-
A pervasive CI/CD vulnerability pattern dubbed “Cordyceps” reveals a supply chain vulnerability that lets unauthenticated attackers seize control of Git-based workflows and, by extension, the software artifacts they produce. The issue is not a single b…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A security incident involving the third-party platform Klue has resulted in unauthorized access to limited customer data in LastPass. The breach occurred after attackers compromised OAuth tokens associated with enterprise integrations. This incident, d…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The Five Eyes cyber security agencies have issued a joint warning that artificial intelligence is rapidly accelerating cyber threats, including the exploitation of zero day vulnerabilities, and urged organizations to act immediately. In a statement rel…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A sophisticated campaign by the actor tracked as “Dropping Elephant” that uses a China-themed decoy document and a heavily reworked, in-memory remote access trojan (RAT). The intrusion chain combines classic living-off-the-land techniques with modern i…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A series of critical vulnerabilities in the widely used open-source LLMOps platform Dify, which powers over one million AI applications. These vulnerabilities, collectively referred to as “DifyTap,” include four flaws, two rated as critical and two tha…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A large-scale analysis of smart TV applications has revealed that thousands of apps available on LG webOS and Samsung Tizen platforms are covertly transforming consumer devices into residential proxy nodes, raising significant security and privacy conc…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
ANY.RUN today launched in-browser data inspection for its Interactive Sandbox, a capability that brings real browser-level visibility directly into URL analysis workflows and addresses longstanding blind spots in phishing investigations. Modern URL phi…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
When securing an Amazon Web Services (AWS) estate, teams naturally concentrate on inbound protections firewalls, WAFs, and IAM policies because those defenses stop the most visible attacks. Yet outbound traffic often remains under-monitored, left permi…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Tata Electronics has reported a cybersecurity incident following claims from a ransomware-linked threat group that it has exfiltrated and published over 200,000 files related to Apple and Tesla’s manufacturing operations. The leaked data, which i…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Microsoft’s latest incident write-up shows that a single intrusion can mask two parallel threat activity streams, one tied to Storm-2603 and another to an unknown actor, making the attack far more complex than a conventional ransomware case. The incide…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


