Tag: software development
144 articles

DevSecOps: Must-Have Best Practices for Ultimate Security
Join NIST NCCoE’s virtual event on August 27, 2025 to learn practical DevSecOps best practices from leading experts and discover how to weave security into every step of your software lifecycle. With cybercrime costs soaring, this is your chance to balance speed and safety through automation, compliance tips, and real-world lessons that make your software more resilient.

Secure Software Development: Must-Have Best Practices
Worried about the security of the software we all depend on? Join NIST NCCoE’s interactive DevSecOps virtual event on August 27, 2025, to hear experts, learn practical secure development practices, and help turn security from an afterthought into a foundation for every project.

SharePoint RCE flaw: Urgent Critical Patch Warning
Microsoft has released an urgent out-of-band patch for a critical SharePoint RCE vulnerability being actively exploited—apply the update to all on-premises servers now to prevent data theft, lateral movement, or ransomware. Verify previous mitigations, ramp up monitoring, and ensure backups and incident plans are ready to limit any damage.

npm package malware: Must-Have Best Defenses
Think a routine dependency update is harmless? The recent npm malware attack—where phishers stole maintainer tokens to publish malicious versions of five popular packages—proves supply-chain trust can be shattered and why maintainers, consumers, and registries must act now to enforce 2FA, rotate tokens, and verify publish provenance.

ZuRu Critical Threat: Exclusive Must-Have Defense
A new ZuRu malware strain is quietly targeting macOS developer machines and toolchains, putting builds, secrets, and the entire software supply chain at risk. Harden workstations, isolate builds, and secure credentials now to prevent a single compromised device from triggering a widespread breach.

North Korean Hackers Intensify Campaign with New Malware Loader
North Korean hackers have taken their game to a new level, sneaking a dangerous malware loader into the trusted npm registry—putting thousands of developers and organizations at risk without them even knowing it. Stay ahead of the threat that’s shaking the very foundation of software supply chains worldwide.

North Korean Hackers Widen Contagious Interview Malware Campaign
Think twice before downloading that interview prep package—North Korean hackers are stealthily slipping dangerous malware into popular npm tools, turning trusted resources into digital traps for developers worldwide.

The Unusual Suspect in Code: How Git Repos Impact Security
Think Git is just a collaboration tool? Think again—exposed Git repositories are quietly fueling some of today’s biggest security breaches by leaking sensitive data right under our noses.

The Unusual Suspect in Coding: Understanding Git Repos
Think exposed Git repositories are harmless? Think again—these hidden gateways quietly grant hackers unseen access, turning everyday coding mishaps into major security nightmares.

Over 600 Laravel Apps Risk Remote Code Execution from Leaked APP_KEYs
Over 600 Laravel apps are at serious risk as leaked APP_KEYs open the door for hackers to run malicious code remotely—here’s what every developer needs to know to protect their projects.

ZuRu Malware Targets Developers Through Trojanized Termius macOS App
Cybercriminals have compromised the trusted macOS SSH client Termius, deploying the ZuRu malware through trojanized installers that stealthily infiltrate developers’ systems and threaten critical infrastructure access. This targeted attack underscores the urgent need for heightened vigilance as adversaries exploit trusted tools to gain strategic footholds in high-value environments.

Alarming 188% Annual Increase in Malicious Open Source Packages
Discover the shocking 188% annual rise in malicious open source packages and its implications for developers and software security.

Microsoft Windows Firewall Raises Concerns Over Microsoft Code
Microsoft Windows Firewall raises concerns over the security of Microsoft code, highlighting potential vulnerabilities and risks for users.

Cisco Alerts Users to Hardcoded Root SSH Credentials in Unified CM
Cisco warns users of hardcoded root SSH credentials in Unified CM, urging immediate updates to safeguard against potential security risks.

Grok 4 Emerges Before Launch with Unique Coding Capabilities
Grok 4 debuts with innovative coding features, set to revolutionize programming efficiency and enhance developer creativity before its official launch.

Microsoft Releases VS Code Copilot Chat Extension as Open Source on GitHub
Microsoft has launched the VS Code Copilot Chat Extension as open source on GitHub, enhancing developer productivity with AI-powered coding assistance.

Security Vulnerability in IDEs: Malicious Extensions Can Evade Verification in Visual Studio Code
Learn how malicious extensions can exploit security vulnerabilities in IDEs like Visual Studio Code, evading verification and jeopardizing developer safety.

Windows 11 Update KB5060829 Introduces 38 New Features and Fixes
Discover Windows 11 Update KB5060829, featuring 38 new enhancements and fixes to improve performance and user experience. Update now!

Surge of ‘Fake Interviews’ Deploys 35 NPM Packages to Distribute Malware
“Discover how a surge in fake interviews is leveraging 35 NPM packages to distribute malware, posing risks to developers and users alike.”

AI Boosts Code Generation: Implications for AppSec Teams
Explore how AI enhances code generation and its implications for AppSec teams, improving security measures and streamlining development processes.

North Korea-Linked Cyberattack: 35 Malicious npm Packages Target Developers
North Korea-linked cyberattack reveals 35 malicious npm packages targeting developers, posing serious security risks and undermining software integrity.

AdaCore and CodeSecure Join Forces to Create Integrated Developer Solutions
AdaCore and CodeSecure unite to deliver integrated developer solutions, enhancing software security and reliability for modern applications.

Stealthy Malware Campaign by Banana Squad Aims at Developers on GitHub
Stealthy malware campaign by Banana Squad targets GitHub developers, exploiting vulnerabilities to deliver malicious payloads and compromise projects.

Ultimate Guide to Secure Vibe Coding
Master secure coding with our ultimate guide on Vibe Coding. Learn essential practices to protect your applications and enhance security.