No menu items!
No menu items!
More

    News

    3 Victims, $5K Entry Fee, Multi-OS, and Double Extortion Tactics

    Mar 24, 2025Ravie LakshmananMalware / Ransomware A ransomware-as-a-service (RaaS) operation called VanHelsing has already claimed three victims since it launched on March 7, 2025. "The...

    How to Balance Password Security Against User Experience

    Mar 24, 2025Ravie LakshmananPassword Security / Compliance If given the choice, most users are likely to favor a seamless experience over complex security measures,...

    VSCode Marketplace Removes Two Extensions Deploying Early-Stage Ransomware

    Mar 24, 2025Ravie LakshmananMalware / Encryption Cybersecurity researchers have uncovered two malicious extensions in the Visual Studio Code (VSCode) Marketplace that are designed to...

    GitHub Supply Chain Attack, AI Malware, BYOVD Tactics, and More

    Mar 24, 2025Ravie LakshmananWeekly Recap / Hacking A quiet tweak in a popular open-source tool opened the door to a supply chain breach—what started...

    Critical Next.js Vulnerability Allows Attackers to Bypass Middleware Authorization Checks

    Mar 24, 2025Ravie LakshmananVulnerability / Web Security A critical security flaw has been disclosed in the Next.js React framework that could be potentially exploited...

    Coinbase Attack Exposes 218 Repositories, Leaks CI/CD Secrets

    The supply chain attack involving the GitHub Action "tj-actions/changed-files" started as a highly-targeted attack against one of Coinbase's open-source projects, before evolving into...

    U.S. Treasury Lifts Tornado Cash Sanctions Amid North Korea Money Laundering Probe

    Mar 22, 2025Ravie LakshmananFinancial Security / Cryptocurrency The U.S. Treasury Department has announced that it's removing sanctions against Tornado Cash, a cryptocurrency mixer service...

    UAT-5918 Targets Taiwan’s Critical Infrastructure Using Web Shells and Open-Source Tools

    Mar 21, 2025Ravie LakshmananThreat Hunting / Vulnerability Threat hunters have uncovered a new threat actor named UAT-5918 that has been attacking critical infrastructure entities...

    Medusa Ransomware Uses Malicious Driver to Disable Anti-Malware with Stolen Certificates

    Mar 21, 2025Ravie LakshmananRansomware / BYOVD The threat actors behind the Medusa ransomware-as-a-service (RaaS) operation have been observed using a malicious driver dubbed ABYSSWORKER...

    Latest articles

    spot_imgspot_img