Cybersecurity Needs to Start Saying ‘No’ Again

https://www.darkreading.com/cyber-risk/security-needs-start-saying-no-again For years, cybersecurity teams were often perceived as the “Department of No,” constantly blocking initiatives due to security concerns. However, in an effort to demonstrate value...
Hundreds of Fake Reddit Sites Push Lumma Stealer Malware

Hundreds of Fake Reddit Sites Push Lumma Stealer Malware

https://www.bleepingcomputer.com/news/security/hundreds-of-fake-reddit-sites-push-lumma-stealer-malware Cybercriminals are leveraging hundreds of fake Reddit and WeTransfer websites to distribute the Lumma Stealer malware. These deceptive websites mimic the appearance...

Subaru Flaw Could Have Let Hackers Track and Control Vehicles

https://samcurry.net/hacking-subaru A critical security vulnerability in Subaru’s Starlink service could have allowed attackers to remotely control and track vehicles in the United States, Canada, and Japan. The flaw, discovered by security researchers Sam Curry...

MasterCard DNS Misconfiguration Exposed for Years

https://krebsonsecurity.com/2025/01/mastercard-dns-error-went-unnoticed-for-years A critical error in MasterCard’s domain name system (DNS) configuration went unnoticed for nearly five years. This misconfiguration could have allowed attackers to intercept or...
Building a Security Champions Program That Actually Works

Building a Security Champions Program That Actually Works

If you’ve been in AppSec for a while, you’ve probably heard of Security Champions. Maybe you’ve even tried to implement a program. But here’s the thing – most of these programs fail within the first year. Today, we’re going to tell you...

DDoS Attack Hits Record Breaking 5.6Tbps

https://blog.cloudflare.com/ddos-threat-report-for-2024-q4 Cloudflare has mitigated the largest DDoS attack ever recorded, peaking at a staggering 5.6 terabits per second (Tbps).1 This UDP-based attack, launched by a Mirai-based botnet of over 13,000 compromised...