Malware-laced GitHub repositories using popular names and topics are being advanced by threat actors through automated updates and fraudulent stars meant to manipulate the leading software developer platform's search rankings as part of a new open-source supply chain attack, The Hacker News reports.
Twenty-one of S&P companies have been subjected to data breaches in 2023, indicating the firms' attractiveness as cyberattack targets due to the lucrative business they bring to threat actors, reports SiliconAngle.
More than 60,000 WordPress sites with the WP-Members Membership Plugin could be compromised with arbitrary script injections due to a high-severity cross-site scripting vulnerability, tracked as CVE-2024-1852, reports SecurityWeek.
Seventy-four percent of codebases had high-risk open source vulnerabilities last year, representing a significant increase over the 48% of those with exploited flaws, proof-of-concept exploits, and remote code execution issues in 2022.
As the number of organizations depending on third parties has grown, so has the amount of third-party risk. Paul Wagenseil provides a snapshot of the state of third-party risk and how your organization can reduce and manage its exposure, with special emphasis on access management, internal segmentation, due diligence, certifications, compliance an...
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.