CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4484

As cited

Copy frozen at (site build).

vulnerabilities

Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day

GitHub extended Dependabot malware alerts to cover eight package ecosystems, including PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer, after previously monitoring only npm. The expansion provides developers with warnings across a broader range of dependency sources.

Why it matters: Developers relying on non-npm packages now gain malware detection visibility in their supply chain; practitioners should update their dependency scanning processes to leverage the newly covered ecosystems.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day

GitHub extended Dependabot malware alerts to cover eight package ecosystems, including PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer, after previously monitoring only npm. The expansion provides developers with warnings across a broader range of dependency sources.

Why it matters: Developers relying on non-npm packages now gain malware detection visibility in their supply chain; practitioners should update their dependency scanning processes to leverage the newly covered ecosystems.

VendorsGitHubSalesforceServiceNow
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary