Inside the Metabase SQLi: Exploited in the Wild
Technical analysis of a Metabase SQL injection vulnerability actively exploited in the wild.
Cloud security research and engineering insights by Rami McCarthy.
Technical analysis of a Metabase SQL injection vulnerability actively exploited in the wild.
Analysis of a supply chain attack hijacking the popular keyv and cacheable npm packages.
Analysis of a supply chain attack on AsyncAPI exploiting a pwn request vulnerability in GitHub Actions, resulting in malicious npm packages with multi-stage payloads.
Analysis of Miasma, a supply chain attack targeting 32 @redhat-cloud-services npm packages via OIDC trusted publishing abuse.
Analysis of TeamPCP's PyPI supply chain attack targeting the durabletask package.
Analysis of TeamPCP's supply chain attack targeting @antv packages on npm.
Technical analysis of Fragnesia, a Linux kernel local privilege escalation vulnerability in ESP-in-TCP packet handling.
Analysis of TeamPCP's continued npm supply chain attacks targeting TanStack and other popular packages.
Analysis of a Linux kernel local privilege escalation vulnerability in ESP and RxRPC packet fragmentation handling.
A comprehensive guide to securing your software supply chain through practical package security measures.