025-5419 — Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
693From Risk to Resilience: Achieving HIPAA Standards in Your App
694The Future of Developer Upskilling Is Human-Led, AI-Supported
695CISA KEV: CVE-2025-21479 — Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability
696CISA KEV: CVE-2025-27038 — Qualcomm Multiple Chipsets Use-After-Free Vulnerability
697AI Trust in Action: How Snyk Agent Redefines Secure Development
698CISA KEV: CVE-2021-32030 — ASUS Routers Improper Authentication Vulnerability
699CISA KEV: CVE-2025-3935 — ConnectWise ScreenConnect Improper Authentication Vulnerability
700CISA KEV: CVE-2025-35939 — Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability
701CISA KEV: CVE-2024-56145 — Craft CMS Code Injection Vulnerability
702CISA KEV: CVE-2023-39780 — ASUS RT-AX55 Routers OS Command Injection Vulnerability
703Welcome-to-The New Era of AI-Driven Development
704Scaling Security Education with Snyk's New Learn Add-on
705AI Is Reshaping Software. Is Your Security Strategy Keeping Up?
706Welcome to Snyk Labs: Charting the Course for AI-Native Security
707Snyk Learn in the Exosphere: Securing Space at HackSpaceCon
708Snyk Report shows 88% of CISOs are concerned with current state of U.S. cyber readiness
709CISA KEV: CVE-2025-4632 — Samsung MagicINFO 9 Server Path Traversal Vulnerability
710Security Testing for Single-Page Applications (SPAs)
711CISA KEV: CVE-2023-38950 — ZKTeco BioTime Path Traversal Vulnerability
712CISA KEV: CVE-2024-27443 — Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
713CISA KEV: CVE-2025-27920 — Srimax Output Messenger Directory Traversal Vulnerability
714CISA KEV: CVE-2024-11182 — MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability
715CISA KEV: CVE-2025-4428 — Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
716CISA KEV: CVE-2025-42999 — SAP NetWeaver Deserialization Vulnerability
717CISA KEV: CVE-2024-12987 — DrayTek Vigor Routers OS Command Injection Vulnerability
718CISA KEV: CVE-2025-32756 — Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability
719CISA KEV: CVE-2025-32709 — Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
720CISA KEV: CVE-2025-30397 — Microsoft Windows Scripting Engine Type Confusion Vulnerability
721CISA KEV: CVE-2025-32706 — Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability
722CISA KEV: CVE-2025-30400 — Microsoft Windows DWM Core Library Use-After-Free Vulnerability
723Snyk @ RSAC 2025
724CISA KEV: CVE-2025-47729 — TeleMessage TM SGNL Hidden Functionality Vulnerability
725Driving AI Security Innovation: Snyk Enhances Global Channel & GSI Partner Program
726CISA KEV: CVE-2024-11120 — GeoVision Devices OS Command Injection Vulnerability
727CISA KEV: CVE-2025-27363 — FreeType Out-of-Bounds Write Vulnerability
728Learn About Open Source Security Risks With the New Snyk Learn Learning Path
729CISA KEV: CVE-2025-3248 — Langflow Missing Authentication Vulnerability
730CISA KEV: CVE-2025-34028 — Commvault Command Center Path Traversal Vulnerability
731CISA KEV: CVE-2024-58136 — Yiiframework Yii Improper Protection of Alternate Path Vulnerability
732Secure AI-Generated Code at Speed with Snyk and ServiceNow
733CISA KEV: CVE-2024-38475 — Apache HTTP Server Improper Escaping of Output Vulnerability
734CISA KEV: CVE-2023-44221 — SonicWall SMA100 Appliances OS Command Injection Vulnerability
735CISA KEV: CVE-2025-31324 — SAP NetWeaver Unrestricted File Upload Vulnerability
736Black Hat Asia 2025: My Journey as a Reviewer, Speaker & Community Connector
737CISA KEV: CVE-2025-1976 — Broadcom Brocade Fabric OS Code Injection Vulnerability
738CISA KEV: CVE-2025-42599 — Qualitia Active! Mail Stack-Based Buffer Overflow Vulnerability
739CISA KEV: CVE-2025-3928 — Commvault Web Server Unspecified Vulnerability
740Snyk Ushers in the Future of DAST: AI-Driven Security for the Age of AI-Driven Development
741CISA KEV: CVE-2025-24054 — Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability
742CISA KEV: CVE-2025-31201 — Apple Multiple Products Arbitrary Read and Write Vulnerability
743CISA KEV: CVE-2025-31200 — Apple Multiple Products Memory Corruption Vulnerability
744Snyk’s Statement on the MITRE CVEs Program Funding Update
745CISA KEV: CVE-2021-20035 — SonicWall SMA100 Appliances OS Command Injection Vulnerability
746Snyk Security Solution Now Integrated into Google Cloud's Gemini Code Assist
747CISA KEV: CVE-2024-53150 — Linux Kernel Out-of-Bounds Read Vulnerability
748CISA KEV: CVE-2025-29824 — Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability
749CISA KEV: CVE-2025-30406 — Gladinet CentreStack and Triofox Use of Hard-coded Cryptographic Key Vulnerability
750CISA KEV: CVE-2025-31161 — CrushFTP Authentication Bypass Vulnerability
751CISA KEV: CVE-2025-22457 — Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability
752Get Off My Lawn and Fix Your Vulnerabilities!
