Security News

Carding tool abusing WooCommerce API downloaded 34K times on PyPI
2025-04-06 14:17

A newly discovered malicious PyPi package named 'disgrasya' that abuses legitimate WooCommerce stores for validating stolen credit cards has been downloaded over 34,000 times from the open-source...

Legacy Stripe API Exploited to Validate Stolen Payment Cards in Web Skimmer Campaign
2025-04-03 04:45

Threat hunters are warning of a sophisticated web skimmer campaign that leverages a legacy application programming interface (API) from payment processor Stripe to validate stolen payment...

Verizon Call Filter API flaw exposed customers' incoming call history
2025-04-02 19:47

A vulnerability in Verizon's Call Filter feature allowed customers to access the incoming call logs for another Verizon Wireless number through an unsecured API request. [...]

Nine-Year-Old npm Packages Hijacked to Exfiltrate API Keys via Obfuscated Scripts
2025-03-28 06:06

Cybersecurity researchers have discovered several cryptocurrency packages on the npm registry that have been hijacked to siphon sensitive information such as environment variables from compromised...

Cloudflare now blocks all unencrypted traffic to its API endpoints
2025-03-22 15:35

Cloudflare announced that it closed all HTTP connections and it is now accepting only secure, HTTPS connections for api.cloudflare.com. [...]

Nearly 12,000 API keys and passwords found in AI training dataset
2025-03-02 15:23

Close to 12,000 valid secrets that include API keys and passwords have been found in the Common Crawl dataset used for training multiple artificial intelligence models. [...]

12,000+ API Keys and Passwords Found in Public Datasets Used for LLM Training
2025-02-28 10:24

A dataset used to train large language models (LLMs) has been found to contain nearly 12,000 live secrets, which allow for successful authentication. The findings once again highlight how...

New Golang-Based Backdoor Uses Telegram Bot API for Evasive C2 Operations
2025-02-17 09:04

Cybersecurity researchers have shed light on a new Golang-based backdoor that uses Telegram as a mechanism for command-and-control (C2) communications. Netskope Threat Labs, which detailed the...

FINALDRAFT Malware Exploits Microsoft Graph API for Espionage on Windows and Linux
2025-02-13 09:11

Threat hunters have shed light on a new campaign targeting the foreign ministry of an unnamed South American nation with bespoke malware capable of granting remote access to infected hosts. The...

The API security crisis and why businesses are at risk
2025-02-05 04:30

In this Help Net Security video, Ivan Novikov, CEO of Wallarm, discusses the 2025 API ThreatStats Report, highlighting how APIs have become the primary attack surface over the past year, mainly...