GitHub rushed to fix a critical vulnerability in less than six hours
GitHub rushed to fix a critical vulnerability in less than six hours

GitHub employees fixed a critical remote code execution vulnerability in less than six hours last month. Wiz Research used AI models to uncover a vulnerability in GitHub’s internal git infrastructure that could have allowed attackers to access millions of public and private code repositories. “Our security team immediately began validating the bug bounty report. Within […]

‘The attacker completed in under five minutes’: Experts warn of North Korea-linked campaign using fake Zoom meetings to target crypto execs

Highly sophisticated scam will leave you questioning what’s real while hackers steal your crypto.

Why Sharing a Screenshot Can Get You Jailed in the UAE

The war in Iran has drawn attention to arrests in the United Arab Emirates over online content, but the legal framework behind that enforcement has existed for years.

Paragon is not collaborating with Italian authorities probing spyware attacks, report says

Despite promising to help determine what happened with the hacks targeting journalists and activists in Italy, Israeli American spyware maker Paragon has reportedly not responded to authorities’ requests for information.

‘The data should be a wake-up call’: Report finds cybersecurity workers feel underpaid, undervalued and overstressed — and that’s putting everyone at risk

Shifting demands for AI skills plus its impact on security is putting cybersecurity workers in stressful positions.

US Supreme Court appears split over controversial use of ‘geofence’ search warrants

The U.S. top court is expected to rule on whether to allow police to identify criminal suspects by dragnet searching the databases of tech giants.

Hackers exploit Robinhood account creation tool to launch worrying phishing scam

The vulnerability has since been fixed and the malicious landing page is offline.

Top open source PyPI package with over 1 million downloads each month hacked to send out malware

This was not a case of stolen credentials, but rather of vulnerability exploitation.

CheckMarx admits it was hit by major cyberattack that saw data leaked onto Dark Web

CheckMarx confirms March 2026 attack did result in data theft.