πNew WriteupβοΈ
βββββββββββββββ
πDate: Mon, 03 Apr 2023 15:32:19 GMT
βββββββββββββββ
βοΈTitle: Are open-source NPM packages always secure to use?
βββββββββββββββ
πLink: https://medium.com/p/215e9d3902be
βββββββββββββββ
Tags: #npm #nodejs #dependency_management #security
βββββββββββββββ
πDate: Mon, 03 Apr 2023 15:32:19 GMT
βββββββββββββββ
βοΈTitle: Are open-source NPM packages always secure to use?
βββββββββββββββ
πLink: https://medium.com/p/215e9d3902be
βββββββββββββββ
Tags: #npm #nodejs #dependency_management #security
Medium
Are open-source NPM packages always secure to use?
Node.js has a rich ecosystem of open-source packages available through the npm registry. These packages provide developers with pre-builtβ¦
πNew WriteupβοΈ
βββββββββββββββ
πDate: Mon, 17 Apr 2023 15:02:15 GMT
βββββββββββββββ
βοΈTitle: Flawed choices: Developers continue to use vulnerable open-source dependencies
βββββββββββββββ
πLink: https://medium.com/p/b12092fb9abd
βββββββββββββββ
Tags: #application_security #cybersecurity #dependency_management #open_source #software_development
βββββββββββββββ
πDate: Mon, 17 Apr 2023 15:02:15 GMT
βββββββββββββββ
βοΈTitle: Flawed choices: Developers continue to use vulnerable open-source dependencies
βββββββββββββββ
πLink: https://medium.com/p/b12092fb9abd
βββββββββββββββ
Tags: #application_security #cybersecurity #dependency_management #open_source #software_development
Medium
Flawed choices: Developers continue to use vulnerable open-source dependencies
While the open-source ecosystem continues to make progress on securing the production of widely used components, devs still need more.
πNew WriteupβοΈ
βββββββββββββββ
πDate: Wed, 27 Sep 2023 10:35:21 GMT
βββββββββββββββ
βοΈTitle: Find Vulnerable Dependencies using OWASP Dependency Check
βββββββββββββββ
πLink: https://medium.com/p/f3c130af6078
βββββββββββββββ
Tags: #java #owasp #vulnerability #maven_plugin #dependency_check
βββββββββββββββ
πDate: Wed, 27 Sep 2023 10:35:21 GMT
βββββββββββββββ
βοΈTitle: Find Vulnerable Dependencies using OWASP Dependency Check
βββββββββββββββ
πLink: https://medium.com/p/f3c130af6078
βββββββββββββββ
Tags: #java #owasp #vulnerability #maven_plugin #dependency_check
Medium
Find Vulnerable Dependencies using OWASP Dependency Check
OWASP Dependency Check is a useful tool for checking vulnerabilities in your project and generating a comprehensive report.
β€· Title: AWS Lambda Layers Simplified: A Beginnerβs Guide
ββββββββββββββββββββββββ
πͺ Author: Thushara Samaraweera
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 26 Dec 2024 06:37:35 GMT
ββββββββββββββββββββββββ
β Tags: #aws_lambda_layer #aws_lambda #reusable #dependency_management
ββββββββββββββββββββββββ
πͺ Author: Thushara Samaraweera
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 26 Dec 2024 06:37:35 GMT
ββββββββββββββββββββββββ
β Tags: #aws_lambda_layer #aws_lambda #reusable #dependency_management
Medium
AWS Lambda Layers Simplified: A Beginnerβs Guide
Step-by-step instructions to get started with Lambda layers and enhance your serverless apps
β€· Title: Dependency Confusion: A Threat Actor in the Modern Software Ecosystem
ββββββββββββββββββββββββ
πͺ Author: Batuhan Sancak
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 10 Apr 2025 05:28:51 GMT
ββββββββββββββββββββββββ
β Tags: #dependency_injection #cybersecurity #appsec #software_development #security
ββββββββββββββββββββββββ
πͺ Author: Batuhan Sancak
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 10 Apr 2025 05:28:51 GMT
ββββββββββββββββββββββββ
β Tags: #dependency_injection #cybersecurity #appsec #software_development #security
Medium
Dependency Confusion: A Threat Actor in the Modern Software Ecosystem
Table of Contents
β€· Title: Malicious NPM Packages Target PayPal Users to Steal Sensitive Data
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 14 Apr 2025 00:16:26 +0000
ββββββββββββββββββββββββ
β Tags: #Malware #cybersecurity #Data Theft #dependency confusion #FortiGuard Labs #Information stealing #javascript #Malicious packages #npm #NPM packages #Package manager #paypal #Software security #supply chain attack
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 14 Apr 2025 00:16:26 +0000
ββββββββββββββββββββββββ
β Tags: #Malware #cybersecurity #Data Theft #dependency confusion #FortiGuard Labs #Information stealing #javascript #Malicious packages #npm #NPM packages #Package manager #paypal #Software security #supply chain attack
