Security
|
Feb 10, 2021
"Shopify's build system automatically installed a Ruby gem only a few hours after I had uploaded it, and then tried to run the code inside it."
Cisco product security continues to demand regular urgent patching from users: the company last week pushing out an advisory after multiple critical (CVSS 9.8) vulnerabilities were found in a family of VPN routers. The bugs grant any unauthenticated, remote attacker the ability to execute code as all-powerful root user.