Security news aggregator

Latest coverage for Library

Stay informed with the latest in information security. Explore our comprehensive library of articles, updates, and insights on cyber threats and defenses.

267 headlines in this view

Refine the feed

Search across headline titles and summaries.

Tag briefing

Background for this topic.

Library is a collection of reusable code used in software development. In the context of information security, a Library pertains to the secure coding practices, vulnerabilities, and the potential risks that come with integrating these collections of functions, routines, or classes into an application. Security-conscious development necessitates the use of libraries that are regularly updated and patched to safeguard against known exploits.

Within information security, the focus on libraries involves ensuring that they do not introduce security weaknesses or backdoors into an application. This includes scrutinizing open-source libraries for security flaws, verifying the authenticity of libraries to avert supply-chain attacks, and implementing strict version control to mitigate the risks associated with outdated or compromised libraries.

Keeping a library secure involves active maintenance, which includes regular audits, applying patches, and monitoring for new vulnerabilities that could impact the software that depends upon these libraries.

Volume over time

Weekly headline count for the current query.

Showing 20 most recent headlines of 267 Filtered view
Bank Info Security 1 month, 1 week ago

Flurry of Supply-Chain Software Library Attacks

Continuous Integration Has Its DownsidesAs supply-chain attacks against widely-used, open-source software repositories continue, experts are urging developers to not only rely on code integrity tools, but also to introduce a delay before merging new repos, since unfolding attacks tend to get spotted in days, if not hours or minutes.

Lightweight LLM-Driven Process Alerted Elastic's Security Team, Says James SpiteriElastic Security Labs quickly spotted the unfolding supply-chain attack that backdoored the popular JavaScript library Axios, thanks to a lightweight, AI-driven tool a researcher created to assess if repository changes looked malicious. Elastic's James Spiteri says further use cases abound.

Two weeks ago, a suspected North Korean threat actor slipped malicious code into a package within Axios, a widely used JavaScript library. The immediate concern was the blast radius: roughly 100 million weekly downloads spanning enterprises, startups, and government systems. But beyond the sheer scale, the attack’s speed was just as worrisome – a stark […] The post Why the Axios attack proves AI is mandatory for supply chain security appeared first on CyberScoop.

The company said a developer tool automatically retrieved a malicious version of the popular open-source library, but insists the integrity of its systems and software were not impacted. The post OpenAI’s Mac apps need updates thanks to the Axios hack appeared first on CyberScoop.

Expect Fallout After Remote Access Trojan Added to Popular JavaScript NPM PackageA supply-chain attack backdoored versions of Axios, a popular JavaScript library that's present in many different software packages, to distribute a cross-platform, remote access Trojan. Identifying the full fallout from the attack could take some time, experts warned.

Researcher: If Exploited, Bug Could Crash Hospital Medical Imaging SystemsThe Cybersecurity Infrastructure and Security Agency is warning of a high severity in Grassroots DICOM, an open-source library commonly used for medical imaging products, that if exploited could allow an attacker to send a specially crafted file resulting in a denial-of-service situation.

Loading more headlines...