GitHub and PyPI Add Time-Based Defenses Against Supply Chain Attacks
GitHub has added a 72-hour Dependabot cooldown, while PyPI now blocks new files added to releases older than 14 days.
GitHub has added a 72-hour Dependabot cooldown, while PyPI now blocks new files added to releases older than 14 days.
CTM360 research exposes a phishing kit targeting insurance portals with real-time OTP interception and live session hijacking across multiple regions.
A viral incident exposes how Flock's camera network wrongly tracked a writer using partial plate matching, while police use the system to surveil people, not ju
North Korea's Contagious Interview campaign has published 108 malicious packages across npm, Packagist, Go, and Chrome in an active supply chain operation calle
A German court ruled Google liable for AI search summaries, reigniting the carrier-vs-publisher debate and raising urgent questions about corporate accountabili
Tata Electronics confirmed a cyberattack on parts of its IT infrastructure. The World Leaks group leaked alleged Apple manufacturing data stolen in the incident
Normalcy bias leads organisations to mistake silence for safety. Cybercriminals exploit that gap between perceived and actual security posture.
Chinese APT group UNC5221 used Brickstorm, Plenet, and AgentPSD to maintain access across a victim network and its MSP for over 18 months.
Free apps embed Bright Data's SDK to route web-scraping traffic through home IPs, including always-on smart TVs, with consent screens that don't match actual da
CISA added CVE-2026-28318, a DoS flaw in SolarWinds Serv-U, to its KEV catalog with a federal patch deadline of June 19, 2026.
An AI agent found 21 FFmpeg zero-days for ~$1,000. That same week, Chrome 149 patched a record 429 bugs.
Over 900 ATG systems in the US sit exposed on the open internet, vulnerable to command execution attacks that could disable fuel leak detection.