infosec Archives - Developer Tech News https://www.developer-tech.com/news/tag/infosec/ Gaming, Apps, HTML5, Java, PHP, C#, .net, IOT Wed, 17 Jan 2024 16:58:12 +0000 en-GB hourly 1 https://www.developer-tech.com/wp-content/uploads/sites/3/2020/09/dev-icon-60x60.png infosec Archives - Developer Tech News https://www.developer-tech.com/news/tag/infosec/ 32 32 GitHub rotates credentials following vulnerability discovery https://www.developer-tech.com/news/2024/jan/17/github-rotates-credentials-following-vulnerability-discovery/ https://www.developer-tech.com/news/2024/jan/17/github-rotates-credentials-following-vulnerability-discovery/#respond Wed, 17 Jan 2024 16:58:10 +0000 https://www.developer-tech.com/?p=45542 GitHub has rotated encryption keys following the discovery of a vulnerability that could have enabled threat actors to steal credentials, the company revealed Tuesday.   The Microsoft-owned firm said it first became aware of the high-severity security flaw tracked as CVE-2024-0200 on 26 December 2023. After investigating the issue and verifying there was no evidence it... Read more »

The post GitHub rotates credentials following vulnerability discovery appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/2024/jan/17/github-rotates-credentials-following-vulnerability-discovery/feed/ 0
PHP 8.0 reaches EOL leaving some websites vulnerable https://www.developer-tech.com/news/2023/nov/27/php-8-0-reaches-eol-leaving-some-websites-vulnerable/ https://www.developer-tech.com/news/2023/nov/27/php-8-0-reaches-eol-leaving-some-websites-vulnerable/#respond Mon, 27 Nov 2023 12:43:31 +0000 https://www.developer-tech.com/?p=45393 PHP 8.0 reached its end of life (EOL) on 26 November 2023 and will no longer receive any updates or patches. PHP 8.0 was released on 26 November 2020 and brought many new features and improvements such as named arguments, attributes, constructor property promotion, match expression, nullsafe operator, JIT, and more. The EOL of PHP... Read more »

The post PHP 8.0 reaches EOL leaving some websites vulnerable appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/2023/nov/27/php-8-0-reaches-eol-leaving-some-websites-vulnerable/feed/ 0
Checkmarx uncovers persistent Python package threat https://www.developer-tech.com/news/2023/nov/16/checkmarx-uncovers-persistent-python-package-threat/ https://www.developer-tech.com/news/2023/nov/16/checkmarx-uncovers-persistent-python-package-threat/#respond Thu, 16 Nov 2023 13:00:03 +0000 https://www.developer-tech.com/?p=45359 Checkmarx has uncovered a threat actor that has been quietly infiltrating the open-source ecosystem for nearly six months, planting malicious Python packages with a focus on deception and financial gain. The malicious actor employed a systematic approach, disguising their packages with names closely resembling popular legitimate Python packages. These decoy packages, camouflaged to blend in,... Read more »

The post Checkmarx uncovers persistent Python package threat appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/2023/nov/16/checkmarx-uncovers-persistent-python-package-threat/feed/ 0
AI coding assistants: A double-edged sword for DevOps in 2024 https://www.developer-tech.com/news/2023/nov/10/ai-coding-assistants-double-edged-sword-devops-2024/ https://www.developer-tech.com/news/2023/nov/10/ai-coding-assistants-double-edged-sword-devops-2024/#respond Fri, 10 Nov 2023 14:06:02 +0000 https://www.developer-tech.com/?p=45339 A growing reliance on AI-powered coding assistants is reshaping how DevOps teams operate, for better or worse. According to Forrester’s 2024 cybersecurity, risk, and privacy predictions, AI coding assistants are becoming integral to boosting productivity. However, a cautionary note accompanies this technological shift, as Forrester warns of potential pitfalls that could lead to cybersecurity breaches.... Read more »

The post AI coding assistants: A double-edged sword for DevOps in 2024 appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/2023/nov/10/ai-coding-assistants-double-edged-sword-devops-2024/feed/ 0
Wallarm highlights disturbing trends in API security threats https://www.developer-tech.com/news/2023/nov/08/wallarm-highlights-disturbing-trends-api-security-threats/ https://www.developer-tech.com/news/2023/nov/08/wallarm-highlights-disturbing-trends-api-security-threats/#respond Wed, 08 Nov 2023 10:40:12 +0000 https://www.developer-tech.com/?p=45331 Wallarm has released its Q3 2023 API ThreatStats report which sheds light on the escalating threats targeting APIs and revealing vulnerabilities that have impacted industry giants such as Netflix, VMware, and SAP. The report’s revamped ‘Top 10 API Security Threats’ compilation outlines 239 vulnerabilities discovered during the quarter, with injections taking the lead. Injections involve... Read more »

