Numerous threat actors were reported by PRODAFT and GreyNoise to be targeting vulnerable JetBrains TeamCity continuous integration and deployment servers impacted by a critical authentication bypass flaw days after the bug was initially disclosed by Sonar security researchers, according to BleepingComputer.
GitHub has introduced passkeys for general availability two months after the feature was released in beta as part of its efforts to bolster phishing protections with wider passwordless security adoption, according to BleepingComputer.
California-based software development firm Retool has attributed the compromise of 27 client accounts, all of which were cryptocurrency organizations, in late August to the new sync functionality in Google Authenticator, according to BleepingComputer.
Secrets exposed by thousands of leading websites SecurityWeek reports that exposed Git directories containing code commits, file paths, source codes, and other secrets were observed across 4,500 websites in the Alexa Top 1 Million Websites list.
BleepingComputer reports that malicious extensions could facilitate the theft of Windows, macOS, and Linux credential manager-stored authentication tokens using a vulnerability in the Microsoft Visual Studio Code editor and development environment.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.