Security News

US charges suspected Redline infostealer developer, admin
2024-10-29 16:14

The identity of a suspected developer and administrator of the Redline malware-as-a-service operation has been revealed: Russian national Maxim Rudometov. Infrastructure takedown As promised on...

BeaverTail Malware Resurfaces in Malicious npm Packages Targeting Developers
2024-10-28 13:51

Three malicious packages published to the npm registry in September 2024 have been found to contain a known malware called BeaverTail, a JavaScript downloader and information stealer linked to an...

Malicious npm Packages Target Developers' Ethereum Wallets with SSH Backdoor
2024-10-22 09:33

Cybersecurity researchers have discovered a number of suspicious packages published to the npm registry that are designed to harvest Ethereum private keys and gain remote access to the machine via...

N. Korean Hackers Use Fake Interviews to Infect Developers with Cross-Platform Malware
2024-10-09 13:33

Threat actors with ties to North Korea have been observed targeting job seekers in the tech industry to deliver updated versions of known malware families tracked as BeaverTail and...

New PondRAT Malware Hidden in Python Packages Targets Software Developers
2024-09-23 06:39

Threat actors with ties to North Korea have been observed using poisoned Python packages as a way to deliver a new malware called PondRAT as part of an ongoing campaign. PondRAT, according to new...

Differential privacy in AI: A solution creating more problems for developers?
2024-09-19 05:00

In the push for secure AI models, many organizations have turned to differential privacy. But is the very tool meant to protect user data holding back innovation? Developers face a tough choice:...

Python Developers Targeted with Malware During Fake Job Interviews
2024-09-17 11:02

Interesting social engineering attack: luring potential job applicants with fake recruiting pitches, trying to convince them to download malware. From a news article These particular attacks from...

WordPress Mandates Two-Factor Authentication for Plugin and Theme Developers
2024-09-12 04:57

WordPress.org has announced a new account security measure that will require accounts with capabilities to update plugins and themes to activate two-factor authentication (2FA) mandatorily. The...

Fake password manager coding test used to hack Python developers
2024-09-11 21:09

Members of the North Korean hacker group Lazarus posing as recruiters are baiting Python developers with coding test project for password management products that include malware. [...]

WordPress.org to require 2FA for plugin developers by October
2024-09-11 17:33

Starting October 1st, WordPress.org accounts that can push updates and changes to plugins and themes will be required to activate two-factor authentication (2FA) on their accounts. [...]