Daily CyberSecurity
Malicious NPM Packages Target PayPal Users to Steal Sensitive Data
FortiGuard Labs discovers malicious NPM packages targeting PayPal users. Attackers use deceptive tactics to steal usernames, paths, and hostnames
β€· Title: How I Discovered a Live Dependency Confusion Vulnerability in a GraphQL-Based Web Application
ββββββββββββββββββββββββ
πͺ Author: Sanaullah Aman Korai
ββββββββββββββββββββββββ
β΄΅ Time: Sat, 05 Jul 2025 17:38:20 GMT
ββββββββββββββββββββββββ
β Tags: #ethical_hacking #dependency_confusion #supply_chain_security #bug_bounty #cybersecurity
ββββββββββββββββββββββββ
πͺ Author: Sanaullah Aman Korai
ββββββββββββββββββββββββ
β΄΅ Time: Sat, 05 Jul 2025 17:38:20 GMT
ββββββββββββββββββββββββ
β Tags: #ethical_hacking #dependency_confusion #supply_chain_security #bug_bounty #cybersecurity
Medium
How I Discovered a Live Dependency Confusion Vulnerability in a GraphQL-Based Web Application
In this write-up, I will walk you through how I discovered a live Dependency Confusion vulnerability using GraphQL introspection andβ¦
β€· Title: The Hidden Threat in Your Code: How Malicious PyPI and npm Packages Are Weaponizing Developer Trustβ¦
ββββββββββββββββββββββββ
πͺ Author: Ismail Tasdelen
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 18 Aug 2025 15:46:03 GMT
ββββββββββββββββββββββββ
β Tags: #dependency_injection #code #application_security #cybersecurity #supply_chain_security
ββββββββββββββββββββββββ
πͺ Author: Ismail Tasdelen
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 18 Aug 2025 15:46:03 GMT
ββββββββββββββββββββββββ
β Tags: #dependency_injection #code #application_security #cybersecurity #supply_chain_security
Medium
The Hidden Threat in Your Code: How Malicious PyPI and npm Packages Are Weaponizing Developer Trust π―
When your favorite programming libraries become digital Trojan horses
β€· Title: Ketorolac Injection Market Growth in 2025β2034: Dynamics, Opportunities, and Strategies
ββββββββββββββββββββββββ
πͺ Author: Prajval Jadhav
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 03 Sep 2025 05:45:58 GMT
ββββββββββββββββββββββββ
β Tags: #dependency_injection #ketorolac #ketorolac_injection #injection #sql_injection
ββββββββββββββββββββββββ
πͺ Author: Prajval Jadhav
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 03 Sep 2025 05:45:58 GMT
ββββββββββββββββββββββββ
β Tags: #dependency_injection #ketorolac #ketorolac_injection #injection #sql_injection
Medium
Ketorolac Injection Market Growth in 2025β2034: Dynamics, Opportunities, and Strategies
βGlobal Ketorolac Injection Market Share and Ranking, Overall Sales and Demand Forecast 2025β2034β is the most recent report published by Exactitude Consultancy, a leading global market researchβ¦
β€· Title: Turning Dependency Confusion Research into a Profitable Stack
ββββββββββββββββββββββββ
πͺ Author: Abdelrhman Allam (sl4x0)
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 08 Oct 2025 15:23:43 GMT
ββββββββββββββββββββββββ
β Tags: #infosec #dependency_confusion #cybersecurity #bug_bounty #supply_chain
ββββββββββββββββββββββββ
πͺ Author: Abdelrhman Allam (sl4x0)
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 08 Oct 2025 15:23:43 GMT
ββββββββββββββββββββββββ
β Tags: #infosec #dependency_confusion #cybersecurity #bug_bounty #supply_chain
Medium
Turning Dependency Confusion Research into a Profitable Stack
βThe easiest way to get started is to find some promising research by someone else, build on it by mixing in other techniques, then applyβ¦
β€· Title: Hunting Dependency Confusion: Supply Chain Vulnerabilities for Bug Bounties
ββββββββββββββββββββββββ
πͺ Author: Aman Bhuiyan
ββββββββββββββββββββββββ
β΄΅ Time: Sat, 11 Oct 2025 19:11:46 GMT
ββββββββββββββββββββββββ
β Tags: #bug_hunting #dependency_injection #hacking #bug_bounty
ββββββββββββββββββββββββ
πͺ Author: Aman Bhuiyan
ββββββββββββββββββββββββ
β΄΅ Time: Sat, 11 Oct 2025 19:11:46 GMT
ββββββββββββββββββββββββ
β Tags: #bug_hunting #dependency_injection #hacking #bug_bounty
Medium
Hunting Dependency Confusion: Supply Chain Vulnerabilities for Bug Bounties
Hey there, fellow bug bounty hunters and security enthusiasts! If youβve been knee-deep in web app pentesting, youβve probably chased XSSβ¦
β€· Title: So, βShift-Leftβ Failed. What Comes Next?
