The CircleCI security breach leaves most of its CI/CD platform clients with a pile of time-consuming cleanup of assorted keys, tokens and variables as they are forced to immediately rotate secrets.
GitHub has shared a DMCA filing from Twitter that indicates source code leak was apparently posted on the site shortly after Elon Musk's introductory round of layoffs began.
A location tracking cloud vulnerability was found on hundreds of smartwatch brands using Thinkrace platform which allows third parties to access the devices without any particular hacking skills.
Google appears to be limiting the web privacy powers of W3C Privacy Interest Group by being the only member to vote “No” in giving PING the ability to block new technical specification with negative implications.
The March 2020 SolarWinds hack, which was not discovered for months, has formally been blamed on Russian hackers by a coalition of US intelligence agencies.
Magecart attackers compromised at least 374 e-commerce sites running end-of-life Magento in a day, including planting 19 backdoors on a single website through SQL injection on a vulnerable plugin.
A third-party data breach has leaked personal information, including government IDs, from the messaging app Discord after threat actors breached a customer support vendor.
Phishing emails were sent to DoD vendors to capture login credentials on lookalike vendor payment website. The hackers then routed payments to shell entity.
China’s new GDPR-style data protection law does almost nothing to curb the state's unfettered access to data stored within the country, but does sharply limit the ways in which tech firms can handle and share it.
Recent survey of 2,000 international consumers suggests that companies unify and modernize identity authentication processes to avoid a mass exodus of customers.









