TeamPCP's Trivy Rampage: EU Cloud Breached, 1,000+ SaaS Targets Quantified
Hackers turned a security scanner into a skeleton key for clouds worldwide. Now, the EU Commission confirms the breach, with 1,000+ SaaS environments in the crosshairs.
Hackers turned a security scanner into a skeleton key for clouds worldwide. Now, the EU Commission confirms the breach, with 1,000+ SaaS environments in the crosshairs.
What if T-Mobile's latest 'minor' breach is just the glitch that exposes deeper vendor risks? The carrier insists it's isolated — one account, no credentials stolen — yet their track record screams caution.
Hackers waltzed into the European Commission's AWS cloud with a pilfered API key, swiping data from 30 EU outfits. CERT-EU calls it TeamPCP's work—supply-chain slop at its finest.
Google's Chrome just got its fifth zero-day fix in 2022. Attackers are hitting hard—North Koreans included—and the browser's under siege like never before.
A year after a critical vulnerability hit Hikvision cameras, 80,000 devices sit unpatched. Now cybercriminals are hawking access on the dark web—turning spy cams into hacker playgrounds.
Your inbox just got riskier if you're Ukrainian. Hackers dressed as the nation's top cyber cops to shove a sneaky RAT called AGEWHEEZE at a million emails — and they're bragging about it.
Forty-two years after inventing quantum cryptography, Charles Bennett and Gilles Brassard just won the $1M Turing Award. Here's why this honor feels more like a pat on the back for elegant physics than a fix for today's security messes.
Depthfirst just vacuumed up $80 million in Series B funding—totaling $120 million in under three months. Their new Dfs-mini1 model promises to lock down smart contracts with specialized AI.
You deploy an AI agent in GCP's Vertex AI thinking it's your trusty sidekick. Turns out, it might be spilling your secrets to attackers. Unit 42's research just blew the lid off this sneaky vulnerability.
Forget flashy ransomware. This crew's quietly mined 27.88 XMR — that's $9,392 — by tricking users with ISO lures since late 2023. But the real scam? RATs and fraud on top.
Picture your brain as a fortress riddled with unpatched exploits. K. Melton's taxonomy of cognitive security just redrew the battle lines between perception and manipulation.
Everyone figured Apple would just nudge users to iOS 26 for DarkSword fixes. Instead, they're backporting patches to iOS 18— a quiet revolution in how giants fight back against shadowy exploits.
Jaguar Land Rover's nightmare was no outlier – 78% of UK manufacturers got cyber-whacked last year. Boards? They're still pretending it's someone else's problem.
Your VPN choice just got a reality check. Malwarebytes Privacy VPN's first audit uncovered serious server setup risks, but swift fixes show they're serious about privacy.
One npm install, and boom—your cloud keys are en route to a hacker's server. Axios, the unsung hero of JS networking, just got turned into a trojan horse.
What if your most trusted HTTP client just became a backdoor? The Axios NPM package was compromised this week in a surgical hit, with signs pointing to North Korean actors.
Your desktop AI helper could be tomorrow's hacker playground. CrowdStrike's latest Falcon upgrades aim to lock it down — but shadow AI's wild west demands more than promises.
Your next innocent website tap could doom your iPhone. A leaked US hacking toolkit called Coruna exploits 23 iOS flaws to slip in undetectable malware, blurring lines between spies and street criminals.
If you've clung to your iPhone 11 or older on iOS 18, Apple's finally pushing DarkSword patches your way. Problem is, the exploit's already loose in the wild.
Attackers slipped infostealers into GitHub Actions and PyPI, turning vulnerability scanners against their users. Over 500,000 machines lost cloud tokens, SSH keys, and Kubernetes secrets in this escalating nightmare.