Malicious code in the Node.js npm registry shakes open source trust model

Email not displaying correctly? View it in your browser.

CSO

CSO Salted Hash

Aug 09, 2017
Featured Image

Pentest firm calls Carbon Black "world’s largest pay-for-play data exfiltration botnet"

On Wednesday, DirectDefense, Inc. disclosed that they've discovered hundreds of thousands of files from Carbon Black customers. The discovery is said to pose a significant risk to Carbon Black's clients, because of the company's dependence on third-party multiscanners in the Cb Response product. Read More

Twitter Facebook LinkedIn

Your Must-Read Stories

Malicious code in the Node.js npm registry shakes open source trust model
44% off Aukey Dash Cam, Full HD Wide Angle With Night Vision - Deal Alert
Social media exploitation key in Trump’s 'extreme vetting' program
NSA whistleblower discusses ‘How the NSA tracks you’

eBook: Silver Peak Systems Inc

2017 Trends: SD-WAN Advances Towards Mainstream Adoption

As SD-WAN adoption continues to gain ground and go mainstream in 2017, the majority of initial enterprise deployments will be hybrid, leveraging both MPLS and a complement of broadband connectivity. Many enterprises already have some level of broadband connectivity to branch and remote locations, but these links often remain idle or are relegated to backup or disaster recovery (DR). Read More

Thumbnail Image

Malicious code in the Node.js npm registry shakes open source trust model

Bad actors using typo-squatting place 39 malicious packages in npm that went undetected for two weeks. How should the open source community respond? Read More

Thumbnail Image
DealPost

44% off Aukey Dash Cam, Full HD Wide Angle With Night Vision - Deal Alert

This cam features an emergency recording mode, activated by sharp turns or sudden stops, which automatically captures unexpected driving incidents. Read More

Thumbnail Image

Social media exploitation key in Trump’s 'extreme vetting' program

Trump administration seeks help from tech firms to create an "extreme vetting" program for immigrants to the U.S. Documents indicate IBM is interested. Read More

Thumbnail Image

NSA whistleblower discusses ‘How the NSA tracks you’

William Binney, who quit the NSA because it engages in the "total invasion of the privacy rights of everybody on the planet," presented "How the NSA tracks you" at the hacker conference SHA2017. Read More

Video/Webcast: Oracle & Dyn

3 Ways ISP DNS Fails Modern Business

Modern digital business has increased the importance of DNS services, and relying on a solution that isn't completely focused on DNS could be putting you at risk. For example, most ISP-based DNS services still use unicast to route DNS traffic (modern DNS providers use anycast networks), force customers to submit tickets for changes, and may not offer 24x7 DNS support. oin this webinar to learn 3 reasons to leave ISP-based DNS behind. Read More

CSO Insider

1. Cybersecurity market research: Top 15 statistics for 2017
2. Lacework unmasks hidden attackers amid data center and cloud chaos
3. SandBlast Mobile simplifies mobile security
4. Is your data being sold on the dark web?
5. Tested: How 4 deception tools deliver truer network security

Editor's Picks

1. Four ways to use open data sources to find cybersecurity candidates
2. Top cloud security controls you should be using
3. The dark web goes corporate
4. 7 things your IT disaster recovery plan should cover
5. Oracle’s monster update emphasizes flaws in critical business applications
Twitter Facebook LinkedIn Google+

You are currently subscribed to CSO Salted Hash as newsletter@newslettercollector.com.

Unsubscribe from this newsletter | Manage your subscriptions | Subscribe | Privacy Policy

Learn more about INSIDER

Copyright (C) 2017 CSO Online Media Group, 492 Old Connecticut Path, Framingham, MA 01701

Please do not reply to this message.
To contact someone directly, send an e-mail to online@csoonline.com.