Security
Headlines
HeadlinesLatestCVEs

Source

DARKReading

Malicious Open Source Packages Spike 188% YoY

Data exfiltration was the most common malware in Sonatype report, with more than 4,400 packages designed to steal secrets, personally identifiable information, credentials, and API tokens.

DARKReading
Suspected Hacker Linked to Silk Typhoon Arrested in Milan

The alleged Chinese state-sponsored hacker faces multiple charges, including wire fraud, aggravated identity theft, and unauthorized access to protected computers.

#auth
Hackers 'Shellter' Various Stealers in Red-Team Tool to Evade Detection

Researchers have uncovered multiple campaigns spreading Lumma, Arechclient2, and Rhadamanthys malware by leveraging key features of the AV/EDR evasion framework.

4 Critical Steps in Advance of 47-Day SSL/TLS Certificates

With certificate lifespans set to shrink by 2029, IT teams need to spend the next 100 days planning in order to avoid operational disruptions.

TAG-140 Targets Indian Government Via 'ClickFix-Style' Lure

The threat actors trick victims into opening a malicious script, leading to the execution of the BroaderAspect .NET loader.

Checking for Fraud: Texas Community Bank Nips Check Fraud in the Bud

Within months of implementing anti-fraud measures and automation, Texas National Bank prevented more than $300,000 in check fraud.

Bert Blitzes Linux & Windows Systems

The new ransomware strain's aggressive multithreading and cross-platform capabilities make it a potent threat to enterprise environments.

DPRK macOS 'NimDoor' Malware Targets Web3, Crypto Platforms

Researchers observed North Korean threat actors targeting cryptocurrency and Web3 platforms on Telegram using malicious Zoom meeting requests.

Ransomware Attack Triggers Widespread Outage at Ingram Micro

The outage began shortly before the July 4 holiday weekend and caused disruptions for customer ordering and other services provided by the IT distributor.

'Hunters International' RaaS Group Closes Its Doors

The announcement comes just months after security researchers observed that the group was making the transition to rebrand to World Leaks, a data theft outfit.