Tech News
Все новости AI & ML Architecture DevOps Open Source Programming Team Management Testing & QA Web

Последние новости

⚑ Сообщить о проблеме

Tech news from the best sources

Все темы AI Gear News Tech agents ai api architecture automation beginners career database devchallenge devops javascript llm machinelearning mcp opensource performance productivity programming python react security showdev testing tutorial typescript webdev
Все EN RU
EN

BMC Vulnerabilities Put Thousands of Servers at Risk of Hardware-Level Compromise

Security researchers are warning that thousands of enterprise servers could be exposed to compromise through vulnerabilities in their Baseboard Mana…

HardwareArtificial IntelligenceSecurity VulnerabilitiesDevOpsnews
InfoQ Aug 25, 2026, 12:00 UTC
EN

DRAM Controller Register Manipulation Breaks CPU Memory Isolation

Security researcher Christopher Domas developed skitter-creek-bath-salts, an open-source hardware security tool that disrupts CPU privilege boundari…

MemorySecurity VulnerabilitiesSecurityDevOpsDevelopmentnews
InfoQ Aug 23, 2026, 04:04 UTC
EN

npm Staged Publishing Available, Adding a Human Approval Step Before Packages Go Live

npm has introduced staged publishing for Node.js, requiring maintainer approval before a version is installable. Versions are queued and must pass a…

Open SourceApplication SecurityNPMSecurity VulnerabilitiesWeb DevelopmentDevelopmentnews
InfoQ Aug 7, 2026, 06:12 UTC
EN

Wiz Discloses CosmosEscape, and Practitioners Debate What Customers Could Have Done

Wiz Research disclosed CosmosEscape, a chain that escaped Azure Cosmos DB's Gremlin sandbox and reached a platform-wide key granting read and write…

Security VulnerabilitiesCloud ArchitectureCloudDatabaseAccess ControlAzureMulti-Tenant DataMulti-tenancyDevOpsArchitecture & DesignDevelopmentnews
InfoQ Aug 6, 2026, 09:21 UTC
EN

GitHub Introduces Default "Cooldown" Policy for Dependabot Version Updates

Instead of immediately opening pull requests when newer dependency versions are released, Dependabot now waits three days before suggesting upgrades…

githubSecurity VulnerabilitiesSoftware Supply ChainDependency ManagementDevOpsDevelopmentnews
InfoQ Jul 28, 2026, 19:00 UTC
EN

AI-Enabled Security Researchers Discover How a Crafted Video Can Provide Attackers Access to Your PC

JFrog Security Research revealed "PixelSmash," a vulnerability in the FFmpeg media framework, allowing for Remote Code Execution and Denial of Servi…

Streaming VideoVideo CodecFFmpeg Video CodecSecurity VulnerabilitiesSecurityDevelopmentDevOpsnews
InfoQ Jul 26, 2026, 09:09 UTC
EN

Indirect Prompt Injection Exploits GitHub's AI Agent to Leak Private Repository Data

GitLost is a prompt-injection exploit discovered by Noma Security that tricks GitHub's new Agentic Workflows into leaking private data. By embedding…

AgentsgithubSecurity VulnerabilitiesLarge language modelsPrompt EngineeringDevOpsDevelopmentnews
InfoQ Jul 23, 2026, 20:00 UTC
EN

BadHost Vulnerability Exposes AI Agents, Evaluators, and LLM Gateways

BadHost is a high-severity authentication bypass vulnerability in the widely used Python web framework Starlette, with 325 million weekly downloads.…

Open SourcePythonSecurity VulnerabilitiesAgentsAI, ML & Data EngineeringDevOpsDevelopmentnews
InfoQ Jun 1, 2026, 14:00 UTC
EN

A Trailing Slash Bypassed AWS API Gateway Authorization

A security researcher found that adding a trailing slash to AWS HTTP API paths bypassed Lambda authorizer authentication entirely, enabling unauthen…

AWSAPI GatewayApplication SecurityAWS LambdaCloudSecurity VulnerabilitiesDevOpsDevelopmentArchitecture & Designnews
InfoQ Jun 1, 2026, 09:55 UTC
EN

Arm Open-Sources Metis, an AI Security Framework Outperforming Traditional SAST Tools

Arm has open-sourced Metis, an agentic AI security framework designed to autonomously uncover complex software vulnerabilities. Unlike traditional p…

ARMSecurityOpen SourceStatic AnalysisLarge language modelsAgentsSecurity VulnerabilitiesDevOpsAI, ML & Data EngineeringDevelopmentnews
InfoQ May 30, 2026, 19:00 UTC
EN

Copy Fail and Dirty Frag: Linux Page-Cache Exploits Target Every Major Distribution

Two recent Linux kernel vulnerabilities have been disclosed: Copy Fail (CVE-2026-31431) on April 29, 2026, and Dirty Frag (CVE-2026-43284 and CVE-20…

LinuxSecurity VulnerabilitiesDevOpsnews
InfoQ May 12, 2026, 08:00 UTC
EN

Attacker Bought 30 WordPress Plugins on Flippa and Backdoored All of Them

An attacker purchased 30+ WordPress plugins on Flippa for six figures, planted a PHP deserialization backdoor in the first commit, and waited eight…

Security VulnerabilitiesApplication SecuritySoftware Supply ChainDependency ManagementDevelopmentArchitecture & Designnews
InfoQ May 6, 2026, 10:00 UTC
EN

Cloudflare Processes 10M+ Daily Insights with New Security Overview Dashboard

Cloudflare has launched a Security Overview dashboard that consolidates security signals into prioritized action items. It surfaces millions of dail…

Security VulnerabilitiesCloudflareReal TimeObservabilityThreat detectionSecurity AssessmentThreatsSecurityIncident ResponseAI, ML & Data EngineeringDevelopmentArchitecture & Designnews
InfoQ May 4, 2026, 14:33 UTC

© Tech News — Агрегатор новостей

English Русский
Карта сайта Правовая информация Конфиденциальность Условия использования Авторские права / Удаление Контакт DSA

Выход с сайта

Вы собираетесь открыть внешний сайт:

Продолжить →