Identity12K hardcoded API keys and passwords found in public LLM training dataSteve ZurierFebruary 28, 2025Criminals use LLMJacking to abuse stolen API keys to GenAI services by selling the access to third parties.
Application securityVS Code theme with nearly 4M installs removed due to security ‘red flags’Laura FrenchFebruary 28, 2025The removal of the free Material Theme was met with controversy as its developer disputed the allegations.
Security ArchitectureGoogle calls for overhaul of memory safety standardsShaun NicholsFebruary 27, 2025Google wants secure-by-design practices to limit access to data stored in memory.
Critical Infrastructure SecurityWindows CE OS flaws pose risk to industrial systems, medical settingsSteve ZurierFebruary 27, 2025Security pros urge teams at industrial sites to air-gap legacy Windows CE systems immediately.
Vulnerability ManagementCybercriminals prefer remote tools over malware, says CrowdStrikeShaun NicholsFebruary 27, 2025Remote tools allow data exfiltration without leaving a footprint or recognizable malware payload.
Vulnerability ManagementCritical Microsoft, Synacor zero-days face active exploitation, CISA saysLaura FrenchFebruary 26, 2025The flaws in Microsoft Partner Center and Synacor Zimbra Collaboration Suite were added to the KEV catalog.
Network SecurityOpenSSF sets baseline security standards for Linux-based softwareSteve ZurierFebruary 26, 2025New standards seen as a good move, but some worry it may breed complacency in security.
Vulnerability ManagementReport: 86% of codebases contain vulnerable open source componentsLaura FrenchFebruary 25, 2025One third of codebases analyzed by Black Duck were vulnerable to jQuery CVE-2020-11023 and CVE-2020-11022.
Threat ManagementResearchers pitch OCCULT for managing AI security threatsShaun NicholsFebruary 25, 2025A group of MITRE researchers have pitched a new standard for defining security threats from AI systems
Critical Infrastructure SecurityDragos: Attackers have moved beyond mere access and reconnaissanceSteve ZurierFebruary 25, 2025Dragos says OT has become a mainstream target – so expect more sophisticated attacks on critical infrastructure.
Modernizing federal hiring: Cutting bureaucracy, enhancing transparency, and strengthening the workforceErnest Kueffner February 27, 2025