Mend.io Blog

Poisoned axios: npm account takeover, 50 million downloads, and a rat that vanishes after install

Poisoned Axios: npm Account Takeover, 50 Million Downloads, and a RAT That Vanishes After Install

LATEST
Learn more

Filter & Search

Github vulnerability alerts - github

GITHUB Vulnerability Alerts

Renovate supports raising Pull Requests immediately for any JavaScript or Python package identified as having a vulnerable version by GitHub’s Vulnerability Alerts.

Read More Read More
Github vulnerability alerts - ahviptcynte0jmntzd1pdgvtzwrpdg9yaw1hz2umzmlszw5hbwu9axrlbwvkaxrvcmltywdlxzvindm1yjnmymjmnjauanbnjnzlcnnpb249mdawmczzawc9zgywmmzmyjzhndg2yzfkngq1nmjknmq0ntuzmmqzzmi

6 Open Source Software Security Concerns Dispelled

Discover and dispel 6 common concerns around using open source software in applications. Learn how to mitigate risks and harness its power.

Read More Read More
Github vulnerability alerts - 9 inb

Announcing Dependency Deprecation Warnings

Renovate allows raising issues to warn a repository if it is using deprecated npm packages. This helps prevent that a dependency you are using may never get updates again.

Read More Read More
Github vulnerability alerts -

CVSS v3 Is Still Missing The Target For Prioritization

Learn about the flaws in the Common Vulnerability Scoring System and how it may impact security professionals.

Read More Read More
Github vulnerability alerts - vulnerability disclosure 1

Vulnerability Disclosure: Find the Bugs in Your Code Before the Hackers Do

Learn about vulnerability disclosure and how to find bugs in your code before hackers do.

Read More Read More
Github vulnerability alerts - owasp a9 1

You Can’t Ignore Using Components With Known Vulnerabilities

Learn why using components with known vulnerabilities is a major issue in application security and how to address it with OWASP guidelines.

Read More Read More
Github vulnerability alerts - ahviptcynte0jmntzd1pdgvtzwrpdg9yaw1hz2umzmlszw5hbwu9axrlbwvkaxrvcmltywdlxzvimmi4njdlogjmntkuanbnjnzlcnnpb249mdawmczzawc9zmi4zdjjnzc1y2vkm2i0odi4yzmynwzhmjczzjiyzgi3d

7 Chinese Open Source Projects You Should Know About

Explore 7 groundbreaking Chinese open source projects like Vue and Dragonfly.

Read More Read More
Github vulnerability alerts - ahviptcynte0jmntzd1pdgvtzwrpdg9yaw1hz2umzmlszw5hbwu9axrlbwvkaxrvcmltywdlxzvimji1ngm5owy5zweuanbnjnzlcnnpb249mdawmczzawc9nthhzgzjnmewodc1zdvjmwm3zme3ogq3mgqyodc4y2m

Known Open Source Vulnerabilities in Reusable Software Components: a Golden Goose For Hackers

Discover the risks of known open source vulnerabilities in reusable software components and how hackers exploit them.

Read More Read More
Github vulnerability alerts -

CVSS v3 Creates New Challenges For Developers

Learn about CVSS v3 and the challenges it brings for developers. Understand how to prioritize remediations & utilize effective usage analysis.

Read More Read More
Github vulnerability alerts - ahviptcynte0jmntzd1pdgvtzwrpdg9yaw1hz2umzmlszw5hbwu9axrlbwvkaxrvcmltywdlxzvimdy3zdzhmwm0mjeuanbnjnzlcnnpb249mdawmczzawc9owe5ode1yjc1nmm1y2rjodcwm2zkzwniota2zdm1zde3d

Top 10 Weirdest Names for Open Source Projects

Discover the top 10 weirdest names for open source projects. From Pig to CockroachDB, learn about these unique projects and their purposes.

Read More Read More
Github vulnerability alerts -

Top 3 Challenges to Fintech in a Post-Equifax World

Discover the top 3 challenges for fintech in the post-Equifax era: stringent regulations, securing customer trust, and application security.

Read More Read More
Github vulnerability alerts -

Top 5 Developer Jokes Explained (Because We Don’t Get Them Either)

Discover the top 5 developer jokes explained. Understand the humor behind coding and programming with insights from fellow developers.

Read More Read More
Github vulnerability alerts - ahviptcynte0jmntzd1pdgvtzwrpdg9yaw1hz2umzmlszw5hbwu9axrlbwvkaxrvcmltywdlxzvhzdvlmtg5ngfizwyuz2lmjnzlcnnpb249mdawmczzawc9zje1mwi3ztezoduwm2vizdyym2mzmzc3zjfintfhowe

The Equifax Hack: 6 Months Later, What Did We Learn?

The Equifax breach was the largest single breach in history, with 145.5 million records being uncovered. Today, 6 months later, we look at the industry and see what we have learned from Equifax.

Read More Read More
Github vulnerability alerts -

Open Source License Trends: 2017 vs. 2016

Explore the open source license trends of 2017 vs. 2016 and the many security issues spanning across each.

Read More Read More
Github vulnerability alerts - top 5 of the month march2018

Top 5 New Open Source Vulnerabilities in March 2018

The top 5 new open source vulnerabilities in March 2018, including Drupal, Microsoft ChakraCore, Jackson-databind, Moment.js, and Marked.js.

Read More Read More
Github vulnerability alerts - docker

Overcoming Docker’s Mutable Image Tags

Why Docker tags are mutable, how Node.js images broke yarn, and how to work with immutable Docker digests instead.

Read More Read More

Subscribe to our Blog

Never miss a post. Opt-out at any time.

Thank you

You’re all set to receive our latest posts.

AI Security & Compliance Assessment

Map your maturity against the global standards. Receive a personalized readiness report in under 5 minutes.