A massive supply chain attack dubbed Megalodon has infected over 5,500 GitHub repositories with credential-stealing malware, creating backdoors and automated workflows.
Despite receiving a raucous round of applause upon its adoption, the UN cybercrime convention's new treaty seems to thus far have displeased most of the entire spectrum of private interests.
The NSA urged developers and organizations to switch to memory-safe languages to address memory safety issues responsible for most exploitable vulnerabilities. Microsoft and Google attribute 70% of some of their product vulnerabilities to software memory safety issues.
NATO is investigating an alleged data theft by a hacktivist group SiegedSec. 845 MB of compressed data was leaked and found to contain unclassified information and 8,000 employee records from 31 nations.
Nation-state hackers with suspected links to Russia were behind the security breach at FireEye. The attackers stole Red Team tools and searched for government customer information.
The FBI says hackers who scraped credit card data by injecting malicious PHP code on an online checkout page were targeting U.S. businesses since September 2020.
The embassy phishing campaign is just one element of a rash of recent activity by the Russian hackers referred to as APT 29, probably better known to the general public as Cozy Bear.
A ransomware gang that recently hit major UK retailers such as Marks & Spencer with cyber attacks is now setting its sights on US companies, according to a warning from Google's security team.
A data breach stemming from a third-party customer service database has affected European airlines Air France and KLM Royal Dutch Airlines.
Security automation is increasingly becoming a necessity in order to keep up with the cyber threats, but security analysts report significant increased stress on the job driven by fear of missing alerts.










