Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
AI coding tools can introduce unvetted or hallucinated open source dependencies faster than traditional security reviews can keep pace. ActiveState explains why organizations should govern packages at the point of selection, before they enter the development pipeline.
AmnesiaStealer is a Rust-based macOS information stealer distributed via fake GitHub download pages using ClickFix social engineering tactics. The malware operates in three stages: a shell script dropper, a credential and data harvesting payload that targets Keychain, browsers, Apple Notes, and Telegram, and a remote browser control module that gives attackers live, interactive access to victim's authenticated sessions via Chrome DevTools Protocol.
Discord's Go Live feature contributed to a 13-year-old girl's death by suicide, according to Brazilian regulators, who told the company to suspend the streaming technology.
Attackers target Kibana, the visualization interface for Elasticsearch, on port 5601, exploiting its API surface, plugin architecture, and history of critical vulnerabilities. This follows previous parts focusing on Elasticsearch attacks.
A new White House memo signed by President Trump instructs the National Coordination Center to establish a program allowing private security companies to apply for approval to hack foreign cybercrime organizations.
The Trump administration will allow private companies to launch attacks on cybercrime organizations, the White House announced.