Security researchers have found over 35,000 code repositories with malicious forks or clones leading back to a single source. Malware in the tainted code repositories is designed to steal environment variables, stored elements that serve as authentication for various online services.
The U.S. state of Georgia’s election website experienced a “probing” cyber attack from a suspected nation-state threat actor, delaying absentee ballot requests.
According to new research, brand-new Android smartphones comes with pre-installed apps which are used for data harvesting, tracking and monitoring, all without the knowledge of the user.
The US Cyber Safety Review Board (CSRB) has published a comprehensive analysis of the Lapsus$ hacker group’s cyber extortion activities. The report highlighted simple but effective tactics the Lapsus$ hackers used to compromise organizations and the existing security gaps enabling them.
Home security company ADT has confirmed a data breach stemming from unauthorized access to a customer database after a threat actor listed the stolen database on an online hacking forum.
The FBI and its European partner law enforcement agencies have dismantled the cybercrime infrastructure of the Radar/Dispossessor ransomware group, a LockBit knockoff.
Under the new treaty between U.S. and UK, social media companies could be forced to open encryption backdoor for law enforcement officials to read the messages from criminals, terrorists and pedophiles.
About 26 Million Fortune 1000 Employee Credentials Available on the Dark Web, Password Reuse Rampant
SpyCloud found about 26 million Fortune 1000 employee credentials circulating on the dark web. Password reuse, weak passwords, and infostealers were responsible for the leaks.
Microsoft has traced the signing key theft back to a "crash dump" error. A breach of a Microsoft engineer's work account by the Chinese hackers then yielded access to the crash dump and the embedded signing key.
British telecommunications service provider Colt Telecom has attributed the multi-day service disruption to a cyber attack claimed by the prolific WarLock ransomware group.










