home/tags/#Security

#Security

16 posts

// posts tagged #security
GLM 5.2 Outperforms Claude on Semgrep's Cybersecurity Benchmarks

GLM 5.2 from Zhipu AI tops Semgrep's internal cybersecurity benchmark suite, outranking Claude. What the numbers mean — and don't mean — for security teams.

AI Fuzzing Just Dropped 20 Zero-Days With No Warning

An anonymous actor used AI-assisted fuzzing to find 20 open source zero-days and published them without disclosure. Here's what that means for your stack.

PinpinRAT: The Fake Interview Attack That Fooled Every AV Engine

How a fabricated VC persona and a malicious TypeScript patch nearly backdoored a Rust maintainer—undetected by all 70 VirusTotal AV engines.

10,000 GitHub Repos Are Serving Malware — and Your Checks Miss It

A coordinated campaign clones real repositories, force-pushes malicious ZIPs every few hours, and scores 0 detections on VirusTotal URL scans. Here's how it works and what to do.

10,000 Malicious GitHub Repos: A Supply Chain Attack at Infrastructure Scale

A researcher uncovered 10,000 GitHub repositories distributing Trojan malware. Here's what the scale reveals about the attack—and who's actually most at risk.

Vibe Coding Goes Corporate: What Google's Calendar App Demo Actually Signals

A Google employee built a working travel-to-calendar app in 2 hours with no code. Here's what that really means for developers and security teams.

FIFA World Cup IDOR: How One Credential Hijacked an Entire Event

A single personal ID was all it took to inject content across FIFA's entire World Cup infrastructure — a case study in IDOR and access control failure.

AUR Supply-Chain Attack Response Tool Hits 1,455 Stars in Days

The atomic-lockfile AUR supply-chain attack exposed a critical flaw in running Arch Linux in CI. Here's what the community scanner can—and cannot—tell you.

GrapheneOS Ported to Android 17: What Developers Need to Know

GrapheneOS has been ported to Android 17 with official releases coming soon — here's what it means for app developers, security engineers, and hardened fleet operators.

Microsoft Releases Lib0xc for Memory-Safe C Development

Microsoft's new Lib0xc library offers safer alternatives to standard C functions, addressing long-standing memory safety concerns in systems programming.