Week in review: Popular npm package hijacked, zero trust security key tenets, wildcard certificate risks

This article has been indexed from Help Net Security

Here’s an overview of some of last week’s most interesting news, articles and interviews: Apple fixes security feature bypass in macOS (CVE-2021-30892) Apple has delivered a barrage of security updates for most of its devices this week, and among the vulnerabilities fixed are CVE-2021-30892, a System Integrity Protection (SIP) bypass in macOS, and CVE-2021-30883, an iOS flaw that’s actively exploited by attackers. SolarWinds hackers are going after cloud, managed and IT service providers Nobelium, the … More

The post Week in review: Popular npm package hijacked, zero trust security key tenets, wildcard certificate risks appeared first on Help Net Security.

Read the original article: Week in review: Popular npm package hijacked, zero trust security key tenets, wildcard certificate risks