753Q&A Session with Snyk & John Hammond: Your Fetch the Flag Questions, Answered
754CISA KEV: CVE-2025-24813 — Apache Tomcat Path Equivalence Vulnerability
755CISA KEV: CVE-2024-20439 — Cisco Smart Licensing Utility Static Credential Vulnerability
756Governance in DevSecOps: Measuring and Improving Security Outcomes
757CISA KEV: CVE-2025-2783 — Google Chromium Mojo Sandbox Escape Vulnerability
758CISA KEV: CVE-2019-9875 — Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability
759CISA KEV: CVE-2025-30154 — reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability
760CVE-2025-29927 Authorization Bypass in Next.js Middleware
761Overcoming AppSec Challenges in FinServ: How CIBC Balances Speed, Security, and Compliance
762CISA KEV: CVE-2017-12637 — SAP NetWeaver Directory Traversal Vulnerability
763CISA KEV: CVE-2024-48248 — NAKIVO Backup and Replication Absolute Path Traversal Vulnerability
764CISA KEV: CVE-2025-1316 — Edimax IC-7100 IP Camera OS Command Injection Vulnerability
765Building a Culture of Secure Coding: Empowering Developers to Build Resilient Software
766Unburdening Developers From Vulnerability Fatigue with Snyk Delta Findings
767CISA KEV: CVE-2025-30066 — tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability
768CISA KEV: CVE-2025-24472 — Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
769Reconstructing the TJ Actions Changed Files GitHub Actions Compromise
770CISA KEV: CVE-2025-21590 — Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability
771CISA KEV: CVE-2025-24201 — Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability
772Snyk and ServiceNow: Streamlining Vulnerability Management with ServiceNow VR Assignment Rules
773Snyk Helps Secure the Golang Bento Project
774AI Code Generation: Code Security & Quality, Benefits, Risks & Top Tools
775DevSecOps Automation Framework
776CISA KEV: CVE-2025-24993 — Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability
777CISA KEV: CVE-2025-24991 — Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability
778CISA KEV: CVE-2025-24985 — Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability
779CISA KEV: CVE-2025-24983 — Microsoft Windows Win32k Use-After-Free Vulnerability
780CISA KEV: CVE-2025-26633 — Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability
781CISA KEV: CVE-2024-13161 — Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability
782CISA KEV: CVE-2024-57968 — Advantive VeraCore Unrestricted File Upload Vulnerability
783CISA KEV: CVE-2025-25181 — Advantive VeraCore SQL Injection Vulnerability
784Learn about API security risks with the new Snyk Learn Learning Path
785Fetch the Flag CTF 2025 Community Writeups
786Can Snyk Detect JWT Security Issues?
787CISA KEV: CVE-2025-22226 — VMware ESXi, Workstation, and Fusion Information Disclosure Vulnerability
788CISA KEV: CVE-2025-22225 — VMware ESXi Arbitrary Write Vulnerability
789CISA KEV: CVE-2025-22224 — VMware ESXi and Workstation TOCTOU Race Condition Vulnerability
790CISA KEV: CVE-2024-50302 — Linux Kernel Use of Uninitialized Resource Vulnerability
791CISA KEV: CVE-2024-4885 — Progress WhatsUp Gold Path Traversal Vulnerability
792CISA KEV: CVE-2018-8639 — Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability
793CISA KEV: CVE-2022-43769 — Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability
794CISA KEV: CVE-2023-20118 — Cisco Small Business RV Series Routers Command Injection Vulnerability
795Solving Security Challenges with Snyk Code and Symbolic AI
796Celebrating Black History Month 2025 at Snyk
797Incorporating security by design: Managing risk in DevSecOps
798Can Snyk Find Weak Cryptographic Algorithms? Bye Bye MD5
799CISA KEV: CVE-2023-34192 — Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
800CISA KEV: CVE-2024-49035 — Microsoft Partner Center Improper Access Control Vulnerability
