Application securityFake npm utilities remotely delete entire app directoriesLaura FrenchJune 6, 2025The malicious packages create backdoor endpoints and act as wipers when activated.
Application securityChrome extensions transmit sensitive data over HTTP, leak API keysSteve ZurierJune 6, 2025Security pros warn that the leaked data could be used to launch profiling, phishing, or other targeted attacks.
Threat Intelligence0-click exploitation of iMessage nickname feature revealedLaura FrenchJune 5, 2025The now-resolved issue was potentially used to target high-profile individuals, researchers say.
IdentitySecuring AI agent identities crucial to enterprises, says research firmKaren "Pepper" HoffmanJune 5, 2025Agentic identity and security platforms (AISP) are quickly becoming the standard for security, says Aragon Research.
IdentityCisco patches Identity Services Engine flaw affecting AWS, Azure, OCISteve ZurierJune 5, 2025Cloud deployments of the Cisco Identity Services Engine could let attackers access sensitive data.
Women in IT SecurityNominations open: SC Media’s 2025 Women in IT SecurityHeidi MurphyJune 5, 2025SC Media opens nominations for its 12th annual Women in IT Security program, spotlighting leadership, resilience, and impact across the cybersecurity industry.
Network SecurityOpen-source Chaos RAT used in recent attacks targeting LinuxLaura FrenchJune 4, 2025The free remote administration tool enables reverse shell access, file management and command execution.
IdentityLumos touts ‘Albus’ as first AI agent for autonomous identity governanceKaren "Pepper" HoffmanJune 4, 2025New AI multi-agent system to assist organizations in scaling up identity governance and administration.
IdentityOpen-source code repos open to supply chain attacks, researchers warnSteve ZurierJune 4, 2025Multiple malicious packages were discovered on npm, PyPI and RubyGems repositories.
IdentityGoogle to drop trust of Chunghwa and NetLock certificates from ChromeShaun NicholsJune 3, 2025Google cites "patterns of concerning behavior" with China- and Hungary-based certificate authorities.