-
November 1, 2022
Lessons From OpenSSL’s 3.0.7 Security Patch (CVE-2022-3786 and CVE-2022-3602: X.509 Email Address Buffer Overflows)
While OpenSSL downgraded the criticality of its 3.0.7 security patch from Critical to High (CVE-2022-3786 and CVE-2022-3602), and it's fair...
-
October 29, 2022
Security Advisory: Critical OpenSSL Vulnerability
On Tuesday, November 1st, OpenSSL is releasing a critical patch. Given the ubiquity of OpenSSL, rapid remediation will be imperative...
-
August 30, 2022
Pipeline Composition Analysis: The Next-Generation of SCA
Software composition analysis (SCA) is a necessary tool that detects vulnerabilities within dependencies such as open source libraries. As the...
-
January 4, 2021
Why Microsoft’s Latest SolarWinds Admission Can’t Be Ignored
Last week, on New Year’s Eve, Microsoft announced that the SolarWinds attackers had been deeper in their environment than previously...