article thumbnail

Some Good News About Application Security

Forrester IT

In my new report, “The State Of Application Security, 2020,” some of the trends are. Applications remain the most popular attack vector, open source continues to infect everything, and too many industries are not investing in the application security controls they need. kind of discouraging.

article thumbnail

Open source developer corrupts widely-used libraries, affecting tons of projects

The Verge

A developer appears to have purposefully corrupted a pair of open-source libraries on GitHub and software registry npm — “ faker.js ” and “ colors.js ” — that thousands of users depend on, rendering any project that contains these libraries useless, as reported by Bleeping Computer. Illustration by Alex Castro / The Verge.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Google’s VR painting app is getting the axe, but it will live on as an open-source project

The Verge

Google is ending development on the virtual reality painting app Tilt Brush — one of the most well-known VR applications — and making it open source. Tilt Brush’s code can be accessed on GitHub now , but Google says some features had to be removed from the open-source release because of licensing restrictions.

article thumbnail

Windows 10 May 2020 Update now available with built-in Linux kernel and Cortana updates

The Verge

Microsoft is releasing its Windows 10 May 2020 Update today. Microsoft released a final version of the update to testers last month , and everyone on Windows 10 can get access to the May 2020 Update through Windows Update today. The May 2020 Update also includes some big Cortana improvements.

Linux 83
article thumbnail

Hottest tech skills to hire for in 2020

Hacker Earth

Here are some of the hottest tech skills (a mix of programming languages, tools, and frameworks; in random order) to hire for in 2020, which will help you thrive in the workplace of tomorrow. Hence, JavaScript will remain one of the hottest tech skills in 2020 and it is unlikely that it will go off the grid in the near future.

article thumbnail

CVE-2020-15359: VDALabs Uses Mayhem To Find MP3Gain Stack Overflow

ForAllSecure

Researchers from VDA Labs used ForAllSecure Mayhem to discover a stack overflow ( CVE-2020-15359 ) in a popular open source sound utility, MP3Gain. 2) Finding CVE-2020-15359. Finding CVE-2020-15359 Through Fuzzing. Once VDA Labs had its Dockerfile, they created a Mayhemfile to fuzz the application.

Linux 52
article thumbnail

CVE-2020-15359: VDALabs Uses Mayhem To Find MP3Gain Stack Overflow

ForAllSecure

Researchers from VDA Labs used ForAllSecure Mayhem to discover a stack overflow ( CVE-2020-15359 ) in a popular open source sound utility, MP3Gain. 2) Finding CVE-2020-15359. Finding CVE-2020-15359 Through Fuzzing. Once VDA Labs had its Dockerfile, they created a Mayhemfile to fuzz the application.

Linux 52