801CISA KEV: CVE-2024-20953 — Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability
802CISA KEV: CVE-2017-3066 — Adobe ColdFusion Deserialization Vulnerability
803CISA KEV: CVE-2025-24989 — Microsoft Power Pages Improper Access Control Vulnerability
804Snyk’s Fetch the Flag CTF is More Than Just a CTF
805CISA KEV: CVE-2025-0111 — Palo Alto Networks PAN-OS File Read Vulnerability
806CISA KEV: CVE-2025-23209 — Craft CMS Code Injection Vulnerability
807CISA KEV: CVE-2025-0108 — Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
808CISA KEV: CVE-2024-53704 — SonicWall SonicOS SSLVPN Improper Authentication Vulnerability
809CISA KEV: CVE-2024-57727 — SimpleHelp Path Traversal Vulnerability
810Do not pass GO - Malicious Package Alert
811CISA KEV: CVE-2025-24200 — Apple iOS and iPadOS Incorrect Authorization Vulnerability
812CISA KEV: CVE-2024-41710 — Mitel SIP Phones Argument Injection Vulnerability
813CISA KEV: CVE-2024-40891 — Zyxel DSL CPE OS Command Injection Vulnerability
814CISA KEV: CVE-2025-21418 — Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability
815CISA KEV: CVE-2025-21391 — Microsoft Windows Storage Link Following Vulnerability
816CISA KEV: CVE-2025-0994 — Trimble Cityworks Deserialization Vulnerability
817Consolidate Security Findings with Snyk and Google Security Command Center
818CISA KEV: CVE-2020-15069 — Sophos XG Firewall Buffer Overflow Vulnerability
819CISA KEV: CVE-2020-29574 — CyberoamOS (CROS) SQL Injection Vulnerability
820CISA KEV: CVE-2024-21413 — Microsoft Outlook Improper Input Validation Vulnerability
821CISA KEV: CVE-2022-23748 — Dante Discovery Process Control Vulnerability
822CISA KEV: CVE-2025-0411 — 7-Zip Mark of the Web Bypass Vulnerability
823Creating SBOMs with the Snyk CLI
824CISA KEV: CVE-2024-53104 — Linux Kernel Out-of-Bounds Write Vulnerability
825CISA KEV: CVE-2018-19410 — Paessler PRTG Network Monitor Local File Inclusion Vulnerability
826CISA KEV: CVE-2018-9276 — Paessler PRTG Network Monitor OS Command Injection Vulnerability
827CISA KEV: CVE-2024-29059 — Microsoft .NET Framework Information Disclosure Vulnerability
828CISA KEV: CVE-2024-45195 — Apache OFBiz Forced Browsing Vulnerability
829CISA KEV: CVE-2025-24085 — Apple Multiple Products Use-After-Free Vulnerability
830CISA KEV: CVE-2025-23006 — SonicWall SMA1000 Appliances Deserialization Vulnerability
831Reviving DevSecOps: How Snyk’s new framework builds trust and collaboration
832The First Round of Changes to Match Snyk's Design Language
833CISA KEV: CVE-2020-11023 — JQuery Cross-Site Scripting (XSS) Vulnerability
834Understanding the EU’s Cyber Resilience Act (CRA)
835Sneak Peek into Fetch the Flag CTF 2025
836CISA KEV: CVE-2024-50603 — Aviatrix Controllers OS Command Injection Vulnerability
837BFI’s Journey in Digital Transformation: A Fireside Chat on Elevating Application Security and Developer Experience
838Snyk Security Labs Testing Update: Cursor.com AI Code Editor
839Snyk Recognized as Trusted Partner and Innovator by JPMorganChase
840CISA KEV: CVE-2025-21335 — Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability
841CISA KEV: CVE-2024-55591 — Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
842CISA KEV: CVE-2023-48365 — Qlik Sense HTTP Tunneling Vulnerability
843CISA KEV: CVE-2024-12686 — BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection Vulnerability
844Securing GenAI Development with Snyk
845CISA KEV: CVE-2025-0282 — Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability
846CISA KEV: CVE-2020-2883 — Oracle WebLogic Server Unspecified Vulnerability
847CISA KEV: CVE-2024-55550 — Mitel MiCollab Path Traversal Vulnerability
848New Year, New Security Goals: Improve Your AppSec in 2025
849CISA KEV: CVE-2024-3393 — Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability
850Did You Make the *Security* Naughty or Nice List This Year?
