A new attack method called the 'Contagious Interview' has emerged, exploiting trust granted to repository authors in Visual Studio Code (VS Code). Once a user gives access to a malicious application from a compromised repository, the app can execute arbitrary commands on the user's system without requiring any further interaction. This poses a significant risk to developers and users who rely on VS Code for their projects, as it can lead to unauthorized access and control over their systems. The attack leverages the trust inherent in open-source collaborations, making it crucial for users to scrutinize the sources of their software. As this method becomes more prevalent, developers should be cautious about the repositories they trust.
Latest Cybersecurity Threats
Real-time threat intelligence from trusted sources
The launch of the GCVE system aims to provide a decentralized approach to tracking software vulnerabilities, addressing the ongoing issues faced by the 25-year-old CVE program. This initiative comes in response to funding difficulties that have raised concerns about the sustainability of the CVE, a resource widely used by cybersecurity professionals globally. By decentralizing the tracking of vulnerabilities, GCVE hopes to enhance reliability and accessibility for users who need to stay informed about security risks. The success of this system may significantly impact how organizations manage and respond to software vulnerabilities, potentially leading to quicker updates and patches. As cybersecurity threats continue to evolve, having a more resilient tracking system could benefit both developers and end-users.
A new type of Linux malware called VoidLink has emerged, specifically targeting cloud environments. What makes this malware stand out is that it has been primarily developed using artificial intelligence. Researchers are concerned about its sophistication and the potential risks it poses to organizations that rely on cloud services. The use of AI in its development could allow for more adaptive and dangerous attacks, making it critical for companies to bolster their security measures. As this malware evolves, it could lead to significant data breaches if not addressed promptly.
BleepingComputer
PcComponentes, a well-known tech retailer in Spain, is facing scrutiny after claims surfaced about a data breach affecting 16 million customers. The company has denied these allegations but acknowledged that it experienced a credential stuffing attack. This type of attack occurs when hackers use stolen credentials from one service to access accounts on another, raising concerns about the security of customer data. While PcComponentes insists that the data breach claims are unfounded, the incident still raises alarms about the potential vulnerabilities faced by online retailers. Customers should be vigilant and consider changing their passwords, especially if they use the same credentials across multiple sites.
SCM feed for Latest
Betsson Group, an online gambling operator, has recently implemented fraud protection and threat intelligence solutions from Group-IB to address increasing sophisticated cyber threats targeting its sports betting and casino platforms. This decision comes as the company aims to bolster its defenses against potential attacks that could compromise user data and financial transactions. The rise in cyber threats in the online gambling industry poses significant risks, not only to operators but also to their customers. By integrating Group-IB’s technology, Betsson is taking proactive steps to enhance its security measures and safeguard its platforms. This move reflects a growing recognition among online gambling companies of the need to invest in advanced cybersecurity solutions to protect against evolving threats.
SCM feed for Latest
Group-IB has reported that artificial intelligence is driving a new phase of cybercrime, termed the 'fifth wave.' This new wave is characterized by the availability of advanced hacking tools that are now affordable, scalable, and accessible to criminals regardless of their technical expertise. As a result, even novice attackers can carry out sophisticated cyberattacks that were once limited to highly skilled hackers. This shift raises significant concerns for businesses and organizations, as the barriers to entry for cybercriminals have been drastically lowered. Companies need to be aware of this evolving threat landscape and take proactive measures to protect their systems and data from potential attacks.
SCM feed for Latest
Germany is working on new legislation to enhance the surveillance and hacking powers of its Federal Intelligence Service. This move is intended to lessen the country's dependence on U.S. intelligence while bringing its capabilities in line with those of other European nations, such as the UK and France. The proposed changes are part of a broader effort to strengthen national security and adapt to evolving threats. If passed, the law would significantly expand the government's ability to monitor communications and conduct cyber operations. This development raises concerns about privacy and civil liberties, as the balance between security and individual rights is increasingly scrutinized.
