TeamPCP's Open-Source Software Attacks
TeamPCP has compromised over 1,000 software packages in less than four months, highlighting the vulnerabilities of the open-source trust model.
The traditional model of finding and patching vulnerabilities is no longer effective, prompting a shift towards risk-based disclosure and prioritization.
TeamPCP has compromised over 1,000 software packages in less than four months, highlighting the vulnerabilities of the open-source trust model.
F5 has released out-of-band security updates to address multiple NGINX web server vulnerabilities, including two critical-severity flaws that could allow attackers to execute code on vulnerable systems.
The Popa botnet, a massive Android-based botnet, has been linked to NetNut, a residential proxy provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd.
India's government blocked Telegram ahead of a national medical exam due to the platform's inability to proactively detect channels selling leaked exam papers.
Klue suffered an OAuth breach, enabling the Icarus threat actors to steal Salesforce CRM data from multiple organizations in an ongoing extortion campaign.
India's ban on Telegram has affected users in the UAE due to BGP hijacking, with the platform's CEO accusing Indian telecom Reliance of sabotage.
A new policy paper advocates for software bills of materials for artificial intelligence to reduce cyber risk and improve transparency.
The Trump administration's decision to impose export controls on Anthropic's AI models has been met with skepticism by lawmakers, who question the national security concerns cited as the reason.
The European Union has granted Ukraine access to its cybersecurity reserve, enabling Kyiv to request emergency assistance from EU-approved experts during major cyberattacks.