720-891-1663

Poisoned Open Source and the Future of Supply Chain Attacks

Two supply chain attacks last month infected open source tools with malware and used them to steal secrets from tens of thousands of organizations. These tools are integrated silently into software that an unknown number of users use. One of them is Trivy, a vulnerability scanner that is integrated into thousands (or more) of development […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Russian Hackers Go After Home Routers to Hijack Internet Traffic

UK security officials warned that Russian military intelligence has been (as in actually occurring now) compromising vulnerable home Internet routers to hijack web traffic and spy on home users. They say this is a broad and ongoing cyberespionage campaign. Why? Because home and small business users do not have the expertise and so they are […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Critical Claude Bug Discovered After Code Accidentally Released

It is old news (as in 3 days old) that Anthropic, maker of Claude, accidentally included hundreds of thousands of source code when they included an internal file in a public release. That file was only meant for internal use. That, by itself, is embarrassing but not catastrophic. It certainly helps hackers look for bugs, […]

Continue reading → [DISPLAY_ACURAX_ICONS]