Microsoft Adds Inline Data Protection to Edge for Business to Block GenAI Data Leaks

25/03/2025 0 Comments 0 tags

Microsoft on Monday announced a new feature called inline data protection for its enterprise-focused Edge for Business web browser. The native data security control is designed to prevent employees from

Critical Ingress NGINX Controller Vulnerability Allows RCE Without Authentication

25/03/2025 0 Comments 0 tags

A set of five critical security shortcomings have been disclosed in the Ingress NGINX Controller for Kubernetes that could result in unauthenticated remote code execution, putting over 6,500 clusters at

VanHelsing RaaS Launch: 3 Victims, $5K Entry Fee, Multi-OS, and Double Extortion Tactics

24/03/2025 0 Comments 0 tags

A ransomware-as-a-service (RaaS) operation called VanHelsing has already claimed three victims since it launched on March 7, 2025. “The RaaS model allows a wide range of participants, from experienced hackers

⚡ THN Weekly Recap: GitHub Supply Chain Attack, AI Malware, BYOVD Tactics, and More

24/03/2025 0 Comments 0 tags

A quiet tweak in a popular open-source tool opened the door to a supply chain breach—what started as a targeted attack quickly spiraled, exposing secrets across countless projects. That wasn’t

VSCode Marketplace Removes Two Extensions Deploying Early-Stage Ransomware

24/03/2025 0 Comments 0 tags

Cybersecurity researchers have uncovered two malicious extensions in the Visual Studio Code (VSCode) Marketplace that are designed to deploy ransomware that’s under development to its users. The extensions, named “ahban.shiba”

How to Balance Password Security Against User Experience

24/03/2025 0 Comments 0 tags

If given the choice, most users are likely to favor a seamless experience over complex security measures, as they don’t prioritize strong password security. However, balancing security and usability doesn’t

Critical Next.js Vulnerability Allows Attackers to Bypass Middleware Authorization Checks

24/03/2025 0 Comments 0 tags

A critical security flaw has been disclosed in the Next.js React framework that could be potentially exploited to bypass authorization checks under certain conditions. The vulnerability, tracked as CVE-2025-29927, carries

GitHub Supply Chain Breach: Coinbase Attack Exposes 218 Repositories, Leaks CI/CD Secrets

23/03/2025 0 Comments 0 tags

The supply chain attack involving the GitHub Action “tj-actions/changed-files” started as a highly-targeted attack against one of Coinbase’s open-source projects, before evolving into something more widespread in scope. “The payload

U.S. Treasury Lifts Tornado Cash Sanctions Amid North Korea Money Laundering Probe

22/03/2025 0 Comments 0 tags

The U.S. Treasury Department has announced that it’s removing sanctions against Tornado Cash, a cryptocurrency mixer service that has been accused of aiding the North Korea-linked Lazarus Group to launder

UAT-5918 Targets Taiwan’s Critical Infrastructure Using Web Shells and Open-Source Tools

21/03/2025 0 Comments 0 tags

Threat hunters have uncovered a new threat actor named UAT-5918 that has been attacking critical infrastructure entities in Taiwan since at least 2023. “UAT-5918, a threat actor believed to be