⤷ Title: Hunting Dependency Confusion: Supply Chain Vulnerabilities for Bug Bounties
════════════════════════
𐀪 Author: Aman Bhuiyan
════════════════════════
ⴵ Time: Sat, 11 Oct 2025 19:11:46 GMT
════════════════════════
⌗ Tags: #bug_hunting #dependency_injection #hacking #bug_bounty
════════════════════════
𐀪 Author: Aman Bhuiyan
════════════════════════
ⴵ Time: Sat, 11 Oct 2025 19:11:46 GMT
════════════════════════
⌗ Tags: #bug_hunting #dependency_injection #hacking #bug_bounty
Medium
Hunting Dependency Confusion: Supply Chain Vulnerabilities for Bug Bounties
Hey there, fellow bug bounty hunters and security enthusiasts! If you’ve been knee-deep in web app pentesting, you’ve probably chased XSS…
⤷ Title: So, “Shift-Left” Failed. What Comes Next?
════════════════════════
𐀪 Author: Ali Naqvi
════════════════════════
ⴵ Time: Wed, 07 Jan 2026 15:40:44 GMT
════════════════════════
⌗ Tags: #dependency_management #application_security #devtools #software_development #shiftleft
════════════════════════
𐀪 Author: Ali Naqvi
════════════════════════
ⴵ Time: Wed, 07 Jan 2026 15:40:44 GMT
════════════════════════
⌗ Tags: #dependency_management #application_security #devtools #software_development #shiftleft
Medium
So, “Shift-Left” Failed. What Comes Next?
Remember the days when Security and Development were two different teams who met annually at the company holiday party? Siloed, with…
⤷ Title: Finding Remote Code Execution in Google: A Bug Hunter’s Story
════════════════════════
𐀪 Author: zabit majeed
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 17:49:36 GMT
════════════════════════
⌗ Tags: #cve #google #bug_bounty #dependency_injection #hacking
════════════════════════
𐀪 Author: zabit majeed
════════════════════════
ⴵ Time: Sun, 11 Jan 2026 17:49:36 GMT
════════════════════════
⌗ Tags: #cve #google #bug_bounty #dependency_injection #hacking
Medium
Finding Remote Code Execution in Google: A Bug Hunter’s Story
Hey everyone, this is Zabit Majeed . I’m an ethical hacker and a part-time bug bounty hunter, and this story is about persistence more…
⤷ Title: How I Discovered a Dependency Confusion Vulnerability in a Ruby Application Leading to RCE
════════════════════════
𐀪 Author: Ahmed Tarek
════════════════════════
ⴵ Time: Sat, 17 Jan 2026 19:06:39 GMT
════════════════════════
⌗ Tags: #pentesting #bug_bounty #dependency_confusion #bug_bounty_tips #ruby
════════════════════════
𐀪 Author: Ahmed Tarek
════════════════════════
ⴵ Time: Sat, 17 Jan 2026 19:06:39 GMT
════════════════════════
⌗ Tags: #pentesting #bug_bounty #dependency_confusion #bug_bounty_tips #ruby
Medium
How I Discovered a Dependency Confusion Vulnerability in a Ruby Application Leading to RCE
hey there,
⤷ Title: # How I Found a Snyk-Verified 9.3
════════════════════════
𐀪 Author: freebold
════════════════════════
ⴵ Time: Sat, 14 Mar 2026 12:48:36 GMT
════════════════════════
⌗ Tags: #supply_chain #cybersecurity #npm #dependency_confusion #bug_bounty
════════════════════════
𐀪 Author: freebold
════════════════════════
ⴵ Time: Sat, 14 Mar 2026 12:48:36 GMT
════════════════════════
⌗ Tags: #supply_chain #cybersecurity #npm #dependency_confusion #bug_bounty
Medium
# How I Found a Snyk-Verified 9.3
# How I Found a Snyk-Verified 9.3 Critical Vulnerability in FDJ United's Gaming Platform — And Got Paid Nothing **By freebold | Security Researcher** --- ## TL;DR I discovered a critical dependency …
⤷ Title: Supply Chain Shield: How DepConfuse Proactively Stops Dependency Confusion Attacks
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 16 Mar 2026 09:24:16 +0000
════════════════════════
⌗ Tags: #Open Source Tool #cybersecurity tools #CycloneDX #DepConfuse #Dependency Confusion #DevSecOps #open source security #PURL #SBOM #Software Composition Analysis #Supply Chain Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 16 Mar 2026 09:24:16 +0000
════════════════════════
⌗ Tags: #Open Source Tool #cybersecurity tools #CycloneDX #DepConfuse #Dependency Confusion #DevSecOps #open source security #PURL #SBOM #Software Composition Analysis #Supply Chain Security
Penetration Testing Tools
Supply Chain Shield: How DepConfuse Proactively Stops Dependency Confusion Attacks
Stop dependency confusion before it starts. DepConfuse is an SBOM-first tool that scans 20+ registries to secure your software supply chain from package takeover.
