Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
This week's Threat Source newsletter introduces Mick as the new editor, a globally recognized security strategist with a career spanning offensive operations, threat intelligence, and incident response. The newsletter covers recent cybersecurity developments and provides insights from Talos Intelligence researchers.
Hackers compromised the maintainer account behind the widely used Rust crate arrayref to introduce malware that executed on developers' systems during compilation. The malicious releases were published to crates.io and executed info-stealing payloads during the build process.
A vulnerability in N-able's Passportal password manager, popular among MSPs and SMBs, exposed password vault master keys even after a patch was issued. The cloud-based design of the product introduces risks that make it challenging to fully secure.
Senators Marsha Blackburn and Richard Blumenthal criticized TikTok for knowingly withholding a critical safety measure for millions of American users. The letter pressed TikTok on why certain safety features were not made available to all users.
Law enforcement training is not keeping pace with the volume and rapid evolution of cybercrimes. Officers primarily need to learn the basics of cyber investigation, but insufficient focus and budgets hinder progress.
This week's ThreatsDay bulletin covers multiple critical security issues including a Gogs 10.0 RCE vulnerability, n8n workflow-to-RCE attacks, and signed driver abuse by threat actors. Legitimate applications are being weaponized to help malware blend in with trusted software.