851CISA KEV: CVE-2021-44207 — Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability
852CISA KEV: CVE-2024-12356 — BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection Vulnerability
853CISA KEV: CVE-2021-40407 — Reolink RLC-410W IP Camera OS Command Injection Vulnerability
854CISA KEV: CVE-2019-11001 — Reolink Multiple IP Cameras OS Command Injection Vulnerability
855CISA KEV: CVE-2022-23227 — NUUO NVRmini2 Devices Missing Authentication Vulnerability
856CISA KEV: CVE-2018-14933 — NUUO NVRmini Devices OS Command Injection Vulnerability
857CISA KEV: CVE-2024-55956 — Cleo Multiple Products Unauthenticated File Upload Vulnerability
858CISA KEV: CVE-2024-35250 — Microsoft Windows Kernel-Mode Driver Untrusted Pointer Dereference Vulnerability
859CISA KEV: CVE-2024-20767 — Adobe ColdFusion Improper Access Control Vulnerability
860CISA KEV: CVE-2024-50623 — Cleo Multiple Products Unrestricted File Upload Vulnerability
861Ultralytics AI Pwn Request Supply Chain Attack
862Snyk’s risk-based approach to prioritization
863CISA KEV: CVE-2024-49138 — Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability
864Snyk-Generated SBOMs Now Include License Details for the Open Source Libraries in Your Projects
865CISA KEV: CVE-2024-51378 — CyberPanel Incorrect Default Permissions Vulnerability
866Seven steps to close coverage gaps with ASPM
8672024 Open Source Security Report: Slowing Progress and New Challenges for DevSecOps
868CISA KEV: CVE-2024-11667 — Zyxel Multiple Firewalls Path Traversal Vulnerability
869CISA KEV: CVE-2024-11680 — ProjectSend Improper Authentication Vulnerability
870CISA KEV: CVE-2023-45727 — North Grid Proself Improper Restriction of XML External Entity (XXE) Reference Vulnerability
871Why a solid DevOps foundation is vital for effective DevSecOps
872Empowering women in security: The impact of mentorship
873Measuring AppSec success: Key KPIs that demonstrate value
874CISA KEV: CVE-2023-28461 — Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability
875CISA KEV: CVE-2024-21287 — Oracle Agile Product Lifecycle Management (PLM) Incorrect Authorization Vulnerability
876CISA KEV: CVE-2024-44309 — Apple Multiple Products Cross-Site Scripting (XSS) Vulnerability
877CISA KEV: CVE-2024-44308 — Apple Multiple Products Code Execution Vulnerability
878CISA KEV: CVE-2024-38813 — VMware vCenter Server Privilege Escalation Vulnerability
879CISA KEV: CVE-2024-38812 — VMware vCenter Server Heap-Based Buffer Overflow Vulnerability
880Women in security: Inspiring leaders of today and tomorrow
881CISA KEV: CVE-2024-9474 — Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability
882CISA KEV: CVE-2024-1212 — Progress Kemp LoadMaster OS Command Injection Vulnerability
883Understanding command injection vulnerabilities in Go
884CISA KEV: CVE-2024-9465 — Palo Alto Networks Expedition SQL Injection Vulnerability
885Snyk named a Customer Favorite in The Forrester Wave™: Software Composition Analysis Software, Q4 2024 Report
886Extending developer security with dev-first dynamic testing
887How ASPM boosts visibility to manage application risk
888CISA KEV: CVE-2021-26086 — Atlassian Jira Server and Data Center Path Traversal Vulnerability
889CISA KEV: CVE-2014-2120 — Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability
890CISA KEV: CVE-2021-41277 — Metabase GeoJSON API Local File Inclusion Vulnerability
891CISA KEV: CVE-2024-43451 — Microsoft Windows NTLMv2 Hash Disclosure Spoofing Vulnerability
892CISA KEV: CVE-2024-49039 — Microsoft Windows Task Scheduler Privilege Escalation Vulnerability
893CISA KEV: CVE-2019-16278 — Nostromo nhttpd Directory Traversal Vulnerability
894CISA KEV: CVE-2024-51567 — CyberPanel Incorrect Default Permissions Vulnerability
895CISA KEV: CVE-2024-43093 — Android Framework Privilege Escalation Vulnerability
896CISA KEV: CVE-2024-5910 — Palo Alto Networks Expedition Missing Authentication Vulnerability
897CISA KEV: CVE-2024-8956 — PTZOptics PT30X-SDI/NDI Cameras Authentication Bypass Vulnerability
898If you don’t know about HTTP Archive’s Web Almanac yet, you should!
899Lottie Player npm package compromised for crypto wallet theft
900Find, auto-fix, and prioritize intelligently, with Snyk's AI-powered code security tools
901CISA KEV: CVE-2024-37383 — RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability
902CISA KEV: CVE-2024-20481 — Cisco ASA and FTD Denial-of-Service Vulnerability
903Vulnerability-Free C and C++ development in automotive manufacturing and software defined vehicles (SDV)
904CISA KEV: CVE-2024-47575 — Fortinet FortiManager Missing Authentication Vulnerability
905Elevating views of risk: Holistic application risk management with Snyk
906Women - Kickstart your Application Security Career!
