FEATURED

The Day the Music Died: Certificate Expiration Takes Down Spotify

“Something expired deep insideThe day the music died” Earlier this week, the music streaming service Spotify went down for about…

4 months ago

From Prototype Pollution to full-on remote code execution, how can adversaries exploit npm modules?

The NodeJS component express-fileupload - touting 7 million downloads from the npm registry -  now has a critical Prototype Pollution…

4 months ago

Intro to Blockchain as a Service (BaaS)

Blockchain? I'm not sure what it is, but I know that bitcoin used to be worthless and now is worth…

4 months ago

Introducing our 2020 State of the Software Supply Chain Report

An analysis of high performance open source development practices

4 months ago

CVE-2020-17479: The return of Validation Bypass (CVE-2019-19507) in `jpv`

In addition to regular vulnerability data research, the Sonatype Security Research Team also contributes to the open-source community by going…

4 months ago

Hitting the Trifecta with GitLab Automated Merge Requests

We’ve been working to integrate component intelligence from Nexus Lifecycle directly into source control management (SCM) systems so that developers…

4 months ago

Nexus Intelligence Insights:CVE-2020-13935 – Apache Tomcat Websocket – Denial of Service (DoS)

For July’s Nexus Intelligence Insight we take a deep dive into a Denial of Service (DoS) vulnerability impacting the popular…

5 months ago

New in Nexus Repository 3.25: How Do I Switch to NuGet V3?

We are excited to announce the official release of Nexus Repository 3.25. Delivering on much anticipation from the Nexus community,…

5 months ago

How to Cyber Security: Fuzz a tank

With the Defensics SDK, you can create fuzzing test suites for any type of data. In this article, we demonstrate…

5 months ago

Trust and Courage are Essential to a Strong Team Culture

Editor's Note: This post was originally shared internally. With the author's permission it is shared here so that prospective coworkers…

6 months ago