It's almost time for our #AMA livestream! Join Principal Security Consultant @H3xxEdit tomorrow at 11:00 AM live on Discord or YouTube for a conversation on building realistic tabletop exercises that actually prepare your team. Bring your questions!
https://t.co/dqJ8WPocMw
Come join me on Talkin' bout INFOSEC today at 4:30
@everyone <@&1114982637480714270> <@&1186544536856576030>
Join us for this week's infosec-news stories with the Black Hills Infosec team live at 4:30pm ET on Mondays -- https://t.co/Nhp8hyi7SU
Preparation is everything when it comes to incident response. Join us on May 21 at 11am ET for an exclusive livestream AMA on IR tabletop exercises with @H3xxEdit. Ask your questions live on Discord and YouTube!
https://t.co/mW22ujknlM
New breach: Vimeo was named in a ShinyHunters extortion campaign following a compromise of the Anodot analytics service. The incident exposed hundreds of gigabytes of data, including 119k unique email addresses. 56% were already in @haveibeenpwned. More: https://t.co/eXznKDS80Y
Microsoft Threat Intelligence has attributed the Axios npm supply chain attack to North Korean state actor Sapphire Sleet. Malicious npm packages for updated versions of Axios (1.14.1 and 0.30.4) downloaded payloads from command and control attributed to Sapphire Sleet.https://t.co/kTKCHm9uZB
Organizations affected by this attack are urged to roll back to safe versions (1.14.0 or 0.30.3 or earlier), rotate secrets and credentials that are exposed to compromised systems, and disable auto-updates. Our latest blog has our analysis of the attack, additional mitigation recommendations, and Microsoft Defender detection and hunting guidance:
A phishing campaign is abusing an official device code OAuth flow. Instead of stealing passwords, attackers trick you into entering a verification code on the real login page to hijack OAuth tokens. This grants long-term access to email and files. Details: https://t.co/bnR9kg4cSy
Check to see if you have these extensions loaded in your environment:
Live Server, Code Runner, Markdown Preview Enhanced, or Microsoft Live Preview. They have critical flaws that might allow attacker access to your system or network. More details here:
https://t.co/Nov84VtXlW
🚨 Update Your iPhone Now — Apple Releases Emergency Security Patch — Daily Mail
Apple has issued an urgent iOS update after warning about a serious security threat. The newly released iOS 26.3 fixes 39 vulnerabilities that could potentially allow attackers to access users’ personal data or even gain partial control of a device.
According to security reports, some of the flaws may have been actively exploited in targeted attacks. That’s why Apple is urging users to install the update as soon as possible.
If automatic updates are turned off, go to Settings → General → Software Update and check manually.
One of the biggest impacts of AI that goes kind of unnoticed is that we’re about to see an explosion of poorly built applications.
Specifically, applications built completely by AI with no thought of security whatsoever.
🧵
IT'S TIME!!! Submit your presentations for consideration to present at the 2025 BSides Tampa happening May 16-17! Excited to see what presentations you all submit! https://t.co/OjaVGiHJXX