Category: DarkReading

Office Of Inspector General (OIG) Finds VDP Not Effective
26
Nov
2025

Office Of Inspector General (OIG) Finds VDP Not Effective

The Department of Commerce’s vulnerability disclosure program (VDP), designed to protect its public-facing information technology systems, has been deemed “not…

Account Takeover Fraud Sees Sharp Spike, FBI Alerts Public
26
Nov
2025

Account Takeover Fraud Sees Sharp Spike, FBI Alerts Public

The Account Takeover fraud threat is accelerating across the United States, prompting the Federal Bureau of Investigation (FBI) to issue…

Code Formatting Tools Share Secrets By The Thousands
25
Nov
2025

Code Formatting Tools Share Secrets By The Thousands

Platforms that developers use to format their input unintentionally share “thousands” of secrets, according to new research. Researchers from watchTowr…

Apache Syncope CVE-2025-65998 Exposes AES Passwords
25
Nov
2025

Apache Syncope CVE-2025-65998 Exposes AES Passwords

A critical security flaw has been uncovered in Apache Syncope, the widely used open-source identity management system, potentially putting organizations…

SitusAMC Data Breach Exposes Corporate Information
25
Nov
2025

SitusAMC Data Breach Exposes Corporate Information

SitusAMC, a major provider of back-end services for leading banks and lenders, has confirmed a SitusAMC data breach that resulted…

New Shai-Hulud Attack Hits Nearly 500 npm Packages with 100+ Million Downloads
24
Nov
2025

New Shai-Hulud Attack Hits Nearly 500 Npm Packages

A new Shai-Hulud supply chain attack has hit nearly 500 npm packages with a total of 132 million monthly downloads….

Oracle Identity Manager vulnerability RCE code
24
Nov
2025

CISA Adds Oracle Identity Manager Vulnerability To KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added an Oracle Identity Manager vulnerability to its Known Exploited Vulnerabilities…

CBI, CBI Dismantles Cybercrime, Cybercrime, FBI, Online Fraud, Call Center Scam, Cybercrime Kingpin
24
Nov
2025

CBI Arrests Fugitive Cybercrime Kingpin Running Fraud Call Centres

Indian authorities recovered Rs. 14 lakh (approximately $16,500) along with 52 laptops containing incriminating digital evidence when they arrested Vikas…

Grafana Flags Critical SCIM Vulnerability CVE-2025-41115
24
Nov
2025

Grafana Flags Critical SCIM Vulnerability CVE-2025-41115

Grafana Labs has issued a warning regarding a maximum-severity security flaw, identified as CVE-2025-41115, affecting its Enterprise product. The vulnerability…

CrowdStrike Fires Suspicious Insider Linked To Hackers
24
Nov
2025

CrowdStrike Fires Suspicious Insider Linked To Hackers

Cybersecurity firm CrowdStrike confirmed the termination of a “suspicious insider” who allegedly shared internal information with hackers. The move came…

Scattered Spider Teens Plead Not Guilty In UK Court
21
Nov
2025

Scattered Spider Teens Plead Not Guilty In UK Court

Two alleged members of the Scattered Spider threat group pled not guilty today to charges related to a cyberattack on…

Android Malware Records Encrypted Messages, Hijacks Devices
21
Nov
2025

Android Malware Records Encrypted Messages, Hijacks Devices

Security researchers have identified a new Android banking trojan that does much more than steal banking credentials. It can also…