CTO
The npm ecosystem is once again at the center of a major supply-chain security incident.
Tomer Filiba
|
2
min read
Sweet Security extended its runtime coverage to Windows environments.
4
A massive supply-chain attack is affecting npm packages.
3
The npm ecosystem has suffered an unprecedented supply-chain attack.
A critical vulnerability in Python's tarfile module (versions ≥ 3.12) allows attackers to modify metadata or permissions on files.
Two researchers have recently discovered an authorization-bypass bug in the popular NextJS framework by Vercel. Tracked as CVE-2025-29927
A new set of high-severity vulnerabilities, collectively dubbed IngressNightmare, has been discovered by Wiz. Sweet keeps you secure.
1
On Friday, a supply chain attack compromised the widely used GitHub Action tj-actions/changed-files, exposing secrets from numerous repos.
The recent XZ (liblzma) supply-chain attack is a marvel of social engineering and a great example of evading detection under the many-eyes..
Bleeping Computer has recently reported on a new vulnerability within Ghostscipt, a widely used library for handling PostScript and PDF file
Yesterday, a new set of vulnerabilities (CVE-2024-47076, CVE-2024-47175/6/7) was discovered on Linux’s Common UNIX Printing System...
We’re excited to announce that Sweet Security has officially released CandyStore – an extremely fast open source key-value store