Skip to content

sicurezza

9 articles on this topic

  • cra
  • compliance

Cyber Resilience Act: under three weeks to 11 September

In July we explained why the CRA's first binding deadline is 11 September 2026, not 2027. Now time is up: from 11 September the 24 and 72-hour clocks for exploited vulnerabilities start. The final checklist, no theory.

, 2 min read

  • nextjs
  • sicurezza

Next.js flags a critical patch for 26 August: get ready now

Vercel did something rare and right: it gave advance notice that a patch for a critical Next.js vulnerability lands on 26 August, in versions 16.3.3 and 15.5.24. The details come that day. What to do in the days before so you do not eat the exploitation window.

, 2 min read

  • sicurezza
  • supply-chain

The worm that infected keyv: inside August's npm supply chain attack

On 4 August the GitHub account of the keyv maintainer was compromised, 127 million weekly downloads, and within two days a self-propagating worm poisoned over 1,300 package versions. You do not need to use keyv to be hit. What we checked across client pipelines.

, 2 min read

  • wordpress
  • sicurezza

WP2Shell: the WordPress flaw that needs no login

On 17 July WordPress closed WP2Shell, a two-CVE chain giving unauthenticated code execution on a clean install, and the first attempts landed within hours. What we checked across the sites we maintain, and why patched does not mean clean.

, 3 min read

Have a project in mind?

Tell us what you need. We reply within one working day.

Articles: sicurezza | SEM Devs