Visualização normal

Antes de ontemBleepingComputer

The EU CRA's Real Question: What Shipped, and When Did You Know?

8 de Setembro de 2026, 17:24
The EU Cyber Resilience Act's vulnerability reporting requirements take effect September 11, giving software vendors as little as 24 hours to report actively exploited flaws. ActiveState explains why knowing exactly what shipped and when vulnerabilities were discovered will be critical to meeting the new requirements. [...]

Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion

13 de Agosto de 2026, 11:00
AI coding tools can introduce unvetted or hallucinated open source dependencies faster than traditional security reviews can keep pace. ActiveState explains why organizations should govern packages at the point of selection, before they enter the development pipeline. [...]

Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack

24 de Julho de 2026, 11:01
Slopsquatting, phantom squatting, and HalluSquatting all exploit the same late-binding attack pattern, where AI coding agents trust hallucinated package, repo, or domain names. ActiveState explains how pre-fetch verification and governed dependency management can help stop these attacks before malicious code enters the pipeline. [...]
❌
❌