North Korea-linked Lazarus Group is targeting freelance software developers to compromise the supply chain.
The post North Korean Hackers Targeting Freelance Software Developers appeared first on SecurityWeek.
Category Added in a WPeMatico Campaign
North Korea-linked Lazarus Group is targeting freelance software developers to compromise the supply chain.
The post North Korean Hackers Targeting Freelance Software Developers appeared first on SecurityWeek.
Both human and machine identities occupy a unique position: they are simultaneously the foundation of cybersecurity and its weakest link.
The post Cyber Insights 2025: Identities appeared first on SecurityWeek.
President Joe Biden issued an executive order aimed at strengthening the nation’s cybersecurity and making it easier to go after foreign adversaries or hacking groups.
The post Biden Executive Order Aims to Shore Up US Cyber Defenses appeared first on SecurityWeek.
Hackers have leaked 15,000 Fortinet firewall configurations, which were apparently obtained as a result of exploitation of CVE-2022–40684.
The post Data From 15,000 Fortinet Firewalls Leaked by Hackers appeared first on SecurityWeek.
In 2024 organizations informed the US government about 585 healthcare data breaches affecting a total of nearly 180 million user records.
The post 2024 US Healthcare Data Breaches: 585 Incidents, 180 Million Compromised User Records appeared first on SecurityWeek.
Jen Easterly hopes CISA is allowed to continue its election-related work under new leadership despite “contentiousness” around that part of its mission.
The post Head of US Cybersecurity Agency Says She Hopes It Keeps up Election Work Under Trump appeared first on SecurityWeek.
Law enforcement turns the PlugX malware’s own self-delete mechanism against it, nuking the China-linked trojan from thousands of US machines.
The post FBI Uses Malware’s Own ‘Self-Delete’ Trick to Erase Chinese PlugX From US Computers appeared first on SecurityWeek.
With DORA’s January 2025 compliance deadline approaching, financial institutions must embrace rigorous testing, tailored threat profiles, and continuous vigilance to safeguard against cyber threats.
The post DORA’s Deadline Looms: Navigating the EU’s Mandate for Threat Led Penetration Testing appeared first on SecurityWeek.
Open source software (OSS) is a prime target for supply chain cyberattacks and protecting it remains a major challenge.
The post Cyber Insights 2025: Open Source and Software Supply Chain Security appeared first on SecurityWeek.
A vulnerability in Google’s OAuth implementation allows takeover of old employee accounts when domain ownership changes.
The post Google OAuth Flaw Leads to Account Takeover When Domain Ownership Changes appeared first on SecurityWeek.
