Luca Pierluigi Famà

6 posts

Polyfill js - Another Supply Chain Attack

Polyfill js - Another Supply Chain Attack

What happens if a popular open-source JavaScript library get hacked?

XZ Backdoor (CVE-2024-3094) - A hidden backdoor in open-source software

XZ Backdoor (CVE-2024-3094) - A hidden backdoor in open-source software

How a malicious actor was able to gain credibility and inject malicious payload in a popular unix-like compression library

JavaScript prototype chain and security risks

JavaScript prototype chain and security risks

What is a prototype in JavaScript and why it can lead to dangerous vulnerabilities

Software Design Security Principles

Software Design Security Principles

A list of basic design principles to build more secure software

Dependency confusion attack technique

Dependency confusion attack technique

Don't blindly trust third party libraries..

DevSecOps vs Log4Shell

DevSecOps vs Log4Shell

How DevSecOps could help mitigate Log4j (and similar) security incidents