
Episode 296 - OWASP Top 10, NX Compromise, Security News Sources
Show notes
Ken and Seth kickoff a podcast by reviewing current state of the OWASP Top 10 project, given recent requests and interactions on Absolute AppSec slack from various contributors. This is followed by an in-depth breakdown of the recent NX npm package compromise. This breakdown shows that even though AI is weaponized to exfiltrate data, the main exploit was the result of a command injection flaw. Crocs and Socks coming back to bit all of us. Finally, Ken and Seth provide a list of resources used to monitor the wider security community.
← Previous
Episode 295 - DEF CON 33 Recap, Crocs and Socks (and Bots)
Next →
Episode 297 - True/False Positives, Phishing Package Maintainers