⤷ Title: Engineers Don’t Care About Compliance. And Spoiler Alert: They Shouldn’t Need To.
════════════════════════
𐀪 Author: Ali Naqvi
════════════════════════
ⴵ Time: Wed, 18 Mar 2026 20:03:01 GMT
════════════════════════
⌗ Tags: #open_source #compliance #dependency_management #application_security #engineering
════════════════════════
𐀪 Author: Ali Naqvi
════════════════════════
ⴵ Time: Wed, 18 Mar 2026 20:03:01 GMT
════════════════════════
⌗ Tags: #open_source #compliance #dependency_management #application_security #engineering
Medium
Engineers Don’t Care About Compliance. And Spoiler Alert: They Shouldn’t Need To.
Let me start with a statement that makes some compliance teams uncomfortable:
⤷ Title: Poisoning the Pipeline: How the “Frank” Campaign Targeted Apple and Google via NPM Dependency Confusion
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 12 May 2026 07:57:45 +0000
════════════════════════
⌗ Tags: #Malware #Alibaba #Apple #CI/CD Security #Cyber Security #Dependency Confusion #DevSecOps #google #JavaScript #Malware 2026 #npm #Panther Threat Research #supply chain attack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 12 May 2026 07:57:45 +0000
════════════════════════
⌗ Tags: #Malware #Alibaba #Apple #CI/CD Security #Cyber Security #Dependency Confusion #DevSecOps #google #JavaScript #Malware 2026 #npm #Panther Threat Research #supply chain attack
Penetration Testing Tools
Poisoning the Pipeline: How the "Frank" Campaign Targeted Apple and Google via NPM Dependency Confusion
Cybersecurity specialists have exposed a pervasive malicious campaign targeting developers, wherein the adversary bypassed the compromise of finished
⤷ Title: Massive npm Dependency Confusion Attack Infiltrates Corporate Ecosystems
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 30 May 2026 01:44:11 +0000
════════════════════════
⌗ Tags: #Malware #Code Security #dependency confusion #DevSecOps #JavaScript dropper #Microsoft Threat Intelligence #npm registry #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 30 May 2026 01:44:11 +0000
════════════════════════
⌗ Tags: #Malware #Code Security #dependency confusion #DevSecOps #JavaScript dropper #Microsoft Threat Intelligence #npm registry #supply chain attack
Daily CyberSecurity
Massive npm Dependency Confusion Attack Infiltrates Corporate Ecosystems
Microsoft uncovers a massive npm dependency confusion attack targeting enterprise infrastructure. Learn how these malicious packages discovered run code.
⤷ Title: irect and Transitive Dependencies: Why Every Version Must Be Analyzed
════════════════════════
𐀪 Author: Juliano Pereira de Souza
════════════════════════
ⴵ Time: Tue, 28 Jul 2026 17:37:47 GMT
════════════════════════
⌗ Tags: #owasp #application_security #cybersecurity #software_security #dependency_management
════════════════════════
𐀪 Author: Juliano Pereira de Souza
════════════════════════
ⴵ Time: Tue, 28 Jul 2026 17:37:47 GMT
════════════════════════
⌗ Tags: #owasp #application_security #cybersecurity #software_security #dependency_management
Medium
irect and Transitive Dependencies: Why Every Version Must Be Analyzed
Finding a vulnerable package is only the beginning of the investigation