Latest Tech News

Stay updated with the latest in technology, AI, cybersecurity, and more

Filtered by: compromise Clear Filter

Self-propagating supply chain attack hits 187 npm packages

Security researchers have identified at least 187 npm packages compromised in an ongoing supply chain attack, with a malicious self-propagating payload to infect other packages. The coordinated worm-style campaign dubbed 'Shai-Hulud' started yesterday with the compromise of the @ctrl/tinycolor npm package, which receives over 2 million weekly downloads. Since then, the campaign has expanded significantly and now includes packages published under CrowdStrike's npm namespace. From tinycolor to

Formula E cars keep getting faster and faster: What’s next for the sport?

In addition to being bigger and heavier, teams are also going to have high- and low-downforce configurations. Racing drivers will always want more grip, but the addition of aerodynamics to push cars down onto the track surface can fundamentally change the racing, and not always in a way that makes for an entertaining spectacle for the audience. That said, Formula E isn’t adding downforce to Gen 4 just because. Change is never easy "This was a hot topic. No mitigation: car performance, car perf

Formula E wraps up season 11—where does the all-EV series go next?

In addition to being bigger and heavier, teams are also going to have high- and low-downforce configurations. Racing drivers will always want more grip, but the addition of aerodynamics to push cars down onto the track surface can fundamentally change the racing, and not always in a way that makes for an entertaining spectacle for the audience. That said, Formula E isn’t adding downforce to Gen 4 just because. Change is never easy "This was a hot topic. No mitigation: car performance, car perf

US nuclear weapons agency reportedly hacked in SharePoint attacks

Unknown threat actors have reportedly breached the National Nuclear Security Administration's network in attacks exploiting a recently patched Microsoft SharePoint zero-day vulnerability chain. NNSA is a semi-autonomous U.S. government agency part of the Energy Department that maintains the country's nuclear weapons stockpile and is also tasked with responding to nuclear and radiological emergencies within the United States and abroad. A Department of Energy spokesperson confirmed in a stateme

NPM package ‘is’ with 2.8M weekly downloads infected devs with malware

The popular NPM package 'is' has been compromised in a supply chain attack that injected backdoor malware, giving attackers full access to compromised devices. This occurred after maintainer accounts were hijacked via phishing, followed by unauthorized owner changes that went unnoticed for several hours, potentially compromising many developers who downloaded the new releases. The 'is' package is a lightweight JavaScript utility library that provides a wide variety of type checking and value v

New Research Shows Data Breaches Keep Coming. Here's How to Protect Yourself

The personal data of Americans continues to be under threat from cybercriminals looking to steal it for their own financial gain, according to a new report from the Identity Theft Resource Center. The nonprofit group, which focuses on helping victims of identity theft, said Wednesday that 1,732 data compromises were reported for the first six months of this year, resulting in 165.7 million victim notifications. The number of reported compromises represents an 11% increase from the same period

Actively exploited vulnerability gives extraordinary control over server fleets

Hackers are exploiting a maximum-severity vulnerability that has the potential to give them complete control over thousands of servers, many of which handle mission-critical tasks inside data centers, the US Cybersecurity and Infrastructure Security Agency is warning. The vulnerability, carrying a severity rating of 10 out of a possible 10, resides in the AMI MegaRAC, a widely used firmware package that allows large fleets of servers to be remotely accessed and managed even when power is unavai

Active exploitation of AMI management tool imperils thousands of servers

Hackers are exploiting a maximum-severity vulnerability that has the potential to give them complete control over thousands of servers, many of which handle mission-critical tasks inside data centers, the US Cybersecurity and Infrastructure Security Agency is warning. The vulnerability, carrying a severity rating of 10 out of a possible 10, resides in the AMI MegaRAC, a widely used firmware package that allows large fleets of servers to be remotely accessed and managed even when power is unavai

Keylogger campaign hitting Outlook Web Access on vulnerable Exchange servers goes global

Serving tech enthusiasts for over 25 years.TechSpot means tech analysis and advice you can trust Facepalm: Keylogging malware is a particularly dangerous threat, as it is typically designed to capture login credentials or other sensitive data from users. When you add a compromised Exchange server to the mix, it creates an even nastier situation for any organization. Researchers from Positive Technologies recently unveiled a new study on a keylogger-based campaign targeting organizations worldw

Keylogger campaign hitting Microsoft Exchange servers goes global

Serving tech enthusiasts for over 25 years.TechSpot means tech analysis and advice you can trust Facepalm: Keylogging malware is a particularly dangerous threat, as it is typically designed to capture login credentials or other sensitive data from users. When you add a compromised Exchange server to the mix, it creates an even nastier situation for any organization. Researchers from Positive Technologies recently unveiled a new study on a keylogger-based campaign targeting organizations worldw

Scania confirms insurance claim data breach in extortion attempt

Automotive giant Scania confirmed it suffered a cybersecurity incident where threat actors used compromised credentials to breach its Financial Services systems and steal insurance claim documents. Scania told BleepingComputer that the attackers emailed several Scania employees, threatening to leak the data online unless their demands were met. Scania is a major Swedish manufacturer of heavy trucks, buses, and industrial and marine engines and is a member of the Volkswagen Group. The company,