On April 16, 2025, CVE-2025-32433 was disclosed—a critical remote code execution (RCE) vulnerability.
Lea Edelstein
|
2
min read
Two researchers have recently discovered an authorization-bypass bug in the popular NextJS framework by Vercel. Tracked as CVE-2025-29927
Tomer Filiba
|
2
min read
A new set of high-severity vulnerabilities, collectively dubbed IngressNightmare, has been discovered by Wiz. Sweet keeps you secure.
Tomer Filiba
|
1
min read
On Friday, a supply chain attack compromised the widely used GitHub Action tj-actions/changed-files, exposing secrets from numerous repos.
Tomer Filiba
|
2
min read
The recent XZ (liblzma) supply-chain attack is a marvel of social engineering and a great example of evading detection under the many-eyes..
Tomer Filiba
|
2
min read
As reported, Snowflake, the data cloud company, is currently under fire for an account hacks campaign...
Sarah Elkaim
|
5
min read
Qualys research has discovered a critical Remote Code Execution (RCE) vulnerability, CVE-2024-6387, that has resurfaced in OpenSSH.
Sarah Elkaim
|
2
min read
Bleeping Computer has recently reported on a new vulnerability within Ghostscipt, a widely used library for handling PostScript and PDF file
Tomer Filiba
|
min read
Sarah Elkaim
|
min read
We’re excited to announce that Sweet Security has officially released CandyStore – an extremely fast open source key-value store
Tomer Filiba
|
2
min read