Security News

Vim devs fix system-pwning text editor bug
2019-06-13 14:02

Diehard text editor users everywhere breathed a sigh of relief this week as the open source community fixed a bug in one of the most venerable *nix programs: Vim.

Devs slam Microsoft for injecting tech-support scam ads into their Windows Store apps
2019-06-04 05:06

Redmond kinda just shrugs after advertising systems sling scareware pop-ups at users Application makers are crying foul after some of their programs distributed via the Windows Store pops open...

Chrome extension devs must drop deceptive installation tactics
2019-05-31 09:41

After announcing its intention to limit third-party developers’ access to Chrome’s webRequest API, which is used by many ad-blocking extensions to filter out content, Google has followed up with...

Freelance devs: Oh, you wanted the app to be secure? The job spec didn't mention that
2019-03-11 06:14

Boffins find pros-for-hire no better at writing secure code than compsci beginners Freelance developers hired to implement password-based security systems do so about as effectively as computer...

As netizens, devs scream bloody murder over Chrome ad-block block, Googlers insist: It's not set in stone (yet)
2019-01-23 22:11

Advertising giant insists it's all still on drawing board – as plugin devs face code rewrites Analysis Following uproar from developers and netizens over proposed changes to Chrome that threaten...

Open-source devs: Wget off your bloated festive behinds and patch this user cred-blabbing bug
2019-01-02 11:36

New year, new security fails, new CVE Happy New Year! Oh, and if you include GNU's wget utility in software you write, pull down the new version released on Boxing Day and push out updates to your users.…

Twitter: Don't panic, but we may have leaked your DMs to rando devs
2018-09-21 21:45

Internet outrage mobile insists year-long API bug would have been super-hard to exploit Twitter is in full damage control mode after disclosing that it may have inappropriately exposed some...

Gits exposed, kinky app devs spanked, Feds spy on spyware buyers, etc
2018-09-08 09:46

Mac APT unearthed and other infosec bits and bytes summarized just for you Roundup This week brought with it a Supermicro shoring up firmware security, a North Korean hacking charge, and a spying...

Hey you smart, well-paid devs. Stop clicking on those phishing links and bringing in malware muck on your shoes
2018-07-25 19:02

At Node Summit, coders served some humble pie Software developers have been lionized in recent years for their influence over the information economy. At the Node Summit in San Francisco,...

Devs know application security is important, but have no time for it
2018-04-17 12:10

Sonatype polled 2,076 IT professionals to discover practitioner perspectives on evolving DevSecOps practices, shifting investments, and changing perceptions, and the results of the survey showed...