Security News
![North Korea targets crypto developers via NPM supply chain attack](/static/build/img/news/north-korea-targets-crypto-developers-via-npm-supply-chain-attack-small.jpg)
Yet another cash grab from Kim's cronies and an intel update from Microsoft North Korea has changed tack: its latest campaign targets the NPM registry and owners of Exodus and Atomic...
![Google Bans 158,000 Malicious Android App Developer Accounts in 2024](/static/build/img/news/google-bans-158000-malicious-android-app-developer-accounts-in-2024-small.jpg)
Google said it blocked over 2.36 million policy-violating Android apps from being published to the Google Play app marketplace in 2024 and banned more than 158,000 bad developer accounts that...
![Lazarus Group Targets Web3 Developers with Fake LinkedIn Profiles in Operation 99](/static/build/img/news/lazarus-group-targets-web3-developers-with-fake-linkedin-profiles-in-operation-99-small.jpg)
The North Korea-linked Lazarus Group has been attributed to a new cyber attack campaign dubbed Operation 99 that targeted software developers looking for freelance Web3 and cryptocurrency work to...
![Time for a change: Elevating developers’ security skills](/static/build/img/news/time-for-a-change-elevating-developers-security-skills-small.jpg)
Organizations don’t know their software engineers’ security skills because they don’t assess them in the interview process. Trying to do that in an interview is challenging, of course, given the...
![Cybercriminals Target Ethereum Developers with Fake Hardhat npm Packages](/static/build/img/news/cybercriminals-target-ethereum-developers-with-fake-hardhat-npm-packages-small.jpg)
Cybersecurity researchers have revealed several malicious packages on the npm registry that have been found impersonating the Nomic Foundation's Hardhat tool in order to steal sensitive data from...
![Malicious npm packages target Ethereum developers' private keys](/static/build/img/news/malicious-npm-packages-target-ethereum-developers-private-keys-small.jpg)
Twenty malicious packages impersonating the Hardhat development environment used by Ethereum developers are targeting private keys and other sensitive data. [...]
![US charges suspected LockBit ransomware developer](/static/build/img/news/us-charges-suspected-lockbit-ransomware-developer-small.jpg)
The US Department of Justice has unsealed charges against Rostislav Panev, 51, a dual Russian and Israeli national, suspected of being a developer for the LockBit ransomware group. Panev was...
![LockBit Developer Rostislav Panev Charged for Billions in Global Ransomware Damages](/static/build/img/news/lockbit-developer-rostislav-panev-charged-for-billions-in-global-ransomware-damages-small.jpg)
A dual Russian and Israeli national has been charged in the United States for allegedly being the developer of the now-defunct LockBit ransomware-as-a-service (RaaS) operation since its inception...
![Tackling software vulnerabilities with smarter developer strategies](/static/build/img/news/tackling-software-vulnerabilities-with-smarter-developer-strategies-small.jpg)
In this Help Net Security interview, Karl Mattson, CISO at Endor Labs, discusses strategies for enhancing secure software development. Mattson covers how developers can address vulnerabilities in...
![Cloudflare’s developer domains increasingly abused by threat actors](/static/build/img/news/cloudflares-developer-domains-increasingly-abused-by-threat-actors-small.jpg)
Cloudflare's 'pages.dev' and 'workers.dev' domains, used for deploying web pages and facilitating serverless computing, are being increasingly abused by cybercriminals for phishing and other...