America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames
I wonder what's in 'external-secret-repo-creds.yaml' and 'AWS-Workspace-Firefox-Passwords.csv'? [...]
I wonder what's in 'external-secret-repo-creds.yaml' and 'AWS-Workspace-Firefox-Passwords.csv'? [...]
The org’s staying mum on the details, but Wednesday’s fixes reach back to unsupported 8.9 branches [...]
While also spoofing all the trusted domains - Apple, Microsoft, and Google - in the same attack [...]
Plus three other stealers in three other packages, all from the same scumbag [...]
Plus ModuleJail, a radical proposal for minimizing the impact of similar bugs [...]
Shai-Hulud worm exploited GitHub Actions misconfiguration to poison shared cache, now project weighing nuclear option on unsolicited contributions [...]
Researchers say 18-year-old flaw already being probed and exploited just days after disclosure [...]
Shift comes amid mounting reports of successful social engineering attacks targeting higher-ups in government [...]
MoD says StormBreaker will plug gap until homegrown SPEAR 3 integration lands [...]
Firefox maker says the tools are basic security infrastructure, not teenage contraband [...]
No customer info stolen, no impact to operations, and no blackmail payment [...]
Multiple researchers using the same tools to find the same bugs are creating ‘unnecessary pain and pointless work’ [...]
Attackers stole a limited amount of internal credential material after malware hidden in poisoned packages reached two staff machines [...]
Parliamentary committee tells ministers online safety regime is failing children and warns 'no action is not an option' [...]
Other than Instructure execs - maybe? [...]
Owe Martin Andresen faces charges in both US and Germany connected with money laundering, claims he sent gold bars directly to his doorstep [...]
Fresh kernel flaw comes with public exploit code and continues ugly run of highly reliable privilege escalation bugs tied to memory and page-cache handling [...]
Human IT managers thought they were being nice to the boss, but were assisting a threat actor [...]
UK researchers find LLMs are learning to finish jobs faster and improving all the time [...]
Reducing memory requirements to control costs in a new wave of kit [...]
Palo Alto Networks found and fixed 75 flaws this month, up from its usual five [...]
If a setting fails in the forest and nobody hears it... [...]
Apache, Alibaba databases vulnerable and only one has a patch [...]
Security pros warn YellowKey claim could make stolen laptops a much bigger problem [...]
Where it’s been well and truly forked, seemingly without Microsoft’s code locker noticing [...]