Security
Headlines
HeadlinesLatestCVEs

Source

DARKReading

HackerOne Employee Fired for Stealing and Selling Bug Reports for Personal Gain

Company says it is making changes to its security controls to prevent malicious insiders from doing the same thing in future; reassures bug hunters their bounties are safe.

DARKReading
#vulnerability
Supply Chain Attack Deploys Hundreds of Malicious NPM Modules to Steal Data

A widespread campaign uses more than 24 malicious NPM packages loaded with JavaScript obfuscators to steal form data from multiple sites and apps, analysts report.

Why Browser Vulnerabilities Are a Serious Threat — and How to Minimize Your Risk

As a result of browser market consolidation, adversaries can focus on uncovering vulnerabilities in just two main browser engines.

Google Chrome WebRTC Zero-Day Faces Active Exploitation

The heap buffer-overflow issue in Chrome for Android could be used for DoS, code execution, and more.

3 Cyber Threats Resulting From Today's Technology Choices to Hit Businesses by 2024

Companies need to consider the cost to disengage from the cloud along with proactive risk management that looks at governance issues resulting from heavy use of low- and no-code tools.

Name That Edge Toon: On Guard

Come up with a clever caption, and our panel of experts will reward the winner with a $25 Amazon gift card.

ICYMI: A Microsoft Warning, Follina, Atlassian, and More

Dark Reading's digest of the other don't-miss stories of the week, including YouTube account takeovers and a sad commentary on cyber-pro hopelessness.

OpenSea NFT Marketplace Faces Insider Hack

OpenSea warns users that they are likely to be targeted in phishing attacks after a vendor employee accessed and downloaded its email list.

Time Constraints Hamper Security Awareness Programs

Even as more attacks target humans, lack of dedicated staff, relevant skills, and time are making it harder to develop a security-aware and engaged workforce, SANS says.

Criminals Use Deepfake Videos to Interview for Remote Work

The latest evolution in social engineering could put fraudsters in a position to commit insider threats.