New York Times Data Breach Exposes 273GB of Source Code Repositories
Security researchers discover breach where attacker exploited exposed GitHub token to steal internal communications, user keys, and software development details.
Security researchers discover breach where attacker exploited exposed GitHub token to steal internal communications, user keys, and software development details.
A critical prompt injection vulnerability, identified as CVE-2024-5184, has been disclosed in EmailGPT, an AI email assistant service that utilizes OpenAI’s GPT models, potentially leading to data exposure, financial loss, and denial-of-service attacks.
A software vulnerability in Ariane Systems’ kiosk platform allows attackers to access hotel guest data and create room keys through check-in terminals, emphasizing the importance of proper security measures and incident response plans.
Security leaders stress the need for understanding and collaboration among colleagues to enhance security posture and mitigate risks.
Recent security assessments by Patchstack have identified multiple vulnerabilities in the WooCommerce Amazon Affiliates (WZone) plugin, affecting all tested versions and prompting users to take protective measures.
A new ransomware group known as “Fog” is targeting organizations in the education and recreation sectors in the United States, using compromised VPN credentials and tactics like pass-the-hash and credential stuffing for lateral movement within networks.