Data Breaches
Nissan North America told roughly 25,000 customers that their personal information was exposed in a data breach via a third-party provider.
Hi, what are you looking for?
Hackers pushed a poisoned arrayref version that added a dependency to fetch a malicious payload from a remote server.
Nissan North America told roughly 25,000 customers that their personal information was exposed in a data breach via a third-party provider.
Oracle's Critical Patch Update for January 2023 includes 327 patches, with more than 70 that address critical-severity vulnerabilities.
Fortinet warned of three malicious PyPI packages containing code that fetches the Wacatac trojan and information stealer.
A GitHub Codespaces feature meant to help with code development and collaboration can be abused for malware delivery.
Software supply chain security firm Phylum has identified a malicious attack targeting Python Package Index (PyPI) users with the PoweRAT backdoor and information stealer.
Security researchers at Microsoft are flagging ransomware attacks on Apple’s flagship macOS operating system, warning that financially motivated cybercriminals are abusing legitimate macOS functionalities...
More than a dozen new Mac malware families were discovered in 2022, including information stealers, cryptocurrency miners, loaders, and backdoors, and many of them...
Enterprise communication and collaboration platform Slack has informed customers that hackers have stolen some of its private source code repositories, but claims impact is...
Last week’s nightly builds of the open source machine learning framework PyTorch were injected with malware following a supply chain attack.Now part of the...
2022 Cybersecurity Year in Review: Top news headlines and trends that impacted the security ecosystem
Identity and access management solutions provider Okta this week informed customers that some of the company’s source code was stolen recently from its GitHub...
Companies have announced securing billions of dollars in cybersecurity-related contracts with the United States government in 2022.
Researchers discovered that the Passwordstate enterprise password manager made by Australian company Click Studios is affected by serious vulnerabilities that could allow an unauthenticated...
Security researchers with ReversingLabs warn of a new supply chain attack using a malicious PyPI module that poses as a software development kit (SDK)...
The U.S. Department of Commerce is adding 36 Chinese high-tech companies, including makers of aviation equipment, chemicals and computer chips, to an export controls...
Microsoft-owned code hosting platform GitHub this week announced multiple security improvements, including free secret scanning for public repositories and mandatory two-factor authentication (2FA) for...
Google introduces OSV-Scanner, a free vulnerability scanner for open source developers building on its open source vulnerability database.
Phylum security researchers warn of a new software supply chain attack relying on typosquatting to target Python and JavaScript developers.
Mordechai Guri, a cybersecurity researcher from the Ben-Gurion University of the Negev in Israel who specializes in air gap jumping, has released a paper...
An Iran-linked advanced persistent threat (APT) actor named Agrius is using a new wiper in attacks targeting entities in South Africa, Israel and Hong...