907CISA KEV: CVE-2024-38094 — Microsoft SharePoint Deserialization Vulnerability
908CISA KEV: CVE-2024-9537 — ScienceLogic SL1 Unspecified Vulnerability
909Ensuring comprehensive security testing in DevOps pipelines
910Introducing: Extensive AppSec visibility with Snyk Analytics
911Snyk announces commitment to Service for America, bringing security education access to all
912CISA KEV: CVE-2024-40711 — Veeam Backup and Replication Deserialization Vulnerability
913How Snyk is prioritizing developer experience
914CISA KEV: CVE-2024-28987 — SolarWinds Web Help Desk Hardcoded Credential Vulnerability
915CISA KEV: CVE-2024-9680 — Mozilla Firefox Use-After-Free Vulnerability
916CISA KEV: CVE-2024-30088 — Microsoft Windows Kernel TOCTOU Race Condition Vulnerability
917Automatically fix code vulnerabilities with AI
918Foundations of trust: Securing the future of AI-generated code
919Analyze Taint Analysis Faster with Improved Contextual Dataflow in Snyk Code
920CISA KEV: CVE-2024-9380 — Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability
921CISA KEV: CVE-2024-23113 — Fortinet Multiple Products Format String Vulnerability
922SnykLaunch Oct 2024: Enhanced PR experience, extended visibility, AI-powered security, holistic risk management
923CISA KEV: CVE-2024-43573 — Microsoft Windows MSHTML Platform Spoofing Vulnerability
924CISA KEV: CVE-2024-43572 — Microsoft Windows Management Console Remote Code Execution Vulnerability
925CISA KEV: CVE-2024-43047 — Qualcomm Multiple Chipsets Use-After-Free Vulnerability
926The mysterious supply chain concern of string-width-cjs npm package
927CISA KEV: CVE-2024-45519 — Synacor Zimbra Collaboration Suite (ZCS) Command Execution Vulnerability
928Proactive AppSec continuous vulnerability management for developers and security teams
929Snyk named a 2024 Gartner Peer Insights™ Customers’ Choice for Application Security Testing for the 3rd consecutive year
930CISA KEV: CVE-2024-29824 — Ivanti Endpoint Manager (EPM) SQL Injection Vulnerability
931Going beyond reachability to prioritize what matters most
932CISA KEV: CVE-2019-0344 — SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability
933CISA KEV: CVE-2020-15415 — DrayTek Multiple Vigor Routers OS Command Injection Vulnerability
934CISA KEV: CVE-2023-25280 — D-Link DIR-820 Router OS Command Injection Vulnerability
935Zero-day RCE vulnerability found in CUPS - Common UNIX Printing System
936Promise queues and batching concurrent tasks in Deno
937Identifying insecure C Code with Valgrind and fixing with Snyk Code
938CISA KEV: CVE-2024-7593 — Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability
939CISA KEV: CVE-2024-8963 — Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability
940Dive into AI and LLM learning with the new Snyk Learn learning path
941CISA KEV: CVE-2020-14644 — Oracle WebLogic Server Remote Code Execution Vulnerability
942CISA KEV: CVE-2022-21445 — Oracle ADF Faces Deserialization of Untrusted Data Vulnerability
943CISA KEV: CVE-2020-0618 — Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability
944CISA KEV: CVE-2024-27348 — Apache HugeGraph-Server Improper Access Control Vulnerability
945Meet Snyk for Government: Our developer security solution with FedRAMP ATO
946CISA KEV: CVE-2014-0502 — Adobe Flash Player Double Free Vulnerablity
947CISA KEV: CVE-2013-0648 — Adobe Flash Player Code Execution Vulnerability
948CISA KEV: CVE-2013-0643 — Adobe Flash Player Incorrect Default Permissions Vulnerability
949Want to avoid a data breach? Employ secrets detection
950CISA KEV: CVE-2024-6670 — Progress WhatsUp Gold SQL Injection Vulnerability
951CISA KEV: CVE-2024-43461 — Microsoft Windows MSHTML Platform Spoofing Vulnerability
952CISA KEV: CVE-2024-8190 — Ivanti Cloud Services Appliance OS Command Injection Vulnerability
953CISA KEV: CVE-2024-38217 — Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability
954CISA KEV: CVE-2024-38014 — Microsoft Windows Installer Improper Privilege Management Vulnerability
9555 reasons why developers at FinServ institutions are outpacing their security teammates
956CISA KEV: CVE-2024-40766 — SonicWall SonicOS Improper Access Control Vulnerability
957CISA KEV: CVE-2017-1000253 — Linux Kernel PIE Stack Buffer Corruption Vulnerability
958CISA KEV: CVE-2016-3714 — ImageMagick Improper Input Validation Vulnerability
959What you should know about PHP code security
960How Axel Springer National Media and Tech achieved continuous security with Snyk
961CISA KEV: CVE-2024-7262 — Kingsoft WPS Office Path Traversal Vulnerability
962CISA KEV: CVE-2021-20124 — Draytek VigorConnect Path Traversal Vulnerability
963The persistent threat: Why major vulnerabilities like Log4Shell and Spring4Shell remain significant
964CISA KEV: CVE-2024-7965 — Google Chromium V8 Inappropriate Implementation Vulnerability
965Snyk Code, the only security tool chosen by developers in Stack Overflow's 2024 AI Search and Developer Tools survey
966CISA KEV: CVE-2024-38856 — Apache OFBiz Incorrect Authorization Vulnerability
967Navigating the AI-powered development era in financial services
968A developer’s best friend: Lessons learned from our canine companions about AI code security
969CISA KEV: CVE-2024-7971 — Google Chromium V8 Type Confusion Vulnerability
