Derek B. Johnson
08
Sep
2025

Supreme Court blocks FTC commissioner Slaughter’s reinstatement

Rebecca Slaughter’s return-to-work orders have been put on hold for the second time this year, after the U.S. Supreme Court…

Dozens of malicious packages on NPM collect host and network data
08
Sep
2025

Hackers hijack npm packages with 2 billion weekly downloads in supply chain attack

In what is being called the largest supply chain attack in history, attackers have injected malware into NPM packages with…

Progress OpenEdge AdminServer Vulnerability Let Attackers Execute Remote Code
08
Sep
2025

Progress OpenEdge AdminServer Vulnerability Let Attackers Execute Remote Code

A critical security vulnerability has been discovered in Progress OpenEdge, a platform for developing and deploying business applications. The flaw,…

npm Packages With 2 Billion Weekly Downloads Hacked in Major Attack
08
Sep
2025

npm Packages With 2 Billion Weekly Downloads Hacked in Major Attack

Aikido Security flagged the largest npm attack ever recorded, with 18 packages like chalk, debug, and ansi-styles hacked to hijack…

GitHub Account Compromise Led to Salesloft Drift Breach Affecting 22 Companies
08
Sep
2025

GitHub Account Compromise Led to Salesloft Drift Breach Affecting 22 Companies

Sep 08, 2025Ravie LakshmananSupply Chain Attack / API Security Salesloft has revealed that the data breach linked to its Drift…

Cyber Lock
08
Sep
2025

A Better Approach to Modern Patch Management

Windows Server Update Services (WSUS) has been a go-to patch management tool for over two decades, providing IT administrators with…

Qualys Confirms Data Breach - Hackers Accessed Salesforce Data in Supply Chain Attack
08
Sep
2025

Qualys Confirms Data Breach – Hackers Accessed Salesforce Data in Supply Chain Attack

Qualys has confirmed it was impacted by a widespread supply chain attack that targeted the Salesloft Drift marketing platform, resulting…

The Lock and Code logo, which includes the Malwarebytes Labs insignia ensconced in a pair of headphones
08
Sep
2025

This “insidious” police tech claims to predict crime (Lock and Code S06E18)

This week on the Lock and Code podcast… In the late 2010s, a group of sheriffs out of Pasco County,…

Salesloft Drift integration restored after probe reveals monthslong GitHub account compromise
08
Sep
2025

Salesloft Drift integration restored after probe reveals monthslong GitHub account compromise

Salesloft said it has restored the integration between its Drift platform and Salesforce after an investigation by Mandiant linked an…

Data breach
08
Sep
2025

March GitHub repo breach led to Salesforce data theft attacks

Salesloft says attackers first breached its GitHub account in March, leading to the theft of Drift OAuth tokens later used…

Exposed 'Kim' Dump Exposes Kimsuky Hackers New Tactics, Techniques, and Infrastructure
08
Sep
2025

Exposed ‘Kim’ Dump Exposes Kimsuky Hackers New Tactics, Techniques, and Infrastructure

A massive data breach in early September 2025 attributed to a cyber actor known simply as “Kim” laid bare an…

Zero-Day in Sitecore Exploited to Deploy WEEPSTEEL Malware
08
Sep
2025

Zero-Day in Sitecore Exploited to Deploy WEEPSTEEL Malware

A critical zero-day vulnerability (CVE-2025-53690) is being actively exploited in Sitecore. This flaw, originating from old, insecure keys, allows hackers…