GitHub and PyPI Add Time-Based Defenses Against Supply Chain Attacks
GitHub has added a 72-hour Dependabot cooldown, while PyPI now blocks new files added to releases older than 14 days.
ThreatsGitHub has added a 72-hour Dependabot cooldown, while PyPI now blocks new files added to releases older than 14 days.
ThreatsCTM360 research exposes a phishing kit targeting insurance portals with real-time OTP interception and live session hijacking across multiple regions.
ThreatsCheck Point has patched three vulnerabilities, including a critical actively exploited authentication bypass in SmartConsole. CISA has added the flaw to its KEV
ToolsGoogle has introduced an opt-in selfie video feature for account recovery. It uses facial comparison to verify identity when users are locked out.
ToolsA viral incident exposes how Flock's camera network wrongly tracked a writer using partial plate matching, while police use the system to surveil people, not ju
ThreatsExpel attributes the April 2026 DigiCert certificate theft to CylindricalCanine, a subgroup of Chinese cybercrime group GoldenEyeDog using Golden Gh0st RAT.
VPN & Privacy
ESET found 11 old UEFI shims that bypass Secure Boot on most UEFI systems. Microsoft revoked the vulnerable binaries in the June 2026 Patch Tuesday update.
Microsoft fixed 570 vulnerabilities in July's Patch Tuesday, nearly triple last month's record. AI-assisted discovery is driving the surge in patch volume.
OpenAI is temporarily lifting GPT-5.6 Sol's five-hour usage cap for Plus, Pro, and Business plans and issuing a one-time usage reset.
Attackers compromised the Injective Labs GitHub repository to publish a malicious npm package that exfiltrates private keys and mnemonic phrases.
AI is rapidly widening the gap between skill and ability in cyberattacks. The same tools that strengthen defense also enable harm.
North Korea's Contagious Interview campaign has published 108 malicious packages across npm, Packagist, Go, and Chrome in an active supply chain operation calle
Security firm runZero disclosed seven vulnerabilities in FatFs, a filesystem library embedded in cameras, drones, and industrial controllers. No upstream fix ex
CISA has added a high-severity Microsoft SharePoint RCE flaw to its KEV catalog. Federal agencies must patch by Saturday under BOD 26-04.
AI enables natural language queries on video footage, allowing intelligence officers to search for behaviors rather than objects—creating vast new surveillance