JFrog Flaws Open Route to Package Cache Poisoning
Two flaws in JFrog Artifactory could let low-privileged users tamper with package metadata and compromise software supply chains.
5 results for “software supply chain”
Two flaws in JFrog Artifactory could let low-privileged users tamper with package metadata and compromise software supply chains.
Anthropic and OpenAI trade narratives of accidental sandbox escapes, raising questions about the safety of their frontier models.
Researchers find top AI models consistently inventing identical, non-existent library names that attackers could potentially weaponize.
Researchers identify a vulnerability where agents mistake untrusted input for verified facts, bypassing current security defenses.
GitHub's npm 12 release hardens software supply chains by disabling install scripts by default and overhauling granular access tokens to mitigate critical risks.