News
  • "Russia's Ukraine War Drives 62% Slump in Stolen Cards"
    Security researchers at Recorded Future stated that the Russian invasion of Ukraine in early 2022 appears to have led to a double-digit decrease in stolen payment card records published to the dark web.  The researchers analyzed detailed threat…
  • "Sigstore Announces the First Stable Release of Code and Certificate Signing Tool for Python"
    The Sigstore community recently announced the first stable release of sigstore-python, enhancing software supply chain security and breaking ground for other client implementations of Sigstore currently in the earlier stages. Sigstore is an open-source…
  • "Fortinet Observed Three Rogue PyPI Packages Spreading the Wacatac Trojan"
    Researchers from FortiGuard Labs found three malicious PyPI packages named "colorslib," "httpslib," and "libhttps" uploaded to the PyPI repository by the same malicious actor, Lolip0p. The packages, which were found on January 10, 2023, are designed to…
  • "Free Decryptors Released for BianLian, MegaCortex Ransomware"
    Avast and Bitdefender have recently released decryptors to help victims of BianLian and MegaCortex ransomware recover their data for free. BianLian, written in Golang, emerged in August 2022 and has been used in targeted attacks against entertainment,…
  • "MSI Accidentally Breaks Secure Boot for Hundreds of Motherboards"
    According to a Polish security researcher named Dawid Potocki, more than 290 MSI motherboards are impacted by insecure default UEFI Secure Boot settings, which enable any operating system image to execute regardless of whether it has a valid or…
  • "Post-quantum Cybersecurity Threats Loom Large"
    According to new research from Zapata Computing, the quantum computing market is maturing with widespread, worldwide interest and increased urgency in addressing post-quantum cybersecurity threats. Seventy-one percent of quantum-adopting companies…
  • "Java, .NET Developers Prone to More Frequent Vulnerabilities"
    According to the software-testing firm Veracode, over three-quarters of Java and .NET applications contain at least one vulnerability from the OWASP Top 10, a list of software flaws commonly used by developers as a baseline for application security. In…
  • "Hackers Can Abuse Legitimate GitHub Codespaces Feature to Deliver Malware"
    Researchers have discovered that threat actors can exploit a legitimate GitHub Codespaces feature to distribute malware to target systems. GitHub Codespaces is a cloud-based customizable development environment that allows users to debug, maintain, and…
  • "CircleCI Confirms Data Breach Was Caused By Infostealer on Employee Laptop"
    Continuous integration and delivery platform CircleCI has recently confirmed that a data breach that occurred on January 04, 2023, was caused by an infostealer being deployed on an employee's laptop.  The company noted that they learned that an…
  • "Qbot Overtakes Emotet in December 2022's Most Wanted Malware List"
    According to security researchers at Check Point, the Qbot Trojan overtook Emotet as the most prevalent malware found in the wild in December 2022, impacting 7% of organizations worldwide.  Additionally, the Glupteba malware, a blockchain-enabled…
  • "Website of Canadian Liquor Distributor LCBO Infected With Web Skimmer"
    Canadian liquor distributor Liquor Control Board of Ontario (LCBO) has recently announced that a web skimmer injected into its online store was used to steal users’ personal data.  One of the largest liquor sellers in Canada, LCBO retails and…
  • "Hack the Pentagon 3.0 Bug Bounty Program to Focus on Facility Control Systems"
    The US Department of Defense (DoD) is getting ready to launch the third installment of its "Hack the Pentagon" bug bounty program, which will focus on the Facility Related Controls System (FRCS) network.  Hack the Pentagon was first launched in 2016…