Microsoft shuts down illegal code-signing operation used by ransomware crims to mask their malware 'Thousands' of US victims, including 12+ machines owned and operated by Redmond
America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames I wonder what's in 'external-secret-repo-creds.yaml' and 'AWS-Workspace-Firefox-Passwords.csv'?
Clear your calendar, Drupal user: You have a critically urgent patch to install The org’s staying mum on the details, but Wednesday’s fixes reach back to unsupported 8.9 branches
Shai-Hulud keeps burrowing: 314 npm packages infected after another account compromise Popular JavaScript modules including size-sensor and echarts-for-react hit as hijacked account closed GitHub warnings
Crook leaks 468k+ records, claims they pwned Portugal’s postal carrier Ordered packages via CTT? Those phishing emails could be tricky to spot
Do fear the Reaper - stealer swipes macOS users' passwords, wallets, then backdoors them While also spoofing all the trusted domains - Apple, Microsoft, and Google - in the same attack
Shai-Hulud copycat worm infects yet another npm package Plus three other stealers in three other packages, all from the same scumbag
Linux kernel flaw opens root-only files to unprivileged users Plus ModuleJail, a radical proposal for minimizing the impact of similar bugs
Dutch cops’ shame game works wonders as most wanted scammers now turned in Game Over?! gamified the identification of scammers who sought thrills from terrorising the elderly
TanStack weighs invitation-only pull requests after supply chain attack Shai-Hulud worm exploited GitHub Actions misconfiguration to poison shared cache, now project weighing nuclear option on unsolicited contributions
NGINX Rift attackers waste no time targeting exposed servers Researchers say 18-year-old flaw already being probed and exploited just days after disclosure
Poland directs officials to ditch Signal in favor of 'secure' state-developed alternative Shift comes amid mounting reports of successful social engineering attacks targeting higher-ups in government
F-35 software delays leave UK buying time with US glide bombs MoD says StormBreaker will plug gap until homegrown SPEAR 3 integration lands
Mozilla warns UK: Breaking VPNs will not magically fix Britain's age-check mess Firefox maker says the tools are basic security infrastructure, not teenage contraband
Grafana Labs admits all its codebase are belong to someone who popped its GitHub account No customer info stolen, no impact to operations, and no blackmail payment
Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable’ Multiple researchers using the same tools to find the same bugs are creating ‘unnecessary pain and pointless work’
Patch time for Cisco SD-WAN admins as vendor drops yet another make-me-admin zero-day CISA hands feds super-tight deadline for this perfect-10, actively exploited flaw
OpenAI caught in TanStack npm supply chain chaos after employee devices compromised Attackers stole a limited amount of internal credential material after malware hidden in poisoned packages reached two staff machines
MPs want social media treated more like unsafe toys than harmless apps Parliamentary committee tells ministers online safety regime is failing children and warns 'no action is not an option'
Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data Other than Instructure execs - maybe?
Cops arrest man suspected of being Dream Market kingpin Owe Martin Andresen faces charges in both US and Germany connected with money laundering, claims he sent gold bars directly to his doorstep
Dirty Frag gets a sequel as Fragnesia hands Linux attackers root-level access Fresh kernel flaw comes with public exploit code and continues ugly run of highly reliable privilege escalation bugs tied to memory and page-cache handling
To gain root access at this company, all an intruder had to do was ask nicely Human IT managers thought they were being nice to the boss, but were assisting a threat actor
AI models are getting better at replacing cybersecurity pros on certain tasks UK researchers find LLMs are learning to finish jobs faster and improving all the time
Cisco to fire 4,000 staff and generously give them free training – on Cisco Reducing memory requirements to control costs in a new wave of kit
Welcome to the vulnpocalypse, as vendors use AI to find bugs and patches multiply like rabbits Palo Alto Networks found and fixed 75 flaws this month, up from its usual five
AWS to Quick admins: The access control didn't work, but you weren't using it anyway, so what's the problem? If a setting fails in the forest and nobody hears it ...