ββββββββββββββββββββββββ
πͺ Author: Ali Naqvi
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 07 Jan 2026 15:40:44 GMT
ββββββββββββββββββββββββ
β Tags: #dependency_management #application_security #devtools #software_development #shiftleft
ββββββββββββββββββββββββ
πͺ Author: Ali Naqvi
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 07 Jan 2026 15:40:44 GMT
ββββββββββββββββββββββββ
β Tags: #dependency_management #application_security #devtools #software_development #shiftleft
Medium
So, βShift-Leftβ Failed. What Comes Next?
Remember the days when Security and Development were two different teams who met annually at the company holiday party? Siloed, withβ¦
β€· Title: Finding Remote Code Execution in Google: A Bug Hunterβs Story
ββββββββββββββββββββββββ
πͺ Author: zabit majeed
ββββββββββββββββββββββββ
β΄΅ Time: Sun, 11 Jan 2026 17:49:36 GMT
ββββββββββββββββββββββββ
β Tags: #cve #google #bug_bounty #dependency_injection #hacking
ββββββββββββββββββββββββ
πͺ Author: zabit majeed
ββββββββββββββββββββββββ
β΄΅ Time: Sun, 11 Jan 2026 17:49:36 GMT
ββββββββββββββββββββββββ
β Tags: #cve #google #bug_bounty #dependency_injection #hacking
Medium
Finding Remote Code Execution in Google: A Bug Hunterβs Story
Hey everyone, this is Zabit Majeed . Iβm an ethical hacker and a part-time bug bounty hunter, and this story is about persistence moreβ¦
β€· Title: How I Discovered a Dependency Confusion Vulnerability in a Ruby Application Leading to RCE
ββββββββββββββββββββββββ
πͺ Author: Ahmed Tarek
ββββββββββββββββββββββββ
β΄΅ Time: Sat, 17 Jan 2026 19:06:39 GMT
ββββββββββββββββββββββββ
β Tags: #pentesting #bug_bounty #dependency_confusion #bug_bounty_tips #ruby
ββββββββββββββββββββββββ
πͺ Author: Ahmed Tarek
ββββββββββββββββββββββββ
β΄΅ Time: Sat, 17 Jan 2026 19:06:39 GMT
ββββββββββββββββββββββββ
β Tags: #pentesting #bug_bounty #dependency_confusion #bug_bounty_tips #ruby
Medium
How I Discovered a Dependency Confusion Vulnerability in a Ruby Application Leading to RCE
hey there,
β€· Title: # How I Found a Snyk-Verified 9.3
ββββββββββββββββββββββββ
πͺ Author: freebold
ββββββββββββββββββββββββ
β΄΅ Time: Sat, 14 Mar 2026 12:48:36 GMT
ββββββββββββββββββββββββ
β Tags: #supply_chain #cybersecurity #npm #dependency_confusion #bug_bounty
ββββββββββββββββββββββββ
πͺ Author: freebold
ββββββββββββββββββββββββ
β΄΅ Time: Sat, 14 Mar 2026 12:48:36 GMT
ββββββββββββββββββββββββ
β Tags: #supply_chain #cybersecurity #npm #dependency_confusion #bug_bounty
Medium
# How I Found a Snyk-Verified 9.3
# How I Found a Snyk-Verified 9.3 Critical Vulnerability in FDJ United's Gaming Platform β And Got Paid Nothing **By freebold | Security Researcher** --- ## TL;DR I discovered a critical dependency β¦
β€· Title: Supply Chain Shield: How DepConfuse Proactively Stops Dependency Confusion Attacks
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 16 Mar 2026 09:24:16 +0000
ββββββββββββββββββββββββ
β Tags: #Open Source Tool #cybersecurity tools #CycloneDX #DepConfuse #Dependency Confusion #DevSecOps #open source security #PURL #SBOM #Software Composition Analysis #Supply Chain Security
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 16 Mar 2026 09:24:16 +0000
ββββββββββββββββββββββββ
β Tags: #Open Source Tool #cybersecurity tools #CycloneDX #DepConfuse #Dependency Confusion #DevSecOps #open source security #PURL #SBOM #Software Composition Analysis #Supply Chain Security
Penetration Testing Tools
Supply Chain Shield: How DepConfuse Proactively Stops Dependency Confusion Attacks
Stop dependency confusion before it starts. DepConfuse is an SBOM-first tool that scans 20+ registries to secure your software supply chain from package takeover.