
Ruby Gem Typosquatting Attack Barely Averted by Chance
A malicious Ruby gem with a subtle typo nearly shipped, highlighting critical gaps in supply chain security.

Five shifts. Five minutes. No noise.
No spam. Unsubscribe anytime. Powered by Beehiiv.

The EU's NIS2 Directive moves beyond mere compliance, imposing direct liability on entities for security failures.
AI's rapid discovery of software flaws outpaces traditional security workflows, demanding new strategies for correlation and remediation.

The popular encrypted email provider's primary domain is inaccessible after being targeted by the U.S. Treasury.

A malicious Ruby gem with a subtle typo nearly shipped, highlighting critical gaps in supply chain security.

An attacker drained $528,000 in SUI from BlueMove DEX not via an overflow, but a subtle desynchronization between contract versions.
An unauthorized Wi-Fi network caused disruptions on a Delta flight, prompting an investigation into a potential security incident.

High-severity vulnerability in Cisco's VPN software is actively exploited, leading to remote denial-of-service attacks.
Microsoft's latest Patch Tuesday tackles a staggering 400 vulnerabilities, including three zero-days, two of which were publicly known.

Roadside cameras can now link device identifiers to vehicle plates, creating a comprehensive digital footprint of movements.
Global distribution giant Wesco is investigating a security incident after threat actor ExfilSquad claimed to have stolen sensitive data.

A new attack exploits proprietary LLM APIs to extract internal reasoning steps, posing significant risks to model privacy and security.
A new 'Pass-ta-key' attack highlights a nuanced difference in passkey handling between Windows and other OS, but experts say it poses no real risk.

Mozilla has replaced its primary GPG signing key for Firefox and Thunderbird after its accidental exposure on GitHub.