Cyber Security
4276 articles
4276 ARTICLES

The MongoDB hack and the importance of secure defaults
There’s a widespread attack on insecure MongoDB installs that has resulted in over 28,000 databases being held ransom. This post explains the hack, how to protect yourself and what can we learn from it.

Building the VSTS Snyk task, an interview with Jesse Houwing
Jesse Houwing is a Lead Consultant at Xpirit. Recently he published a really helpful Visual Studio Team Services (VSTS) task making it easier to get Snyk incorporated into your VSTS workflow. We interviewed him to learn more about how he did it.

Announcing Snyk CLI for Ruby, and more ways to fix Ruby vulnerabilities
Since we launched Ruby last month, we’ve been working away on improvements. Today we’re excited to let you know about our extended support for Ruby.

Differences in version handling between RubyGems and npm

Fixing a Remote Code Execution Vulnerability in EJS
This week we added a high-severity Remote Code Execution vulnerability in the EJS package to our vulnerability database.

A brief history of modularity
Just over a week ago, we were sponsors at the Brighton conference, ffconf. It was a day full of brilliant talks, both thought provoking and useful. Ashley Williams of npm gave a talk titled “A brief history of modularity”, which we felt was particularly relevant to Snyk, and so we thought we’d share a summary of the talk here.


Launching serverless Snyk
Today we’re releasing the Serverless Snyk plugin—a plugin for the Serverless framework that helps you to prevent vulnerable packages in your application, using Snyk!

Building Security Tools Developers Love
In the latest episode of “The Secure Developer”, I had the pleasure of interviewing Sabin Thomas, VP Engineering at Codiscope.

Yarn is Micro Secure
In 2016, Facebook announced the open-source release of Yarn: an alternative client for the npm registry. While it’s true that Yarn is often much faster than other clients, and that the new lockfile ensures more consistency when your application is installed, the security claims around it are a little over-optimistic.

Fixing Serverless Security Vulnerabilities
Well over 80% of successful exploits today occur due to unpatched servers. Approaches such as Serverless & PaaS should dramatically reduce the risk of outdated binaries. Unfortunately, this transition does nothing to secure open source code packages.
