DROP Platform Lets Californians Reduce Digital Footprint

California’s DROP Platform Launches, Bringing Data Deletion to Thousands of Residents A groundbreaking new platform is set to go live on August 1st in California, allowing residents to request the deletion of their personal data from over 600 registered data brokers with just a single click. The Delete Request and Opt-out Platform (DROP), managed by … Read more

Interpol Leverages Global System to Curtail Fraud Payments

Global Coalition Haults $6.6 Million in Fraudulent Payments, Offers Glimmer of Hope for Victims In a significant breakthrough in the fight against cybercrime, law enforcement agencies and financial organizations have successfully halted over $6.6 million in fraudulent payments, part of a larger operation aimed at curbing business email compromise (BEC) scams. This achievement is all … Read more

The Morning After We Pull a Root of Trust, Nobody Owns It

The Morning After We Pull a Root of Trust, Nobody Owns It Imagine waking up one morning to find that your bank’s online services have been severely disrupted. The reason? A trusted certificate authority (CA) has been distrusted by major browsers, causing widespread chaos in the financial sector. This scenario may sound like science fiction, … Read more

CISA Issues Fresh SBOM Guidance. Did They Get It Right?

A Sweeping Update to SBOM Guidance Falls Short of Real Risk Management Improvements The US Cybersecurity and Infrastructure Security Agency (CISA) has released a comprehensive update to software bill of materials (SBOM) guidance, incorporating feedback from over 90 organizations, including tech giants like Google, Microsoft, and Amazon Web Services. The new framework introduces a dozen … Read more

Interpol Leverages Global System to Curtail Fraud Payments

Interpol’s Global Anti-Fraud Network Cracks Down on Scammers in Record-Breaking Operation In a major victory for global law enforcement, Interpol has revealed that its international network of agencies and financial institutions has successfully blocked over $6.6 million in fraudulent payments as part of a massive operation to combat business email compromise (BEC) scams. The breakthrough … Read more

CISA Issues Fresh SBOM Guidance. Did They Get It Right?

A Long-Overdue Update: CISA Issues Fresh SBOM Guidance, But Will It Make a Difference? The US Cybersecurity and Infrastructure Security Agency (CISA) has released new guidelines for the minimum elements that organizations should include in a software bill of materials (SBOM). This move comes after months of consultation with major players like Google, Microsoft, and … Read more

Online ad firm Adform’s script compromised to steal cryptocurrency

Online Ad Firm Adform’s Script Compromised to Steal Cryptocurrency, Thousands of Websites Affected In a disturbing discovery, online advertising firm Adform has suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to thousands of websites using its ad platform. The malicious activity, which has been ongoing for the past week, allowed attackers to hijack clipboard content … Read more

Arch Linux disables AUR package adoption to stop malware flood

Arch Linux has temporarily disabled its popular package repository, the Arch User Repository (AUR), due to a sudden surge in malicious takeovers of existing packages. This move is aimed at preventing further spread of malware and giving developers time to clean up the affected packages. The decision was announced on the distribution’s mailing list by … Read more

Amgen says cloud data breach exposed patient health, proprietary info

Pharmaceutical giant Amgen has suffered a significant cloud-based data breach, exposing sensitive patient health information and proprietary corporate data to unauthorized access. The incident highlights the ongoing risks of cloud storage vulnerabilities and the importance of robust cybersecurity measures. Amgen, based in California, is a leading developer and manufacturer of medicines for serious illnesses, including … Read more

ESET tracks rise in malicious AI skills and adaptable malware

Cyberattackers Get Smarter, Faster, with AI-Powered Malware on the Rise The cybersecurity landscape is evolving rapidly, with threat actors leveraging artificial intelligence (AI) to improve their operations and evade detection. According to a new report from ESET, malicious AI skills and adaptable malware are on the rise, posing significant challenges for security professionals. In the … Read more