❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

Security firms dispute credit for overlapping CVE reports

By: Ax Sharma
14 October 2025 at 10:52
FuzzingLabs has accused the YCombinator-backed startup, Gecko Security, of replicating its vulnerability disclosures. Gecko allegedly filed for 2 CVEs based on FuzzingLabs' reports without crediting them. Gecko denies any wrongdoing, callingΒ the allegations a misunderstanding over disclosure process. [...]

ParkMobile pays... $1 each for 2021 data breach that hit 22 million

By: Ax Sharma
5 October 2025 at 08:16
ParkMobile has finally wrapped up a class action lawsuit over the platform's 2021 data breach that hit 22 million users. But there's a catch: victims are receiving compensation in the form of a $1 in-app credit, which they must claim manually. And, it comes with an expiration date. [...]

NPM package caught using QR Code to fetch cookie-stealing malware

By: Ax Sharma
23 September 2025 at 06:42
Newly discovered npm package 'fezbox'Β employs QR codes to hide a second-stage payload to steal cookies from a user's web browser. The package,Β masquerading as a utility library, leverages this innovative steganographic technique to harvest sensitive data, such as user credentials,Β from a compromised machine. [...]

Self-propagating supply chain attack hits 187 npm packages

By: Ax Sharma
16 September 2025 at 12:46
Security researchers have identified at leastΒ 187Β npm packages compromised in an ongoing supply chain attack. The coordinated worm-style campaign dubbed 'Shai-Hulud' started yesterday with the compromise of the @ctrl/tinycolor npm package, and has now expanded to CrowdStrike's npm namespace. [...]
❌
❌