GitHub Warns of Private Repositories Downloaded Using Stolen OAuth Tokens

github-warns-of-private-repositories-downloaded-using-stolen-oauth-tokens

GitHub has sounded the alarm on a cyberattack that resulted in the private repositories of dozens of organizations being downloaded by an unauthorized party abusing stolen OAuth user tokens.

The incident was identified on April 12, when the code hosting platform observed suspicious activity on its npm production infrastructure.

read more

Cloud Security Startup DoControl Raises $30 Million

cloud-security-startup-docontrol-raises-$30-million

Cloud data security startup DoControl has closed a $30 million Series B funding round that brings the total raised by the company to $43 million.

The financing round was led by Insight Partners, with additional investments from Cardumen Capital, CrowdStrike Falcon Fund, RTP Global, and StageOne Ventures.

read more

Energy Provider in Ukraine Targeted With Industroyer2 ICS Malware

energy-provider-in-ukraine-targeted-with-industroyer2-ics-malware

An energy provider in Ukraine was recently targeted with a new piece of malware designed to cause damage by manipulating industrial control systems (ICS).

The attack, which targeted high-voltage electrical substations, has been analyzed by Ukraine’s Computer Emergency Response Team (CERT-UA), cybersecurity firm ESET, and Microsoft.

read more