### [Exploits Explained: ZIP embedding attack on Google Chrome extensions](https://readme.synack.com/exploits-explained-zip-embedding-attack-on-google-chrome-extensions)
Malcolm Stagg recounts the discovery of CVE-2024-0333, a vulnerability in Google Chrome that could have been exploited to install malicious extensions.

---

### [Rapid7 vs JetBrains: A vulnerability disclosure process gone bad](https://readme.synack.com/rapid7-vs-jetbrains-a-vulnerability-disclosure-process-gone-bad)
A recent conflict between Rapid7 and JetBrains over how to disclose vulnerabilities was marred by blame, confusion and conflicting philosophies.

---

### [CVSS 4.0 is shaking up vulnerability management. Here’s what’s changed](https://readme.synack.com/cvss-4-is-shaking-up-vulnerability-management.-heres-whats-changed)
CVSS 4.0 urges companies to go beyond base scores, allowing them to more accurately judge the threat posed by particular vulnerabilities.

---

### [The problems with vulnerability reporting](https://readme.synack.com/the-problems-with-vulnerability-reporting)
Several recent incidents in the U.S. system for reporting vulnerabilities highlight the importance of accurate, comprehensive bug reports for defenders.

---

### [MOVEit Transfer saga shows danger of the 'Dark Middle'](https://readme.synack.com/moveit-transfer-saga-shows-danger-of-the-dark-middle)
When attackers find vulnerabilities in software used by service providers with dozens or hundreds of clients, the impact of a breach can quickly spiral out of control.

---

### [Memory safety is the first step, not the last, towards secure software](https://readme.synack.com/memory-safety-is-the-first-step-not-the-last-towards-secure-software)
The U.S. government and technology giants alike are urging developers to replace C and C++ with modern, memory-safe languages like Rust. Will it be enough?

---

### [As APIs proliferate, attackers follow](https://readme.synack.com/as-apis-proliferate-attackers-follow)
With APIs accounting for more than half of all internet traffic, attacks on mobile and web application endpoints continue to grow.

---

### [Home is where the hackers are: The dizzying task of securing remote work](https://readme.synack.com/home-is-where-the-hackers-are-the-dizzying-task-of-securing-remote-work)
Increases in phishing attacks, credential stuffing against corporate cloud services and unpatched vulnerabilities in consumer hardware have all skyrocketed since the COVID pandemic upended work routines.

---

### [Flawed choices: Developers continue to use vulnerable open-source dependencies](https://readme.synack.com/flawed-choices-developers-continue-to-use-vulnerable-open-source-dependencies)
While the open-source ecosystem continues to make progress on securing the production of widely used components, developers need better tools and a security culture to benefit.

---

### [From programmer to pwner: My zero-day journey to Pwn2Own](https://readme.synack.com/from-programmer-to-pwner-my-zero-day-journey-to-pwn2own)
Security researcher Vera Mens and her colleagues on Claroty’s Team82 took on some of the toughest challenges in the industrial cybersecurity field at Pwn2Own Miami.
