Building a Security Champions Program That Actually Works

Building a Security Champions Program That Actually Works

If you’ve been in AppSec for a while, you’ve probably heard of Security Champions. Maybe you’ve even tried to implement a program. But here’s the thing – most of these programs fail within the first year. Today, we’re going to tell you...

DDoS Attack Hits Record Breaking 5.6Tbps

https://blog.cloudflare.com/ddos-threat-report-for-2024-q4 Cloudflare has mitigated the largest DDoS attack ever recorded, peaking at a staggering 5.6 terabits per second (Tbps).1 This UDP-based attack, launched by a Mirai-based botnet of over 13,000 compromised...

Stealthy WordPress Skimmers Infiltrate Database Tables

Stealthy Credit Card Skimmer Targets WordPress Checkout Pages via Database Injection Cybersecurity researchers have uncovered a new wave of credit card skimmers targeting WordPress e-commerce sites. This campaign injects malicious JavaScript into the wp_options table...

Fake CrowdStrike Job Offers Used to Distribute Cryptominer

https://www.crowdstrike.com/en-us/blog/recruitment-phishing-scam-imitates-crowdstrike-hiring-process Cybercriminals are targeting developers with a new phishing campaign that impersonates CrowdStrike, a cybersecurity company. The campaign tricks victims into...

Phishing Texts Trick iMessage Users into Disabling Security

https://www.bleepingcomputer.com/news/security/phishing-texts-trick-apple-imessage-users-into-disabling-protection Cybercriminals are employing a new tactic in their smishing (SMS phishing) campaigns: tricking Apple iMessage users into replying to texts, thereby...