A cybersecurity startup is warning of a major, unattended weak link in the software supply chain: the vexing problem of valuable corporate secrets — API keys, usernames and passwords, and security certificates — publicly exposed in corporate repositories.
‘Serpent’ Backdoor Used in Malware Attacks on French Entities
French organizations in the construction, government, and real estate sectors have been targeted with a new backdoor in a string of malware attacks, according to a warning from Proofpoint.
QNAP Devices Targeted in New Wave of DeadBolt Ransomware Attacks
Internet search engine Censys on Monday warned that a new wave of DeadBolt ransomware attacks has been targeting network-attached storage (NAS) devices made by QNAP.
Application Security Firm ForAllSecure Raises $21 Million
Application security testing firm ForAllSecure this week announced that it has closed a $21 million Series B investment round that brings the total raised by the company to $36 million.
The funding round was co-led by Koch Disruptive Technologies (KDT) and New Enterprise Associates (NEA).
Over 1 Million Impacted in Data Breach at Texas Dental Services Provider
Dental and orthodontic care provider JDC Healthcare Management (JDC) has revealed that the information of a large number of Texans was compromised in a data breach discovered last year.
High-Severity UEFI Vulnerabilities Patched in Dell Enterprise Laptops
Firmware security company Binarly this week disclosed the details of several vulnerabilities that impact the Unified Extensible Firmware Interface (UEFI) of multiple Dell enterprise laptop models.
Microsoft, Okta Investigating Data Theft Claims
Microsoft has launched an investigation after a hacker group claimed to have stolen the source code of some of the tech giant’s products.
SSE Company Skyhigh Security Emerges From McAfee Enterprise
Private equity giant Symphony Technology Group (STG) on Tuesday announced the launch of a new security service edge (SSE) company named Skyhigh Security.
Hotels in Macau Targeted in Attacks Linked to South Korea’s DarkHotel APT
The South Korea-linked state-sponsored threat actor DarkHotel is believed to have conducted a series of recent attacks targeting major hotel chains in Macau, according to Trellix, an XDR company launched earlier this year following the merger of McAfee Enterprise and FireEye.













