A Deceptive Dependabot, Insecure JWT, CISA Wants HBOMs, OpenSSF's Critical Projects - ASW #257
A Deceptive Dependabot, Insecure JWT, CISA Wants HBOMs, OpenSSF's Critical Projects - ASW #257

A Deceptive Dependabot, Insecure JWT, CISA Wants HBOMs, OpenSSF's Critical Projects - ASW #257

đź‘‘Royal_kreeshđź‘‘

59 min
News
Play

Description

<p>Attackers impersonate Dependabot commits, an alg of "none" plagues a JWT, CISA calls for hardware bills of materials, OpenSSF lists its critical projects, Exim (finally! maybe?) has some patches, bug bounties and open source projects, and more!</p> <p>Show Notes: <a rel="noopener" target="_blank" href= "https://securityweekly.com/asw-257">https://securityweekly.com/asw-257</a></p>

Uploader

roxy_run

roxy_run

A Deceptive Dependabot, Insecure JWT, CISA Wants HBOMs, OpenSSF's Critical Projects - ASW #257 - Listen Free | WowFM