Security News

Bogus npm Packages Used to Trick Software Developers into Installing Malware
2024-04-27 05:12

An ongoing social engineering campaign is targeting software developers with bogus npm packages under the guise of a job interview to trick them into downloading a Python backdoor. Cybersecurity...

Friday Squid Blogging: Searching for the Colossal Squid
2024-04-26 21:07

What motivates the Russian autocrat? Browder argues that "Putin is a little man, who has stolen too much money, who is terrified of losing power. If he loses power he will go to jail, lose his money, and die. So you've this little [man] who is scared of losing his life. So what [does Putin] do?" He creates "a foreign enemy. That is what the Ukrainian invasion is all about."Browder warns that despite heroic efforts: Ukraine can still lose the war if the West backs away from its commitments to the besieged nation. What would come next? Browder argues that Putin cannot back down or not begin an invasion of Europe: Putin's ability to survive, having stolen hundreds of billions from his own people, depends on him being able to portray himself as a war president keeping his nation safe.

BeyondTrust Report: Microsoft Security Vulnerabilities Decreased by 5% in 2023
2024-04-26 18:22

The number of Microsoft vulnerabilities has mostly flattened in 2023, with elevation of privilege and identity attacks being particularly common, according to BeyondTrust's annual Microsoft Vulnerabilities report. The total number of Microsoft vulnerabilities has remained mostly steady for the past four years, with a slight dip in 2023 from 1,292 to 1,228 reported vulnerabilities.

Kaiser Permanente handed over 13.4M people's data to Microsoft, Google, others
2024-04-26 18:14

Your profile can be used to present content that appears more relevant based on your possible interests, such as by adapting the order in which content is shown to you, so that it is even easier for you to find content that matches your interests. Content presented to you on this service can be based on your content personalisation profiles, which can reflect your activity on this or other services, possible interests and personal aspects.

Telegram is down with "Connecting" error
2024-04-26 16:38

Telegram users are currently experiencing issues worldwide, with users unable to use the website and mobile apps. [...]

Second time lucky for Thoma Bravo, which scoops up Darktrace for $5.3B
2024-04-26 16:00

Your profile can be used to present content that appears more relevant based on your possible interests, such as by adapting the order in which content is shown to you, so that it is even easier for you to find content that matches your interests. Content presented to you on this service can be based on your content personalisation profiles, which can reflect your activity on this or other services, possible interests and personal aspects.

Fake job interviews target developers with new Python backdoor
2024-04-26 14:20

A new campaign tracked as "Dev Popper" is targeting software developers with fake job interviews in an attempt to trick them into installing a Python remote access trojan. The developers are asked to perform tasks supposedly related to the interview, like downloading and running code from GitHub, in an effort to make the entire process appear legitimate.

Severe Flaws Disclosed in Brocade SANnav SAN Management Software
2024-04-26 14:03

Several security vulnerabilities disclosed in Brocade SANnav storage area network (SAN) management application could be exploited to compromise susceptible appliances. The 18 flaws impact all...

UK's Investigatory Powers Bill to become law despite tech world opposition
2024-04-26 12:00

Your profile can be used to present content that appears more relevant based on your possible interests, such as by adapting the order in which content is shown to you, so that it is even easier for you to find content that matches your interests. Content presented to you on this service can be based on your content personalisation profiles, which can reflect your activity on this or other services, possible interests and personal aspects.

Long Article on GM Spying on Its Cars’ Drivers
2024-04-26 11:01

About Bruce Schneier I am a public-interest technologist, working at the intersection of security, technology, and people. I've been writing about security issues on my blog since 2004, and in my monthly newsletter since 1998.