Back Feeds2.Feedburner Code review used to be the only way to catch these bugs
An automated system called NOVA read the source code of 3,915 open-source projects over two months and came back with 14,090 vulnerabilities, each one confirmed through the system’s validation pipeline. Vulnerability researchers at Palo Alto Networks’ Unit 42 built the system and checked its output against the public record afterward. Only 85 findings matched anything already documented, and most of those were published two to eight weeks after NOVA had found them. The count is … More →
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
