In the security news this week: • North Carolina ports and contingency plans • Back to paper and pencils • Midnight Blizzard compromises hotel Wi-Fi • DNS strikes again • Captive portals, stolen credentials, and nation-state scale • Phishing-resistant MFA • Goodbye SMS and voice authentication • Cornflake RAT and Chaco Shell • The NPM worm • Hundre...
As detailed in Bleeping Computer, the University of Pennsylvania experienced a significant data breach in 2025 due to a compromised single sign-on (SSO) account, underscoring the concentrated risks associated with this convenient authentication method.
Understanding which party can take which API actions — and which party is accountable for the resulting configuration state — determines where security controls must be implemented
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.