Fake Open VSX Extensions Harvest Private Repo and CI Data
77 counterfeit Open VSX extensions beaconed to one domain, 19 harvesting git and CI identity
Mahesh covers ransomware gangs, data leak sites, and dark web marketplaces, mapping how stolen data surfaces and gets sold. Follows ShinyHunters-style groups across leak forums.
252 stories filed
77 counterfeit Open VSX extensions beaconed to one domain, 19 harvesting git and CI identity
A Google Firebase misconfiguration lets users of tl;dv, an AI meeting tool, query any other users' meeting information…
Cloud and SaaS are now the preferred operating environments for threat actors, amid a continued shift to identity…
Over the weekend, the vendor discovered another vector of authentication bypass CVE-2026-18577 that gives attackers…
Researchers dug into the root of the problem with the goal of promoting industry collaboration on improved protective…
New HollowFrame loader hid Go code in a fake Python DLL after pre-staging Defender exclusions
The organization behind Team USA's Olympic/Paralympic fencing teams has automated identity verification to handle…
A myriad of software makes up the typical AI harness, and trust issues between the components can create concerning…
The UK’s National Cyber Security Centre wants network device makers to improve forensic observability
OpenAI's goal-seeking agent compromised a Modal customer environment and others during its sandbox escape.
Dark Reading Confidential Episode 20: Expert Rich Mogull reflects on lessons cyber teams should pull from the OpenAI…
The National Cyber Security Centre has released a detailed framework to assist with incident response and recovery