A new Trojan written in the Go programming language has pivoted from attacks against government agencies to US schools. The …
Codecov to retire the Bash script responsible for supply chain attack wave
Codecov has introduced a new uploader that relies on NodeJS to replace and remove a Bash script responsible for a …
SEC settles with First American over massive leak of mortgage data, disclosure
The Securities and Exchange Commission (SEC) has agreed to a settlement with First American over the leak of millions of …
Facebook awards $30,000 bounty for exploit exposing private Instagram content
Facebook has awarded $30,000 to a researcher for reporting vulnerabilities in Instagram’s privacy features. According to a Medium blog post …
This strange malware stops you from visiting pirate websites
A strain of malware with odd intentions when it comes to piracy and the moral compass of its victims has …
Over a billion records belonging to CVS Health exposed online
In another example of misconfigured cloud services impacting security, over a billion records belonging to CVS Health have been exposed …
Critical remote code execution flaw in thousands of VMWare vCenter servers remains unpatched
Researchers have warned that thousands of internet-facing VMWare vCenter servers still harbor critical vulnerabilities weeks after patches were released. The …
Volkswagen, Audi disclose data breach impacting over 3.3 million customers, interested buyers
Volkswagen has revealed a data breach impacting over 3.3 million customers. The majority of impacted individuals are either current or …
PuzzleMaker attacks exploit Windows zero-day, Chrome vulnerabilities
Researchers say zero-day vulnerabilities fixed in Microsoft’s recent Patch Tuesday round have been used in targeted attacks against the enterprise. …
Feds strike Slilpp, a marketplace for flogging initial access credentials
Law enforcement has seized one of the largest marketplaces for selling stolen account credentials. The website’s infrastructure has been taken …