970CISA KEV: CVE-2024-39717 — Versa Director Dangerous File Type Upload Vulnerability
971Three trends shaping software supply chain security today
972CISA KEV: CVE-2021-31196 — Microsoft Exchange Server Information Disclosure Vulnerability
973CISA KEV: CVE-2022-0185 — Linux Kernel Heap-Based Buffer Overflow Vulnerability
974CISA KEV: CVE-2021-33045 — Dahua IP Camera Authentication Bypass Vulnerability
975CISA KEV: CVE-2024-23897 — Jenkins Command Line Interface (CLI) Path Traversal Vulnerability
976The journey to AppSec gold: Lessons we can learn from the Olympians
977CISA KEV: CVE-2024-28986 — SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
978Vulnerabilities in NodeJS C/C++ add-on extensions
979Four easy ways to analyze your Java and Kotlin code
980CISA KEV: CVE-2024-38107 — Microsoft Windows Power Dependency Coordinator Privilege Escalation Vulnerability
981CISA KEV: CVE-2024-38193 — Microsoft Windows Ancillary Function Driver for WinSock Privilege Escalation Vulnerability
982CISA KEV: CVE-2024-38213 — Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
983CISA KEV: CVE-2024-38178 — Microsoft Windows Scripting Engine Memory Corruption Vulnerability
984CISA KEV: CVE-2024-38189 — Microsoft Project Remote Code Execution Vulnerability
985A security expert’s view on Gartner’s generative AI insights - Part 2
986CISA KEV: CVE-2024-32113 — Apache OFBiz Path Traversal Vulnerability
987CISA KEV: CVE-2024-36971 — Android Kernel Remote Code Execution Vulnerability
988Extend the power of your AppSec data with the new Snyk and Snowflake integration
989CISA KEV: CVE-2018-0824 — Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability
990A denial of service Regex breaks FastAPI security
991Preventing SQL injection in C# with Entity Framework
992CISA KEV: CVE-2024-37085 — VMware ESXi Authentication Bypass Vulnerability
993CISA KEV: CVE-2023-45249 — Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerability
994CISA KEV: CVE-2024-5217 — ServiceNow Incomplete List of Disallowed Inputs Vulnerability
995CISA KEV: CVE-2024-4879 — ServiceNow Improper Input Validation Vulnerability
996CISA KEV: CVE-2024-39891 — Twilio Authy Information Disclosure Vulnerability
997CISA KEV: CVE-2012-4792 — Microsoft Internet Explorer Use-After-Free Vulnerability
998Welcoming Diana Brunelle: Snyk’s New Chief People Officer
99910 Dimensions of Python Static Analysis
1000CISA KEV: CVE-2022-22948 — VMware vCenter Server Incorrect Default File Permissions Vulnerability
1001CISA KEV: CVE-2024-28995 — SolarWinds Serv-U Path Traversal Vulnerability
1002CISA KEV: CVE-2024-34102 — Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability
1003CISA KEV: CVE-2024-36401 — OSGeo GeoServer GeoTools Eval Injection Vulnerability
1004A stepping stone towards holistic application risk and compliance management of the Digital Operational Resiliency Act (DORA)
1005Going beyond “shift left” to extend AppSec in all directions
1006CISA KEV: CVE-2024-23692 — Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
1007CISA KEV: CVE-2024-38080 — Microsoft Windows Hyper-V Privilege Escalation Vulnerability
1008CISA KEV: CVE-2024-38112 — Microsoft Windows MSHTML Platform Spoofing Vulnerability
1009CISA KEV: CVE-2024-20399 — Cisco NX-OS Command Injection Vulnerability
1010Polyfill supply chain attack embeds malware in JavaScript CDN assets
1011CISA KEV: CVE-2020-13965 — Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability
1012CISA KEV: CVE-2022-2586 — Linux Kernel Use-After-Free Vulnerability
1013CISA KEV: CVE-2022-24816 — OSGeo GeoServer JAI-EXT Code Injection Vulnerability
1014Finding and fixing exposed hardcoded secrets in your GitHub project with Snyk
1015Snyk Code now secures AI builds with support for LLM sources
1016Why ASPM is the future of AppSec: Key points from our newest whitepaper
1017Automate security controls from development to production on Google Cloud
1018Integrating the Snyk Language Server with IntelliJ IDEs
10194 AI coding risks and how to address them
1020Why “vulnerability management” falls short in modern application security
1021CISA KEV: CVE-2024-4358 — Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability
1022CISA KEV: CVE-2024-26169 — Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability
1023CISA KEV: CVE-2024-32896 — Android Pixel Privilege Escalation Vulnerability
1024Snyk and AWS announce native Amazon EKS support directly from the AWS Management Console
1025Essential Node.js backend examples for developers in 2024
1026CISA KEV: CVE-2024-4577 — PHP-CGI OS Command Injection Vulnerability
1027AI quality: Garbage in, garbage out
1028Talk to us about Snyk CLI
1029Securing next-gen development: Lessons from Trust Bank and TASConnect
1030Secure AI tool adoption: Perceptions and realities
1031Snyk sponsors Snowflake Summit
103210 modern Node.js runtime features to start using in 2024
1033Fastify plugins as building blocks for a backend Node.js API
1034Preventing broken access control in express Node.js applications
1035Learning from cloud transformation as we move to AI
1036Symmetric vs. asymmetric encryption: Practical Python examples
1037AppSec spring cleaning checklist
1038Meet the new host for The Secure Developer podcast