Bug hunter tracks down three massive MCP flaws and one vendor won't fix theirs Apache, Alibaba databases vulnerable and only one has a patch
Mystery Microsoft bug leaker keeps the zero-days coming Security pros warn YellowKey claim could make stolen laptops a much bigger problem
Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub Where it’s been well and truly forked, seemingly without Microsoft’s code locker noticing
Vietnam to develop domestic cloud so it can ditch risky overseas operators for government workloads Communist government plans personalized ‘data-driven decision-making based on real-time information’ by 2035
Doozy of a Patch Tuesday includes 30 critical Microsoft CVEs The good news: no 0-days. The bad news: busy week ahead for Microsoft admins
Foxconn confirms cyberattack after ransomware crew claims it stole confidential Apple, Nvidia files Affected factories back up and running, we're told
Congress investigates Canvas breach as company pays ransom Instructure CEO Steve Daly's got some explaining to do
AirBit crypto Ponzi victims can now claim slice of $400M asset haul After guilty pleas, prison terms, and seizures, the DOJ has opened the compensation process
US bank reports itself after slinging customer data at 'unauthorized AI app' Volume and sensitivity of the data cited as chief concerns
Cache-poisoning caper turns TanStack npm packages toxic Six-minute supply chain blitz pushed 84 malicious versions with credential theft and disk-wiping code
Apple, Google drag cross-platform texting into the encrypted age After years of stopping dead at the green bubble border, iPhone and Android users can finally send E2EE messages without relying on third-party apps
FleetWave outage takes another turn. Chevin confirms crooks accessed customer data A month after bringing systems back online, SaaS vendor tells customers attackers potentially walked off with operational data, contact details, and payroll numbers
Japan’s PM orders cybersecurity review to stop Mythos going full CyberZilla Fears exponential increase in attack scale and speed
Double Canvas breach acknowledged as ShinyHunters sets new pay-or-leak deadline UPDATED: Sorry, kids, everything's back up so get to work on your new assignment - An essay on the ethics of paying ransoms, because it looks like that's what happened here
Cookie thieves caught stealing dev secrets via fake Claude Code installers New IElevator2 COM interface? No problem
Anthropic’s bug-hunting Mythos was greatest marketing stunt ever, says cURL creator After all that hype, AI scanner found one low-severity cURL flaw
BWH Hotels guests warned after reservation data checks out with cybercrooks Customers urged to keep an eye out for phisherfolk
Google says criminals used AI-built zero-day in planned mass hack spree GTIG says AI-powered hacking has moved well beyond phishing emails and chatbot tricks
Water company's leaky security earns near-£1M fine Utility provider failed to detect Cl0p ransomware attack for nearly two years
Checkmarx tackles another TeamPCP intrusion as Jenkins plugin sabotaged Cybercrooks ruin engineers' weekends with Saturday attack
Worm rubs out competitor's malware, then takes control All your compromised credentials are belong to us now instead of the other gang
Disgraced US gov software contractor found guilty of database destruction Twin brother still faces trial over broader cybercrime allegations
'Dirty Frag' Linux flaw one-ups CopyFail with no patches and public root exploit Broken disclosure embargo left admins facing a fresh root-level flaw with no CVE
Meta U-turns on encryption push for Instagram as DMs go plaintext After years of insisting end-to-end encryption was the future of online comms, Zuckcorp has handed itself full visibility into user chats once again
Hackers ate my homework: Educational SaaS Canvas down after cyberattack ShinyHunters takes the credit and gives developer an F for security
Meta fights Ofcom over how many billions count as billions Social media biz says watchdog's fine formula is 'disproportionate' and should stop counting global revenue
Mozilla boasts Mythos boosted Firefox bug cull Yet it remains unclear if Anthropic's uber model was effective, or if better model middleware is what makes the difference
Fake IT workers rented laptops to Nork scammers, got prison time Matthew Isaac Knoot and Erick Ntekereze Prince will each do 18 months for hosting laptops used by North Korean IT workers to remotely infiltrate US companies
Anthropic response to 1-click pwn: Shouldn't have clicked 'ok' Security biz Adversa AI argues users of AI tools need clearer warnings
60% of MD5 password hashes are crackable in under an hour Happy World Password Day! Maybe it's finally time to kill this holiday in favor of World No-More-Passwords Day?
$250M crypto-robbing gang’s dirty work guy sentenced to 6.5 years behind bars The then-teen was told to break in and steal what the keyboard warriors couldn’t
State-backed hackers hammer Palo Alto firewall zero-day before patch lands Internet-facing PAN-OS firewalls are once again doing impressions of initial access brokers
Hungarian cops cuff suspected swatter after two-year FBI probe 20-year-old fessed up after investigators found video of crime in progress
The network password was a key plot point in one of the most famous movies of all time Fortunately, it was a legit contractor who guessed it
Arctic Wolf kicks 250 employees out of the pack to save money for AI Cuts appear to hit sales, product, and marketing, accounting for under 10% of staff
1 in 8 employees totally cool with selling work credentials 13% say they’ve sold logins or know someone who has, survey suggests
Iran cybersnoops still LARPing as ransomware crooks in espionage ops MOIS-linked cyber outfit puts on a ransomware show to disguise the wide-open backdoor behind the scenes
UK age-gating plans risk breaking the internet, privacy groups warn Activists say ministers are targeting access rather than Big Tech's data-hungry business models
Taiwan cops say student's radio kit brought bullet trains to a standstill Investigators spent weeks unravelling enthusiast's bedroom project
India orders infosec red alert in case Mythos sparks crime spree Securities regulator urges market players to develop new strategies and nail cyber-basics before AI models fuel mass attacks
ServiceNow clears agents for landing with new AI control tower ServiceNow acquisitions Veza and Traceloop join to monitor agents and AI workflows
Attackers are cashing in on fresh 'CopyFail' Linux flaw Researchers dropped a reliable root exploit and it didn’t sit idle for long
Real estate giant confirms vishing incident as ShinyHunters and Qilin both come knocking Cushman & Wakefield activated incident response protocols after serial extortionists issued separate threats