Application securityDomain takeovers possible with legacy Python bootstrap script flawSC StaffDecember 1, 2025Old Python packages' bootstrap files are impacted by a security weakness that could enable a domain takeover attack-based supply chain compromise of the Python Package Index, according to The Hacker News.
Application securitySynced calendars a potential threat vector for millions of devicesLaura FrenchNovember 26, 2025Expired or compromised domains could be used to push out malicious calendar files.
Application securityThird-party hack may have spread to JPMorgan, Citi, and Morgan StanleySteve ZurierNovember 24, 2025FBI investigating breach into residential loan mortgage company SitusAMC.
Vulnerability ManagementCloudflare, Gh0stRAT, npm, North Koreans, Arch, Steam, Documentaries, Aaran Leyland.. – SWN #530November 18, 2025Cloudflare, Gh0stRAT, npm, North Korean Employees, Arch Linux Steam Machine, Documentaries, Aaran Leyland, and more on the Security Weekly News.
Application securityHackers actively exploiting year-old flaws in WordPress plug-insSteve ZurierOctober 28, 2025Vulnerabilities in GutenKit and Hunk Companion plug-ins could lead to remote code execution (RCE).
Vulnerability ManagementPython-socket.io module flaw lets attackers access business serversSteve ZurierOctober 27, 2025Security pros say teams that build apps in python-socket.io should patch right away.
Application securityWhen yesterday’s code becomes today’s threatBrian TrzupekOctober 21, 2025New npm supply chain attack exposes risks of outdated dependencies, highlighting need for real-time code risk alerts.