1039Integrating Snyk Code SAST results in your ServiceNow workflows
1040More accurate than GPT-4: How Snyk’s CodeReduce improved the performance of other LLMs
1041Snyk AppRisk Pro: A holistic approach to application risk management
1042Snyk CLI: Introducing Semantic Versioning and release channels
1043How Mulesoft fosters a developer-first, shift-left culture with Snyk
1044360 degrees of application security with Snyk
1045Snyk Code’s auto-fixing feature, Snyk Agent Fix, just got better
1046DevOpsDays Singapore 2024: Unmasking the security pitfalls in AI-generated code
1047Building an npm package compatible with ESM and CJS in 2024
1048Day in the life of a food giant CISO
1049An investigation into code injection vulnerabilities caused by generative AI
1050How SAS secures their AI-generated code
1051Nine Docker pro tips for Node.js developers
1052Six takeaways from our ASPM masterclass series
1053Exploiting HTTP/2 CONTINUATION frames for DoS attacks
1054The XZ backdoor CVE-2024-3094
1055Securing your SBOM on Google Cloud
1056How Snyk ensures safe adoption of AI
1057Getting started with PHP static analysis in 2024
1058Snyk's AppSec dream team
1059Snyk users don't have to worry about NVD delays
1060GitHub “besieged” by malware repositories and repo confusion: Why you'll be ok
1061AppSec Maturity Models
1062Snyk Learn and the NIST Cybersecurity Framework (CSF)
1063Welcoming Gary Olson: Snyk’s new Chief Revenue Officer
1064Essential AI Tools to Boost Developer Productivity and Security
1065Defense in Depth
1066Snyk documentation: Our journey so far
10675 Node.js security code snippets every backend developer should know
1068How REI built a DevSecOps culture and how Snyk helped
1069Preventing server-side request forgery in Node.js applications
1070Preventing SQL injection attacks in Node.js
1071With Love, Your Applications
1072Snyk & Atlassian: How to embed security in AI-assisted software development
1073Reporting AppSec risk up to your CISO
1074Automatic source locations with Rego
1075Welcoming Danny Allan and Brian Rogan: Snyk leadership team expands with key appointments to accelerate innovation
1076The 4 best DevSecOps tools for a secure DevOps workflow
1077New Year's security resolutions for 2024 from Snyk DevRel, SecRel, and friends
1078Understanding and mitigating the Jinja2 XSS vulnerability (CVE-2024-22195)
1079Snyk welcomes Helios, accelerating our ASPM vision with runtime insights
1080Build and deploy a Node.js security scanning API to Platformatic Cloud
1081Krampus delivers an end-of-year Struts vulnerability
1082Kroger’s approach to supply chain security
1083Command injection in Python: examples and prevention
1084Is your team on the *security* naughty or nice list?
1085Vulnerability disclosure: Which comes first, the security bug in PHP or the CVE?
1086Common SAML vulnerabilities and how to remediate them
1087Snyk named as a top cybersecurity company in inaugural Fortune Cyber 60 2023 list
1088Enhancing code to cloud security with the Common Configuration Scoring System
1089Snyk highlights AWS re:Invent 2023
1090Three reasons to invest in an ASPM solution in 2024
1091Snyk recognized as an Emerging Segment Leader in Application Security in Snowflake's Next Generation of Cybersecurity Applications report
1092Code injection in Python: examples and prevention
1093Secure password hashing in Go
1094Accelerate C/ C++ security with Snyk
1095Snyk named a 2023 Gartner Peer Insights™ Customers’ Choice for Application Security Testing
1096Achieving developer security adoption at Nylas with Snyk
1097Snyk Fetch the Flag CTF 2023 writeup: Off the SETUID
1098Snyk Fetch the Flag CTF 2023 writeup: Honey Baked Messages
1099Snyk Fetch the Flag CTF 2023 writeup: Protect The Environment
1100Snyk is your security companion for Amazon CodeWhisperer
1101Handling security vulnerabilities in Spring Boot
1102Nightfall AI and Snyk unite to deliver AI-powered secrets scanning for developers
11034 Advantages of using AI code review
1104A DevSecOps solution for your apps on AWS from Snyk
1105Exploring WebExtension security vulnerabilities in React Developer Tools and Vue.js devtools
1106File encryption in Python: An in-depth exploration of symmetric and asymmetric techniques
1107Our favorite 2023 Snyk Fetch the Flag CTF writeups from the community
1108Improving the UI/UX of the Snyk VS Code extension
1109Snyk Apps now GA: An easy, standardized, and secure framework for building custom integrations
1110Vulnerability vs Weakness: Understanding Key Differences in AppSec
1111Rego 103: Types of values and rules
1112Snyk achieves AWS Security Competency
1113Demystifying the AWS shared security responsibility model
1114Real-time threat protection with Snyk and SentinelOne
1115Rego 102: Combining queries with AND/OR and custom messages
1116Snyk Week of Impact 2023: A week of meaningful contributions and community engagement
1117What’s new in CVSS 4.0
1118Secure your software supply chain with the new Snyk Vulnerability Intelligence for SBOM ServiceNow integration
1119Security vs. Development: A game of priorities
1120Asset-first application security: What is it and how can it help
1121What does Biden's Executive Order on AI safety measures mean for businesses?
