Dependabot alerts now cover more ecosystems by ingesting malware advisories from the OpenSSF malicious-packages repository.
• Expanded malware data includes npm, PyPI, and more ecosystems
https://t.co/hZS2a7NEQe
The Python Package Index is introducing new restrictions to protect Python package installers and inspectors from ZIP confusion attacks. There is no evidence that this vulnerability has been exploited. Read the blog post for more information:
https://t.co/AnacA4HTSa
The Malicious Packages repository contains 16,000
Data points including:
✨Contains 9k examples from npm, 6.5k from pypi, and some from rubygems and https://t.co/a8GQJOThtZ
Download the OpenSSF 2023 Annual Report and learn more: https://t.co/5zy1dffq06
#OSSSecurity
The Package Analysis project analyzed over 5 million
packages in the last year
PyPI: 1M 🐍
RubyGems: 82K 💎
Packagist: 226K 📦
NPM: 3.5M 📜
https://t.co/Iv7Fx5R48z: 209K 🦀
Learn more: https://t.co/5zy1dffXPE
#OSSSecurity
The OpenSSF Package Analysis team is excited to announce launch of our Malicious Packages repository, the 1st open source system for collecting & publishing cross-ecosystem reports of malicious packages. Learn more: https://t.co/4iIZI9x3cF
Excited to share that my son Nathan Naveen, a high school student, will be presenting at SupplyChain Security Con! In his lightning talk, he will share his journey with OpenSSF and unveil criticality scores. #supplychainsecuritycon#openssf
https://t.co/RuK9FINqn2
Today we take you behind the scenes like never before, learn about the work @Google's security experts do behind closed doors to keep billions safe every day. The HACKING GOOGLE docuseries is streaming NOW on @YouTube → https://t.co/QP1TpgPXgV
Join @jamiedukee in his talk "Hacking Rental e-Scooters - Real World Examples" as he discusses the scooter iot devices, methods such as social & reverse engineering will be discussed, code, exploits and documentation for these attacks will be showcased.
https://t.co/u9jeB48VRg
Join @CalebBrown in his talk "OpenSSF's Package Analysis" as he discusses the challenges with uploading malicious packages to a package repository, typosquatting, and dependency confusion. He will be sharing stories and what do we do about this?
https://t.co/ssCCwrZtFa
Proof that fuzzing can discover exploitable vulnerabilities that aren't memory corruption! OSS-Fuzz discovered a very interesting command injection vulnerability which was just fixed: https://t.co/QOw9Vv26RE
We are proud to be working with organizations like @Google make open source more secure than ever before.
Watch #Google's Caleb Brown talk about how OpenSSF is improving the state of #opensource#software#security!
Full interview here: https://t.co/83p65d91xK
@MarkHnsn @OpenSSF Discord attacks are usually either premium account theft, fraud/scams or for finding privileged data. For example: this is a recent fraud attack being done with stolen Discord and Instagram access: https://t.co/XNq6q6izeb
Over the last few months I've been working on an Open Source project for the @openssf to analyse packages available on public repositories to detect maliciousness. Read more about it here:
https://t.co/q3zTtbLcpb and here: https://t.co/C6hVaRlCzU
This log4j exploit = remote code execution in basically everything
Arbitrary code execution in iCloud, Twitter, Steam, CloudFlare, Amazon, Tesla, Baidu, Tencent
This may well be devastating 0day RCE exploit that has ever been dropped in all of history.
https://t.co/CeQNtSBpZV
House selling protip: don't leave your work username and password stuck up on the wall while random strangers walk through your house.
Also: "P@ssword123" is not a great password.
We're feeling...electric. Get charged up with a new @googlemaps that brings helpful information about electric vehicle charging stations so your 🚗 is ready to ride → https://t.co/mMIvJgunmK