A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the…
Tag: EN
GitHub Expands Supply Chain Malware Detection From npm to 8 Package Registries
GitHub has expanded its malware detection capabilities beyond npm, providing developers with broader protection against malicious open-source packages.…
CISA Warns of Progress LoadMaster Command Injection Vulnerability Exploited in Attacks
CISA has added a critical Progress LoadMaster vulnerability to its Known Exploited Vulnerabilities catalog after attackers were observed targeting exposed…
Windows WalletService Vulnerability Allows Attackers to Escalate Privileges – PoC Released
Microsoft has patched a Windows WalletService vulnerability that could let local attackers gain SYSTEM privileges, with a public proof of concept urging…
Scans for Solana (Surfpool?) Endpoints, (Mon, Aug 10th)
Solana is a crypto platform known for speed. Developers like it to develop distributed applications or to implement crypto payments. To interact with the…
Red Hat ACM Privilege Escalation Vulnerability Lets Attackers Gain Full Cluster-Admin Access
Red Hat has disclosed a critical privilege escalation flaw, tracked as CVE-2026-10090, affecting the Application Subscription controller in Red Hat…
Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant
Atlassian fixed a flaw letting one crafted link make its Rovo AI assistant exfiltrate company data
Civil-society initiative will pay cybersecurity vendors to protect rural water systems
The group is seeking philanthropic grants, but its founder said the federal government ultimately needs to step in.
New turnkey kit makes it easy for anyone to become a scammer
We discovered a kit that gave us an insight into how modern online scams are built, promoted, and potentially used to target everyday consumers.
China’s New Challenge: Fake AI Videos During Natural Disasters
As China grapples with intensified storms and flooding over recent months, authorities face an unexpected secondary crisis: a surge of AI-generated fake…
Syrian migrant smugglers arrested in coordinated strike in Germany and Serbia
This follows several years of intensive and extensive investigations led by the German Federal Police under the direction of three Bavarian Public…
Bank of Baroda Data Breach: What We Know About the Alleged 1TB Dark Web Leak
Bank of Baroda has confirmed a cybersecurity incident involving a compromised employee email account after reports emerged that nearly 1TB of data…
Levi Strauss Breach Began With Social Engineering of 3 Employees
Levi Strauss says hackers socially engineered three employees and stole corporate data, highlighting the growing threat of identity-based attacks.
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized…
Fake The Odyssey Downloads Are Hiding Password-Stealing Malware
Fake downloads of The Odyssey are spreading Lumma Stealer malware capable of stealing passwords, cookies, payment data, and cryptocurrency information.
A Practical Pipeline for Identifying Sensitive Columns Before Test Data Masking
I work as a data analyst at a legal services company. Part of my work involves protecting sensitive data during the Test Data Management (TDM) process.…
Claude-Powered Agent Exploits Australian Gym API, Removes Waitlisted Member
A Claude-powered AI agent exploited an Australian gym API flaw, removed a member from a waitlist, and exposed new risks from autonomous agents.
77 Counterfeit Open VSX Extensions Collected Developer and CI/CD Data
Security researchers found 150 lookalike Open VSX extensions published under trusted names, highlighting how extension marketplaces can expose developer…
OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns
The current GPT-5.6-Sol has been assigned a ‘high’ cybersecurity threshold, but Astra could reach the maximum ‘critical’ threshold.
WordPress Plugins Compromised Without a Single File Change
Poisoned JSON feed let attackers backdoor WordPress sites without changing any plugin files
