GitLab Continuous Integration pipelines are being targeted in a new software supply chain attack dubbed CrateDepression, which involves malware deployment, reports SecurityWeek.
Threat actors have been launching millions of attacks exploiting a remote code execution flaw in the Tatsu Builder plugin for WordPress, with up to half of the nearly 100,000 websites leveraging the plugin still at risk of attacks, according to BleepingComputer.
Costa Rican President Rodrigo Chaves has claimed that the Conti ransomware gang has been working with collaborators across Costa Rica in a recent ransomware attack against its government agencies, reports CyberScoop.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.