SCM feed for Latest
Keeper Security has identified ongoing issues with identity and access management as the likely cause behind two recent security incidents in the Asia-Pacific region. While specific details about the incidents were not disclosed, the firm emphasized that failures in managing user identities and access controls can lead to significant security vulnerabilities. This situation raises concerns for organizations operating in the region, as poor identity management can expose sensitive data and increase the risk of breaches. Companies are encouraged to reassess their security practices to better protect against these types of failures. The implications of these incidents underscore the importance of effective identity management in maintaining overall cybersecurity.
Anthropic has addressed several critical vulnerabilities found in their Git MCP server, identified by the AI security startup Cyata. The issues include a path validation bypass (CVE-2025-68145), an unrestricted git_init problem (CVE-2025-68143), and an argument injection vulnerability in git_diff (CVE-2025-68144). These vulnerabilities could potentially allow attackers to manipulate Git operations, which could compromise the integrity of code repositories. It is essential for users of the Git MCP server to apply the latest patches to ensure their systems are secure against these threats, as failure to do so may expose them to exploitation. Users are urged to stay informed about these vulnerabilities and take necessary actions to protect their environments.
SCM feed for Latest
cURL, the widely used open-source tool for transferring data, has decided to shut down its bug bounty program. This decision comes after the organization was inundated with submissions generated by artificial intelligence, which made it difficult to discern legitimate reports from automated ones. The influx of AI-generated submissions overwhelmed the program, prompting cURL to prioritize genuine contributions from human researchers. This move affects the community of security researchers who rely on bug bounties to report vulnerabilities and receive compensation for their efforts. The closure of the program raises concerns about the future of crowdsourced security testing, especially as AI technologies become more prevalent in various domains.
SCM feed for Latest
A recent report from Corporation Service Co. (CSC) indicates that a significant number of Global 2000 companies are falling short on domain security. Specifically, 67% of these companies have implemented fewer than half of the recommended security measures for their domains. This lack of adequate protection raises concerns about the vulnerability of these major organizations to cyber threats, such as phishing and domain spoofing. Without proper domain security practices, companies risk their reputation and data integrity, which can lead to financial losses and customer trust issues. The findings serve as a wake-up call for businesses to prioritize their domain security strategies and adopt necessary measures to safeguard their online presence.
The Everest ransomware group has claimed responsibility for a data breach affecting McDonald's India. They provided screenshots as proof, which reportedly include sensitive information such as financial reports, audit trails, pricing data, and internal communications. This incident raises concerns about the security of corporate data and the potential implications for customer trust and business operations. Companies need to take this threat seriously and evaluate their cybersecurity measures to prevent similar breaches. The exposure of such sensitive data could lead to financial losses and reputational damage for McDonald's India.
TP-Link has addressed a serious vulnerability in its VIGI camera line, which was rated with a CVSS score of 8.7. This flaw allowed attackers on the same local network to bypass authentication during the password recovery process, potentially giving them unauthorized access to the cameras. Users of TP-Link VIGI cameras should be aware of this issue, as it could compromise the security of their surveillance systems. The company has released patches to fix this vulnerability, and it is crucial for users to apply these updates promptly to protect their devices from potential exploitation. Ensuring that all camera firmware is up-to-date is essential for maintaining security.
The Hacker News
Zoom and GitLab have rolled out security updates to fix several vulnerabilities, including a critical flaw that could allow remote code execution (RCE) on Zoom Node Multimedia Routers (MMRs). This vulnerability, identified as CVE-2026-22844, poses a significant risk as it could enable an attacker to execute malicious code during a meeting. Additionally, the updates address issues related to denial-of-service (DoS) attacks and two-factor authentication (2FA) bypasses, which could compromise user accounts. Organizations using these platforms should prioritize applying the latest updates to safeguard their systems against potential exploitation. Keeping software up to date is crucial to maintaining security and protecting sensitive data.
SCM feed for Latest
Cloudflare has patched a vulnerability in its Web Application Firewall (WAF) that could allow attackers to bypass security measures and gain direct access to servers. This vulnerability was identified by researchers from FearsOff in October and reported through Cloudflare's bug bounty program. Companies using Cloudflare’s WAF should be aware that this issue posed a risk of unauthorized access to their systems. The patch has been released to mitigate this risk, and it’s crucial for users to apply the updates promptly to ensure their applications remain secure. Staying ahead of such vulnerabilities is essential for maintaining the integrity of web applications.