#code-signing

[ follow ]
fromTechzine Global
3 days ago

Vulnerability in Notepad++ updater exploited for malware

A security vulnerability in the Notepad++ update mechanism has been exploited to spread malicious code. What began as a report within the Notepad++ community at the end of October was later confirmed to be a structural weakness in the updater. Analysis by BleepingComputer shows that attackers were able to execute malware via this mechanism. Notepad++ has since released a fix in version 8.8.9.
Information security
Information security
fromDevOps.com
6 months ago

Code Signing in the DevOps Era: Silver Bullet or Security Theater? - DevOps.com

Code signing requires effective management and controls to be a true security measure, or it creates a false sense of security.
[ Load more ]