CodeBreach: AWS CodeBuild misconfiguration → full SDK takeover
Google weaponizes Net-NTLMv1 with rainbow tables
OpenCode CVSS 10.0 RCE (unauthenticated localhost server)
Svelte ecosystem: 5 CVEs DoS + XSS
Handling shell secrets without leaking to /proc
#AppSec
CodeBreach: AWS CodeBuild misconfiguration → full SDK takeover
Google weaponizes Net-NTLMv1 with rainbow tables
OpenCode CVSS 10.0 RCE (unauthenticated localhost server)
Svelte ecosystem: 5 CVEs DoS + XSS
Handling shell secrets without leaking to /proc
#AppSec
🪓 6-bug chain → pre-auth RCE in LogPoint SIEM
🪓 PassSeeds: hijacking passkeys for crypto beyond WebAuthn
🪓 Tailscale kills default TPM encryption
🪓 Malicious VS Code extensions in the wild
🪓 Notion AI prompt injection exfiltration
🪓 npm staged publishing post
#AppSec
🪓 6-bug chain → pre-auth RCE in LogPoint SIEM
🪓 PassSeeds: hijacking passkeys for crypto beyond WebAuthn
🪓 Tailscale kills default TPM encryption
🪓 Malicious VS Code extensions in the wild
🪓 Notion AI prompt injection exfiltration
🪓 npm staged publishing post
#AppSec
MongoDB CVE that hit self-hosted instances
tokenless CSRF making it into OWASP guidance
OpenPGP implementation bugs.
LangChain CVE-2025-68664
TruffleHog's JWT liveness checks.
appsecweekly.net/p/issue-14-a...
#DevSecOps
MongoDB CVE that hit self-hosted instances
tokenless CSRF making it into OWASP guidance
OpenPGP implementation bugs.
LangChain CVE-2025-68664
TruffleHog's JWT liveness checks.
appsecweekly.net/p/issue-14-a...
#DevSecOps