1122Rego 101: Introduction to Rego
1123Dependency injection in Python
1124Snyk welcomes Reviewpad: Code, commit, celebrate!
1125The art of conditional rendering: Tips and tricks for React and Next.js developers
1126Weak Hash vulnerability discovered in crypto-js and crypto-es (CVE-2023-46233 & CVE-2023-46133)
1127Why You Need a Security Companion for AI-Generated Code
1128Adding Snyk security to Jira and Bitbucket Cloud
1129Getting started with query parameterization
1130Power up security collaboration with Snyk and Slack
1131Securing symmetric encryption algorithms in Java
1132Installing and managing Java on macOS
1133Find and fix HTTP/2 rapid reset zero-day vulnerability CVE-2023-44487
1134Cybersecurity Venture’s 2023 Software Supply Chain Attack Report
1135SAS and Snyk discuss the future of AI for development and security teams
1136High severity vulnerability found in libcurl and curl (CVE-2023-38545)
1137Priorities from the OpenSSF Secure Open Source Software Summit 2023
1138Snyk Partner Speak video series with HashiCorp
1139Does AI lead to AppSec hell or nirvana?
1140Modern VS Code extension development tutorial: Building a secure extension
1141Critical WebP 0-day security CVE-2023-4863 impacts wider software ecosystem
1142Signing container images: Comparing Sigstore, Notary, and Docker Content Trust
1143Snyk is named a Strong Performer as a first-time entrant in the Forrester Wave™: Static Application Security Testing (SAST) Q3 2023
1144Developer-first supply chain security
1145Modern VS Code extension development: The basics
1146Security implications of cross-origin resource sharing (CORS) in Node.js
1147An Introduction to capture the flag
1148A guide to input validation with Spring Boot
1149Top considerations for addressing risks in the OWASP Top 10 for LLMs
1150Fetch the Flag CTF 2023 sneak peek
1151Node.js vs. Deno vs. Bun: Performance & JavaScript Runtime Comparison
11527 AppSec tips from Snowflake’s Director of Product Security
1153What kind of (security) dog are you?
1154How Okta empowers devs to find & fix security issues with Snyk
1155Using JLink to create smaller Docker images for your Spring Boot Java application
1156Streamline dependency updates with Mergify and Snyk
1157Does GitOps enhance application security?
1158What are AI hallucinations and why should developers care?
1159Secure Java URL encoding and decoding
1160CodeSecDays conference and more complete security coverage with GitGuardian
1161Manage security issues in Jira with Snyk Security in Jira Cloud
1162.NET developers alert: Moq NuGET package exfiltrates user emails from git
1163Snyk Ranked #19 on 2023 Forbes Cloud 100 List
1164Limitations of a single AI model
1165Mitigating DOM clobbering attacks in JavaScript
1166New SEC cybersecurity rules put more onus on the CISO, not so much on directors
1167Discussions on improving security through chaos engineering
1168Software Supply Chain Security Tools: Types, Features & Considerations
1169How Snyk can help secure supply chains per "A Guide to Implementing the Software Bill of Materials (SBOM) for Software Management"’ by Japan's METI
1170Implementing TLS in Kubernetes
1171How secure is WebAssembly? 5 security concerns unique to WebAssembly
1172Control your role! Kubernetes RBAC explored
1173Snyk's 2023 State of Open Source Security: Supply chain security, AI, and more
1174Finding and fixing insecure direct object references in Python
1175Swift deserialization security primer
1176XS leaks: What they are and how to avoid them
1177Building a security-conscious CI/CD pipeline
1178The importance of verifying webhook signatures
1179Using insecure npm package manager defaults to steal your macOS keyboard shortcuts
1180Mimic your mental model with Project Collections
1181Maximizing IAM security with AWS permissions boundaries and Snyk
1182Research with Snyk and Redhunt Labs: Scanning the top 1000 orgs on GitHub
1183SnakeYaml 2.0: Solving the unsafe deserialization vulnerability
1184Patches of Pride: Love, inclusivity, & cute pets in celebration of Pride month
1185Understanding Kubernetes Pod Security Standards
1186Celebrating Juneteenth at Snyk
1187The SecurityManager is getting removed in Java: What that means for you
1188Snyk named a Leader, placed highest in Strategy category in The Forrester Wave: Software Composition Analysis (SCA), Q2 2023 report
1189Snyk Partner Speaks series: True DevSecOps with Snyk and Dynatrace
1190Snyk welcomes Enso: Enabling security leaders to scale their AppSec program with ASPM
1191Snyk Learn now aligns with the NIST NICE Workforce Framework
1192Reduce risk to your supply chain with a software bill of materials (SBOM)
1193SnykLaunch June ‘23: Insights and DeepCode AI enable faster fixes and prioritization
1194What can you do with an enriched SBOM? A parlay quickstart guide