Tag: security

GitHub is finally tightening up security around npm following multiple attacks

GitHub will enforce 2FA and deprecate legacy tokens to improve package publishing security Trusted Publishing will expand, and token-based publishing will be restricted by default Shai-Hulud worm breached npm, prompting removal of over 500 compromised packages Following a number of recent high-profile attacks and hacking attempts, GitHub has decided to…

Read More

“It could be catastrophic to the city” – US Secret Service takes down massive million-dollar network of SIM cards it says was capable of taking down comms across New York

A massive communications network was uncovered in New York The network is made of 300 servers containing 100,000 SIM cards Only part of the network was deployed, with more equipment discovered ready to be added to the network The US Secret Service has uncovered and dismantled a telecommunications network in…

Read More

Unhackable backup storage could have helped in the M&S hack case by keeping data physically offline – but it comes at a cost

Recent Marks & Spencer attack reveals flaws in current enterprise backup strategies HyperBUNKER pushes offline storage while critics question cost and practicality Data diodes create one-way channels, keeping vaults disconnected from networks Major UK retailer Marks & Spencer (M&S) was recently hit by a ransomware attack WHICH disrupted internal systems…

Read More

Huge theft reportedly sees 2TB of private data stolen – police files hit in major breach

Maida.health allegedly leaks 2.3TB of Brazilian military police medical and personal data Cybercriminals advertised stolen records including diagnostics, ID cards, and healthcare contracts online Healthcare remains a top target due to sensitive data and risk of identity theft or fraud Maida.health, a Brazilian health technology company, allegedly suffered a data…

Read More

Car giant Stellantis confirms data breach after third-party hit by cyberattack

Stellantis confirms data breach via third-party platform supporting North American customer services Attack linked to ShinyHunters, part of broader Salesforce-related data theft campaign Customers warned to avoid suspicious emails and remain alert for phishing attempts Stellantis, one of the world’s largest automakers, confirmed suffering a cyberattack and losing sensitive customer…

Read More

Hackers can now inject AI deepfakes directly into iOS video calls using this tool – here’s how to stay safe

Deepfake injection attacks bypass cameras and deceive video verification software directly Face swaps and motion re-enactments transform stolen images into convincing deepfakes Managed detection services can identify suspicious patterns before attacks succeed Digital communication platforms are increasingly vulnerable to sophisticated attacks that exploit advanced artificial intelligence. A report from iProov…

Read More