RSS Anyway
Sign in
RSS Anyway
Hot
Latest
Following
Status
About
Sign in
RSS Anyway
Hot
Latest
Following
Status
About
corgea.com
Sign in to follow
corgea.com
RSS
Atom
JSON
items
|
feeds
01.
ViteVenom: seven fake Vite npm scopes used blockchain dead-drops to launch a detached RAT
corgea.com
·
/rss.xml
▲ 0
· Jul 22
02.
Weekly Briefing - 21-07-2026
corgea.com
·
/rss.xml
▲ 0
· Jul 21
03.
SleeperGem: hijacked dormant RubyGems accounts turned `require` into a persistent developer backdoor
corgea.com
·
/rss.xml
▲ 0
· Jul 19
04.
CVE-2026-48815: `sigstore-js` dropped `certificateOIDs` checks, weakening JavaScript artifact-verification policy
corgea.com
·
/rss.xml
▲ 0
· Jul 16
05.
Changelog - July 16, 2026
corgea.com
·
/rss.xml
▲ 0
· Jul 16
06.
11 malicious NuGet tools disguised as game cheats stage `pepesoft.exe` and spreadsheet-backed host surveillance
corgea.com
·
/rss.xml
▲ 0
· Jul 15
07.
Weekly Briefing - 14-07-2026
corgea.com
·
/rss.xml
▲ 0
· Jul 14
08.
AsyncAPI's July 14 npm compromise chained `pull_request_target`, unsigned branch pushes, and require-time malware
corgea.com
·
/rss.xml
▲ 0
· Jul 14
09.
Compromised `jscrambler` npm releases escalated from preinstall dropper to import-time Rust infostealer
corgea.com
·
/rss.xml
▲ 0
· Jul 13
10.
CVE-2026-54174: `apko` and `melange` trusted APK control metadata without proving the installed data section
corgea.com
·
/rss.xml
▲ 0
· Jul 13
11.
Injective's 1.20.21 npm release turned wallet key derivation into mnemonic and private-key exfiltration
corgea.com
·
/rss.xml
▲ 0
· Jul 11
12.
Braintree.Net on NuGet skims live card data, merchant keys, and host secrets in production
corgea.com
·
/rss.xml
▲ 0
· Jul 11
13.
Malicious Go command module stages PowerShell loader and links to a 222-repository GitHub lure network
corgea.com
·
/rss.xml
▲ 0
· Jul 9
14.
Changelog - July 9, 2026
corgea.com
·
/rss.xml
▲ 0
· Jul 9
15.
Paysafe, Skrill, and Neteller typosquats on npm and PyPI stole developer secrets
corgea.com
·
/rss.xml
▲ 0
· Jul 8
16.
CVE-2026-33264: Apache Airflow let DAG authors cross into scheduler and API-server RCE
corgea.com
·
/rss.xml
▲ 0
· Jul 8
17.
Snyk vs Veracode: Full Comparison + Why Teams Are Choosing Corgea
corgea.com
·
/rss.xml
▲ 0
· Jul 8
18.
Checkmarx vs Veracode: Full Comparison + Why Teams Are Choosing Corgea
corgea.com
·
/rss.xml
▲ 0
· Jul 8
19.
Weekly Briefing - 07-07-2026
corgea.com
·
/rss.xml
▲ 0
· Jul 7
20.
CVE-2026-53359: Januscape turns KVM shadow-page role confusion into Linux guest-to-host escape
corgea.com
·
/rss.xml
▲ 0
· Jul 7
21.
Rollup polyfill lookalikes on npm hide an import-time loader, JSONKeeper stage, and 216.126.236.244 RAT
corgea.com
·
/rss.xml
▲ 0
· Jul 6
22.
The Crypto Wars are back, this time over AI models
corgea.com
·
/rss.xml
▲ 0
· Jul 6
23.
FBI TeamPCP alert ties Trivy, KICS, LiteLLM, and Telnyx into one supply-chain playbook
corgea.com
·
/rss.xml
▲ 0
· Jul 5
24.
CVE-2026-46242: Bad Epoll turns Linux eventpoll cleanup into local root
corgea.com
·
/rss.xml
▲ 0
· Jul 5
25.
CVE-2026-12481: Keras Lambda.from_config() turns unset safe mode into code execution
corgea.com
·
/rss.xml
▲ 0
· Jul 4
26.
PolinRider expands from npm into Go, Packagist, and Chrome extension supply-chain poisoning
corgea.com
·
/rss.xml
▲ 0
· Jul 3
27.
Corgea vs. Snyk: We benchmarked SAST on a deliberately vulnerable repo
corgea.com
·
/rss.xml
▲ 0
· Jul 2
28.
Corgea vs. Aikido: We benchmarked SAST on a deliberately vulnerable repo
corgea.com
·
/rss.xml
▲ 0
· Jul 2
29.
Changelog - July 2, 2026
corgea.com
·
/rss.xml
▲ 0
· Jul 2
30.
CVE-2026-55407: `buffa` and `connectrpc` amplify tiny protobuf payloads into Rust OOMs
corgea.com
·
/rss.xml
▲ 0
· Jul 1
page 1
next →