Checkmarx Security Research Team

Category //

Checkmarx Security Research Team

The evolutionary tale of a persistent Python threat 

In the vast landscape of the open-source ecosystem, shadows occasionally move. While this realm thrives on collaboration and knowledge sharing, it’s also a playground for predators, from novice hackers to well-coordinated nation-state actors. Over recent months, one such threat has

Read More »

Surprise: When Dependabot Contributes Malicious Code  

What Happened?  About Dependabot  Dependabot is GitHub’s free automated dependency management tool for software projects. It continuously monitors a project’s dependencies (like libraries and packages) for security vulnerabilities and outdated versions. When it detects issues, it automatically generates pull requests

Read More »
Skip to content