Mike Shema
- A twenty-five years old curl bug | daniel.haxx.se
- Auditing the Ruby ecosystem’s central package repository | Trail of Bits Blog
- Top AWS re:Invent Announcements for Security Teams 2024 | Wiz Blog
- Open Source Usage Trends and Security Challenges Revealed in New Study
Download the report here
- WorstFit!
Noting this because it falls into the category of parsing, defaults, and choosing between failure modes.
- Open Source Malware Reaches More Than 778500 Packages, According to Sonatype Researchers
The report is behind a regwall. I've included it here to talk about the phrase, "...npm, exemplifies the risk contained in public repositories, representing 98.5% of the malicious packages Sonatype has identified in the past year."
John Kinsella
- Microsoft MFA found to be lax, bypassable
Folks at Oasis Security found out that Microsoft was allowing 3 minutes to accept a MFA token - 2.5 minutes longer than specified in RFC-6238. This gave attackers six times as long to attempt to brute force the value.
- Getting PCIE memory access via SD card reader
This might be a little more hardware hacking than appsec, but is still a good read on some of the history of memory card interfaces and DMA attacks. End-of-day, they've created a custom board to insert into a SD card reader that provides access to the laptop's memory via PCI Express.









