Security News > 2023 > January > Serious Security: How to improve cryptography, resist supply chain attacks, and handle data breaches

So we though we'd take a quick look back at some of the major issues we covered over the last couple of weeks, and reiterate the serious security lessons we can learn from them.
If you are ever stuck with doing a data breach notification, don't try to rewrite history to your marketing advantage.
If you receive a data breach notification, and there are obvious things you can do that will improve both your theoretical security and your practical peace of mind, try to find the time to do them.
Cryptography is essential for national security and for and the functioning of the economy.
These crooks used DNS lookups with "Server names" that were actually exfiltrated data.
Apparently, the attackers in this case are now claiming that they stole personal data, including private keys, for "Research reasons" and say they've deleted the stolen data now.
News URL
Related news
- ⚡ THN Weekly Recap: GitHub Supply Chain Attack, AI Malware, BYOVD Tactics, and More (source)
- AI-Powered SaaS Security: Keeping Pace with an Expanding Attack Surface (source)
- Recent GitHub supply chain attack traced to leaked SpotBugs token (source)
- SpotBugs Access Token Theft Identified as Root Cause of GitHub Supply Chain Attack (source)
- That massive GitHub supply chain attack? It all started with a stolen SpotBugs token (source)
- New TCESB Malware Found in Active Attacks Exploiting ESET Security Scanner (source)
- Western Sydney University discloses security breaches, data leak (source)
- Ripple's xrpl.js npm Package Backdoored to Steal Private Keys in Major Supply Chain Attack (source)
- Ripple NPM supply chain attack hunts for private keys (source)
- Linux 'io_uring' security blindspot allows stealthy rootkit attacks (source)