#softwaresecurity

4 posts · Last used 18d

Back to Timeline
Pedram @psoheil@c.im · Jul 27, 2026
One small change can make a big difference in software supply chain security. PyPI has introduced a new safeguard that rejects uploads of new files to package releases older than 14 days. This helps prevent attackers who compromise a maintainer’s account or publishing pipeline from silently adding malicious files to a long-trusted package version months after it was released. While this doesn’t eliminate all supply chain threats, it significantly reduces the risk of “package poisoning” attacks against pinned dependencies and encourages immutable releases, a security best practice every ecosystem should strive for. Security isn’t about a single silver bullet, it’s about layering defenses that make attacks increasingly difficult. Could we see similar protections become the standard across other package registries like npm, NuGet, and RubyGems? https://cybersecuritynews.com/pypi-14-day-release-lock/amp/ #CyberSecurity #AppSec #SupplyChainSecurity #PyPI #Python #DevSecOps #SoftwareSecurity #OpenSource #SecureByDesign #SoftwareSupplyChain #Infosec
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 24, 2026
GitHub updates its bug bounty program on July 27, cutting public payouts while moving maximum rewards to an invite-only VIP program. #GitHub #BugBounty #Cybersecurity #InfoSec #SoftwareSecurity https://meterpreter.org/github-bug-bounty-payouts/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Curtis Carter @codingcoyote@floss.social · Jul 18, 2026
Reasons you still need a human in the loop: "Researcher poisons open-weight AI model for under $100 https://share.google/6GPUoUdIMJG8EFPWh" Besides the occasional hallucinations, the lack of creativity, and an inability to encode certain types of info into the models (at least for now), #security is a huge issue. A #developer experienced in spotting malicious code and exploitable patterns can catch this sort of issue as often as in regular code reviews. #softwareDevelopment #AI #softwaresecurity
1
0
0
The Bad Place @TheBadPlace@mastodon.ozioso.online · Apr 09, 2026
The Guardian | Anthropic says its latest AI model can expose weaknesses in software security by Agence France-Presse AI company says purpose of its Claude Mythos model is to bolster defenses against hacking in common applications Anthropic on Tuesday said its yet-to-be-released artificial intelligence model called Claude Mythos has proven keenly adept at exposing software weaknesses. Mythos has laid bare thousands of vulnerabilities in commonly used applications for which no patch or fix exists, prompting the San Francisco-based AI startup to form an alliance with cybersecurity specialists to bolster defenses against hacking and withhold wide distribution. Continue reading... Read more: https://www.theguardian.com/technology/2026/apr/08/anthropic-ai-cybersecurity-software #ai(artificialintelligence) #anthropic #cybersecurityspecialists #softwaresecurity #vulnerabilities
0
0
0

You've seen all posts