Latest Cybersecurity News and Articles


GitHub Desktop Vulnerability Risks Credential Leaks via Malicious Remote URLs

27 January 2025
Multiple security vulnerabilities have been disclosed in GitHub Desktop as well as other Git-related projects that, if successfully exploited, could permit an attacker to gain unauthorized access to a user's Git credentials. "Git implements a protocol called Git Credential Protocol to retrieve credentials from the credential helper," GMO Flatt Security researcher Ry0taK, who discovered the flaws

Building Automation Protocols Increasingly Targeted in OT Attacks: Report

27 January 2025
Industrial automation protocols continue to be the most targeted in OT attacks, but building automation systems have been increasingly targeted.  The post Building Automation Protocols Increasingly Targeted in OT Attacks: Report appeared first on SecurityWeek.

Trump administration dismisses Cyber Safety Review Board (CSRB)

27 January 2025
The Department of Homeland Security has dismissed its advisory committees, including the Cyber Safety Review Board (CSRB).

Phishing rose 30.5% year-over-year in APAC region

27 January 2025
According to a recent report, between 2023 and 2024, the median monthly rate of advanced email attacks in the APAC region surged by 26.9%.

Git Vulnerabilities Led to Credentials Exposure

27 January 2025
Vulnerabilities in Git’s credential retrieval protocol could have allowed attackers to compromise user credentials. The post Git Vulnerabilities Led to Credentials Exposure appeared first on SecurityWeek.

⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [27 January]

27 January 2025
Welcome to your weekly cybersecurity scoop! Ever thought about how the same AI meant to protect our hospitals could also compromise them? This week, we’re breaking down the sophisticated world of AI-driven threats, key updates in regulations, and some urgent vulnerabilities in healthcare tech that need our attention. As we unpack these complex topics, we'll equip you with sharp insights to

Change Healthcare Data Breach Impact Grows to 190 Million Individuals

27 January 2025
The impact of the Change Healthcare ransomware-caused data breach has increased from 100 million to 190 million individuals. The post Change Healthcare Data Breach Impact Grows to 190 Million Individuals appeared first on SecurityWeek.

Do We Really Need The OWASP NHI Top 10?

27 January 2025
The Open Web Application Security Project has recently introduced a new Top 10 project - the Non-Human Identity (NHI) Top 10. For years, OWASP has provided security professionals and developers with essential guidance and actionable frameworks through its Top 10 projects, including the widely used API and Web Application security lists.  Non-human identity security represents an emerging

GamaCopy Mimics Gamaredon Tactics in Cyber Espionage Targeting Russian Entities

27 January 2025
A previously unknown threat actor has been observed copying the tradecraft associated with the Kremlin-aligned Gamaredon hacking group in its cyber attacks targeting Russian-speaking entities. The campaign has been attributed to a threat cluster dubbed GamaCopy, which is assessed to share overlaps with another hacking group named Core Werewolf, also tracked as Awaken Likho and PseudoGamaredon.

MintsLoader Delivers StealC Malware and BOINC in Targeted Cyber Attacks

27 January 2025
Threat hunters have detailed an ongoing campaign that leverages a malware loader called MintsLoader to distribute secondary payloads such as the StealC information stealer and a legitimate open-source network computing platform called BOINC. "MintsLoader is a PowerShell based malware loader that has been seen delivered via spam emails with a link to Kongtuke/ClickFix pages or a JScript file,"

Industry Moves for the week of January 27, 2025 - SecurityWeek

27 January 2025
Explore industry moves and significant changes in the industry for the week of January 27, 2025. Stay updated with the latest industry trends and shifts.

Meta's Llama Framework Flaw Exposes AI Systems to Remote Code Execution Risks

26 January 2025
A high-severity security flaw has been disclosed in Meta's Llama large language model (LLM) framework that, if successfully exploited, could allow an attacker to execute arbitrary code on the llama-stack inference server.  The vulnerability, tracked as CVE-2024-50050, has been assigned a CVSS score of 6.3 out of 10.0. Supply chain security firm Snyk, on the other hand, has assigned it a

Top cybersecurity conferences in 2025

24 January 2025
Security magazine highlights a few upcoming cybersecurity conferences in 2025.

Subaru Starlink Vulnerability Exposed Cars to Remote Hacking

24 January 2025
A vulnerability in Subaru’s Starlink connected vehicle service exposed US, Canada, and Japan vehicle and customer accounts. The post Subaru Starlink Vulnerability Exposed Cars to Remote Hacking appeared first on SecurityWeek.

North Korean Fake IT Workers More Aggressively Extorting Enterprises

24 January 2025
North Korean fake IT workers are more aggressively extorting their employers in response to law enforcement actions. The post North Korean Fake IT Workers More Aggressively Extorting Enterprises appeared first on SecurityWeek.

In Other News: VPN Supply Chain Attack, PayPal $2M Settlement, RAT Builder Hacks Script Kiddies

24 January 2025
Noteworthy stories that might have slipped under the radar: Korean VPN supply chain attack, PayPal settles with New York for $2 million, trojanized RAT builder targets script kiddies.   The post In Other News: VPN Supply Chain Attack, PayPal $2M Settlement, RAT Builder Hacks Script Kiddies appeared first on SecurityWeek.

RANsacked: Over 100 Security Flaws Found in LTE and 5G Network Implementations

24 January 2025
A group of academics has disclosed details of over 100 security vulnerabilities impacting LTE and 5G implementations that could be exploited by an attacker to disrupt access to service and even gain a foothold into the cellular core network. The 119 vulnerabilities, assigned 97 unique CVE identifiers, span seven LTE implementations – Open5GS, Magma, OpenAirInterface, Athonet, SD-Core, NextEPC,

US Charges Five People Over North Korean IT Worker Scheme

24 January 2025
The US has announced charges against five individuals involved in a fake IT workers scheme to funnel funds to North Korea. The post US Charges Five People Over North Korean IT Worker Scheme appeared first on SecurityWeek.

CISA Warns of Old jQuery Vulnerability Linked to Chinese APT

24 January 2025
CISA has added the JQuery flaw CVE-2020-11023, previously linked to APT1, to its Known Exploited Vulnerabilities (KEV) catalog.   The post CISA Warns of Old jQuery Vulnerability Linked to Chinese APT appeared first on SecurityWeek.

Millions Impacted by PowerSchool Data Breach

24 January 2025
Four decades of student and educator information was stolen from PowerSchool – tens of millions are potentially affected. The post Millions Impacted by PowerSchool Data Breach appeared first on SecurityWeek.