RSS
Naked Security
bust
cybercrime
hacking
PyPI
Supply chain
Uncategorized
S3 Ep136: Navigating a manic malware maelstrom
malware
Python
PyPI open-source code repository deals with manic malware maelstrom
Packagist
php
PHP Packagist supply chain poisoned by hacker “looking for a job”
blackmail
data breach
extortion
MSI
private key
Ransomware
Attention gamers! Motherboard maker MSI admits to breach, issues “rogue firmware” alert
3cx
Wi-Fi
World Backup Day
S3 Ep129: When spyware arrives from someone you trust
0 day
Ben-Gurion University
iOS
skimming
vulnerability
Zero-day
S3 Ep113: Pwning the Windows kernel – the crooks who hoodwinked Microsoft [Audio + Text]
GitHub
GitHub blighted by “researcher” who created thousands of malicious projects
exfiltration
SecOps
XDR
Poisoned Python and PHP packages purloin passwords for AWS access
Microsoft
oauth
Zero Trust
GitHub issues final report on supply-chain source code intrusions