Six Proto6 flaws in protobuf.js enable RCE and DoS attacks; patched in versions 7.5.6 and 8.0.2 to protect Node.js services.
They swear they haven’t peeked at the closely guarded secret and that they’ll keep the cryptographic competition going.
The Miasma credential-stealing attack framework, which has recently targeted open-source ecosystems through supply-chain ...