All Posts

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Security

Apr 8, 2026

Apache Struts Vulnerabilities in 2026: Critical CVEs Still Unpatched

From Equifax to today: why Apache Struts EOL vulnerabilities are a growing enterprise risk

Greg Allen

Greg Allen

Share this post via:

herodevs.com/blog-posts/
apache-struts-vulnerabilities-in-2026-critical-cves-still-unpatched

Security

Apr 7, 2026

The Clock is Ticking: Preparing for the .NET 8 and 9 End-of-Life Security Event

Why .NET 8 and 9 EOL is a hard deadline—and how to secure your migration to .NET 10

Hayden Barnes

Hayden Barnes

Share this post via:

herodevs.com/blog-posts/
the-clock-is-ticking-preparing-for-the-net-8-and-9-end-of-life-security-event

Security

Apr 2, 2026

The Supply Chain Attack Playbook: Why Package Ecosystems Keep Getting Compromised

Why maintainer accounts are the weakest link in modern package ecosystems—and what needs to change

Allison Vorthmann

Allison Vorthmann

Share this post via:

herodevs.com/blog-posts/
the-supply-chain-attack-playbook-why-package-ecosystems-keep-getting-compromised

Security

Apr 1, 2026

CVE-2025-1647: Bootstrap 3 XSS Vulnerability via DOM Clobbering in Tooltip and Popover Components

How a DOM clobbering flaw in Bootstrap 3 bypasses HTML sanitization—and what teams can do about it

Greg Allen

Greg Allen

Share this post via:

herodevs.com/blog-posts/
cve-2025-1647-bootstrap-3-xss-vulnerability-via-dom-clobbering-in-tooltip-and-popover-components

Security

Apr 1, 2026

CVE-2026-22022 and CVE-2026-22444: Apache Solr Authorization Bypass and File-Access Vulnerabilities Explained

Breaking down Solr’s latest security flaws and how to protect EOL and production systems

Greg Allen

Greg Allen

Share this post via:

herodevs.com/blog-posts/
cve-2026-22022-and-cve-2026-22444-apache-solr-authorization-bypass-and-file-access-vulnerabilities-explained

Security

Mar 31, 2026

HeroDevs Now Publishes VEX Data: Fewer False Positives, Less Noise

HeroDevs Now Publishes OpenVEX Data So Your Scanning Tools Can Automatically Filter Out the Noise

Edward Ezekiel

Edward Ezekiel

Share this post via:

herodevs.com/blog-posts/
herodevs-now-publishes-vex-data-fewer-false-positives-less-noise

Products

Mar 30, 2026

Ruby on Rails End-of-Life Versions: The Dual Ruby + Rails EOL Problem Enterprises Face in 2026

Why Running EOL Ruby and Rails Together Creates Compounding Security Risk—and What to Do About It

Greg Allen

Greg Allen

Share this post via:

herodevs.com/blog-posts/
ruby-on-rails-end-of-life-versions-the-dual-ruby-rails-eol-problem-enterprises-face-in-2026