The post Wallarm highlights disturbing trends in API security threats appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/2023/nov/08/wallarm-highlights-disturbing-trends-api-security-threats/feed/ 0
State of Java: Resilience amid licensing changes and security concerns https://www.developer-tech.com/news/2023/oct/27/state-of-java-resilience-licensing-changes-security-concerns/ https://www.developer-tech.com/news/2023/oct/27/state-of-java-resilience-licensing-changes-security-concerns/#respond Fri, 27 Oct 2023 09:28:10 +0000 https://www.developer-tech.com/?p=45254 Azul has unveiled its first annual State of Java Survey & Report, which offers a deep exploration of the Java landscape. The study – based on responses from over 2,000 Java users worldwide – aims to provide unparalleled insights into Java’s current standing, particularly its influence on enterprises of various sizes. Java’s ubiquity and vital... Read more »

The post State of Java: Resilience amid licensing changes and security concerns appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/2023/oct/27/state-of-java-resilience-licensing-changes-security-concerns/feed/ 0
Sauce Labs exposes some developers’ risky habits https://www.developer-tech.com/news/2023/oct/03/sauce-labs-exposes-some-developers-risky-habits/ https://www.developer-tech.com/news/2023/oct/03/sauce-labs-exposes-some-developers-risky-habits/#respond Tue, 03 Oct 2023 15:32:51 +0000 https://www.developer-tech.com/?p=45180 A survey by Sauce Labs of 500 US-based developers has put the spotlight on some concerning practices. One alarming discovery was the tendency of developers to push code to production without adequate testing. 67 percent of respondents admitted to this practice, jeopardising software quality, user experience, and system stability. Additionally, 68 percent confessed to merging... Read more »

The post Sauce Labs exposes some developers’ risky habits appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/2023/oct/03/sauce-labs-exposes-some-developers-risky-habits/feed/ 0
Mathew Payne, GitHub: Protecting code while nurturing user experience https://www.developer-tech.com/news/2023/aug/18/mathew-payne-github-protecting-code-nurturing-user-experience/ https://www.developer-tech.com/news/2023/aug/18/mathew-payne-github-protecting-code-nurturing-user-experience/#respond Fri, 18 Aug 2023 13:54:35 +0000 https://www.developer-tech.com/?p=45057 Developer caught up with Mathew Payne, Principal Field Security Specialist at GitHub, to discuss the platform’s security strategies and how they aim to strike a balance between robustness and a seamless user experience. At the heart of GitHub’s security philosophy lies a commitment to safeguarding user code. Payne emphasised that a major focus is on... Read more »

The post Mathew Payne, GitHub: Protecting code while nurturing user experience appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/2023/aug/18/mathew-payne-github-protecting-code-nurturing-user-experience/feed/ 0
Malicious PyPI package discovered in ongoing ‘PaperPin’ campaign https://www.developer-tech.com/news/2023/aug/04/malicious-pypi-package-ongoing-paperpin-campaign/ https://www.developer-tech.com/news/2023/aug/04/malicious-pypi-package-ongoing-paperpin-campaign/#respond Fri, 04 Aug 2023 11:05:45 +0000 https://www.developer-tech.com/?p=44995 In a recent analysis conducted by Sonatype, a malicious Python Package Index (PyPI) package named ‘VMConnect’ was discovered masquerading as the legitimate VMware vSphere connector module ‘vConnector’. The counterfeit package was found to contain sinister code designed to compromise users’ systems. Further investigation revealed an ongoing campaign involving additional packages like “ethter” and “quantiumbase,” all... Read more »

The post Malicious PyPI package discovered in ongoing ‘PaperPin’ campaign appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/2023/aug/04/malicious-pypi-package-ongoing-paperpin-campaign/feed/ 0
Apple will require developers to explain their API use https://www.developer-tech.com/news/2023/jul/28/apple-require-developers-explain-api-use/ https://www.developer-tech.com/news/2023/jul/28/apple-require-developers-explain-api-use/#respond Fri, 28 Jul 2023 14:45:07 +0000 https://www.developer-tech.com/?p=44951 In an effort to bolster user privacy and crack down on fingerprinting, Apple has announced that developers will soon be required to provide detailed explanations for their app’s use of certain APIs before submitting them to the App Store. The APIs in question are now classified as “required reason APIs,” meaning developers must articulate the... Read more »

The post Apple will require developers to explain their API use appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/2023/jul/28/apple-require-developers-explain-api-use/feed/ 0