Skip to content
GeekWire
  • HOME
  • NEWS
    • CERT
    • EXPLOITS
    • NCSC
    • NVD
    • SECURELIST
    • US-CERT
  • BLOG
    • Books
    • OSINT
    • Pentest
    • Privacy
  • GHDB
  • CHDB
  • OSINT
  • ARCHIVE
  • ABOUT
    • Privacy Policy
    • Terms of Use
    • External Links
    • Sitemap
GeekWire
GeekWire
  • HOME
  • NEWS
    • CERT
    • EXPLOITS
    • NCSC
    • NVD
    • SECURELIST
    • US-CERT
  • BLOG
    • Books
    • OSINT
    • Pentest
    • Privacy
  • GHDB
  • CHDB
  • OSINT
  • ARCHIVE
  • ABOUT
    • Privacy Policy
    • Terms of Use
    • External Links
    • Sitemap

OpenSSF

SBOM Everywhere: The OpenSSF Plan for SBOMs

20 May 2022

The Open Source Security Foundation (OpenSSF) has published a mobilization plan to improve the resiliency and security of open source …

Tags IT, OpenSSF, Plans, SBOM, Sponsored

White House joins OpenSSF and the Linux Foundation in securing open-source software

13 May 2022

Securing the open-source software supply chain is a huge deal. Last year, the Biden administration issued an executive order to improve …

Tags IT, News, OpenSSF, Plans, White House

Linux, OpenSSF Champion Plan to Improve Open Source Security

13 May 2022

The White House and tech industry pledge $150 million over two years to boost open source resiliency and supply chain …

Tags IT, News, OpenSSF, Plans

A 10-point plan to improve the security of open source software

13 May 2022

The Linux Foundation and the Open Source Software Security Foundation, with input provided by executives from 37 companies and many U.S. …

Tags Google Cloud, IT, JFrog, OpenSSF, The Linux Foundation

OpenSSF announces Alpha-Omega Project to improve global OSS supply chain security

1 February 2022

OpenSSF announced the Alpha-Omega Project to improve the security posture of open source software (OSS) through direct engagement of …

Tags IT, News, OpenSSF, Projects

Google announces Scorecard V4 in partnership with GitHub and OpenSSF

19 January 2022

The Open Source Security Foundation (OpenSSF), GitHub and Google announced on Wednesday the launch of Scorecards V4, which includes larger …

Tags IT, News, OpenSSF

Reducing security risk in open source software with GitHub Actions and OpenSSF Scorecards V4

19 January 2022

GitHub is committed to helping secure the future of open source security, and it is why we continue to partner with our industry peers …

Tags Github, IT, Open Source Hosting, Open Source Software, OpenSSF

The OpenSSF and the Linux Foundation Address Software Supply Chain Security Challenges at White House Summit

14 January 2022

WASHINGTON (January 13, 2022) Today marks an important moment in the Linux Foundation’s history of engagement with public sector …

Tags Address, Challenges, IT, OpenSSF, Summit
Cookie-Free

NVD

  • CVE-2022-29662 – CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via …26 May 2022
  • CVE-2022-29687 – CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerabili …26 May 2022
  • CVE-2022-29663 – CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via …26 May 2022
  • CVE-2022-29688 – CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerabili …26 May 2022
  • CVE-2021-42692 – There is a stack-overflow vulnerability in tinytoml v0.4 that can cause a crash or DoS. …26 May 2022
  • CVE-2022-29664 – CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via …26 May 2022

EXPLOITS

  • qdPM 9.1 – Remote Code Execution (RCE) (Authenticated) (v2)26 May 2022
  • m1k1o’s Blog v.10 – Remote Code Execution (RCE) (Authenticated)23 May 2022
  • OpenCart v3.x Newsletter Module – Blind SQLi23 May 2022
  • SolarView Compact 6.0 – OS Command Injection17 May 2022
  • T-Soft E-Commerce 4 – SQLi (Authenticated)17 May 2022
  • T-Soft E-Commerce 4 – ‘UrunAdi’ Stored Cross-Site Scripting (XSS)17 May 2022

SECURELIST

  • Managed detection and response in 202126 May 2022
  • The Verizon 2022 DBIR25 May 2022
  • What’s wrong with automotive mobile apps?25 May 2022
  • ISaPWN – research on the security of ISaGRAF Runtime23 May 2022
  • Evaluation of cyber activities and the threat landscape in Ukraine17 May 2022
  • HTML attachments in phishing e-mails16 May 2022

Information Cyber Network Enterprise Security News

Copyright © 2022 GeekWire | Cookie-Free | Privacy Policy | We are not responsible for the content of external sites.

GeekWire Information Cyber Network Enterprise Security News