09 Sep

More packages poisoned in npm attack, but would-be crypto thieves left pocket change

During the two-hour window on Monday in which hijacked npm versions were available for download, malware-laced packages reached one in 10 cloud environments, according to

Author rabih
09 Sep

New cybersecurity rules land for Defense Department contractors

It’s about to get a lot harder for private companies that are lax on cybersecurity to get a contract with the Pentagon, as the Defense

Author rabih
09 Sep

Defense Dept didn’t protect social media accounts, left stream keys out in public

The US Department of Defense, up until this week, routinely left its social media accounts wide open to hijackers via stream keys – unique, confidential

Author rabih
09 Sep

No gains, just pains as 1.6M fitness phone call recordings exposed online

Exclusive Sensitive info from hundreds of thousands of gym customers and staff – including names, financial details, and potentially biometric data in the form of

Author rabih
09 Sep

What the Plex? Streaming service suffers yet another password spill

Streaming platform Plex is warning some users to reset their passwords after suffering yet another breach. The popular media server provider, which people definitely use

Author rabih
09 Sep

Nokia successor HMD spawns secure device biz with Euro-made smartphone

Finnish phone maker HMD Global is launching a business unit called HMD Secure to target governments and other security-critical customers, and has its first device

Author rabih
09 Sep

Anthropic’s Claude Code runs code to test if it is safe – which might be a big mistake

App security outfit Checkmarx says automated reviews in Anthropic’s Claude Code can catch some bugs but miss others – and sometimes create new risks by

Author rabih
09 Sep

Preventing business disruption and building cyber-resilience with MDR

Business Security Given the serious financial and reputational risks of incidents that grind business to a halt, organizations need to prioritize a prevention-first cybersecurity strategy

Author rabih
09 Sep

UK toughens Online Safety Act with ban on self-harm content

Tech companies will be legally required to prevent content involving self-harm from appearing on their platforms – rather than responding and removing it – in

Author rabih
09 Sep

Forget disappearing messages – now Signal will store 100MB of them for you for free

Encrypted messaging app Signal is rolling out a free storage system for its users, with extra space if folks are willing to pay for it.

Author rabih
08 Sep

WhatsApp’s former security boss claims reporting infosec failings led to ousting

WhatsApp’s former head of security, Attaullah Baig, has filed a lawsuit against its parent company, Meta, alleging that the social media megalith retaliated against him

Author rabih
08 Sep

The US government has no idea how many cybersecurity pros it employs

The US federal government employs tens of thousands of cybersecurity professionals at a cost of billions per year – or at least it thinks it

Author rabih
08 Sep

Drift massive attack traced back to loose Salesloft GitHub account

The Salesloft Drift breach that compromised “hundreds” of companies including Google, Palo Alto Networks, and Cloudflare, all started with miscreants gaining access to the Salesloft

Author rabih
08 Sep

How huge breach started: Drift attackers gained entry via a Salesloft GitHub account

The Salesloft Drift breach that compromised “hundreds” of companies including Google, Palo Alto Networks, and Cloudflare, all started with miscreants gaining access to the Salesloft

Author rabih
08 Sep

Dev snared in crypto phishing net, 18 npm packages compromised

Crims have added backdoors to at least 18 npm packages after developer Josh Junon inadvertently authorized a reset of the two-factor authentication protecting his npm

Author rabih
08 Sep

Salt Typhoon used dozens of domains, going back five years. Did you visit one?

Security researchers have uncovered dozens of domains used by Chinese espionage crew Salt Typhoon to gain stealthy, long-term access to victim organizations going back as

Author rabih
08 Sep

PACER buckles under MFA rollout as courts warn of support delays

US courts have warned of delays as PACER, the system for accessing court documents, struggles to support users enrolling in its mandatory MFA program. Several

Author rabih
08 Sep

CISA sounds alarm over TP-Link wireless routers under attack

Infosec in brief The US Cybersecurity and Infrastructure Security Agency (CISA) has said two flaws in routers made by Chinese networking biz TP-Link are under

Author rabih
Load moreLoadingAll items loaded