Log inSign up
JFrog Security
1,592 posts
JFrog Security profile banner
@JFrogSecurity

JFrog Security

@JFrogSecurity
The JFrog Security Research Team empowers developers and companies to excel by identifying, prioritizing, and mitigating software risks.
USA / Israel
research.jfrog.com
Joined November 2017
309
Following
5,558
Followers
RepliesRepliesRepostsRepostsMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • @JFrogSecurity
    JFrog Security
    @JFrogSecurity
    Sep 3
    CVSS 9.8, but the code doesn't add up. CVE-2026-47890 and CVE-2026-59313 in Spring claim critical impact, but: ❌Same root cause: a stray \r corrupting an SSE stream ❌Spring scores both 2.6, Low, same vector ❌CISA scores both 9.8, Critical, no server-side compromise possible
  • @JFrogSecurity
    JFrog Security
    @JFrogSecurity
    Aug 30
    Read our full technical analysis at: research.jfrog.com/post/shai-hulu…
    @JFrogSecurity
    JFrog Security
    @JFrogSecurity
    Aug 29
    🚨 SUPPLY CHAIN ALERT: Popular npm package @7nohe/openapi-react-query-codegen (~200K downloads/mo) was compromised on Aug 28. Threat actors hijacked an insecure GitHub Actions workflow to publish 10 malicious versions carrying a Bun-based malware payload. Compromised Versions:
  • @JFrogSecurity
    JFrog Security
    @JFrogSecurity
    Aug 29
    🚨 SUPPLY CHAIN ALERT: Popular npm package @7nohe/openapi-react-query-codegen (~200K downloads/mo) was compromised on Aug 28. Threat actors hijacked an insecure GitHub Actions workflow to publish 10 malicious versions carrying a Bun-based malware payload. Compromised Versions:
    6
  • @JFrogSecurity
    JFrog Security
    @JFrogSecurity
    Aug 20
    Read the full details on our blog: research.jfrog.com/post/arrayref-…
    @JFrogSecurity
    JFrog Security
    @JFrogSecurity
    Aug 20
    🚨 Compromised Rust crate on crates.io! The Packages arrayref (~245M downloads) v0.3.10, append-only-vec v0.1.9, and internment v0.8.7 have been compromised! They all silently pulled in proc-macro1, a typosquat of proc-macro2. Its build.rs downloads
  • @JFrogSecurity
    JFrog Security
    @JFrogSecurity
    Aug 20
    🚨 Compromised Rust crate on crates.io! The Packages arrayref (~245M downloads) v0.3.10, append-only-vec v0.1.9, and internment v0.8.7 have been compromised! They all silently pulled in proc-macro1, a typosquat of proc-macro2. Its build.rs downloads
    3
Advertisement
Advertisement