Attackers hijacked top-level domains, minted fake security certs for Google and other orgs
Imagine going to a Google website at its correct URL, only to be redirected to a crim’s illegitimate copy. Attackers hijacked top-level domains, allowing them to alter DNS records and…
US states sue popular kitmaker TP-Link over China risks
The attorneys general of Florida, Iowa, Montana, and Nebraska have sued ubiquitous networking and smart home tech maker TP-Link, alleging its security claims were misleading and it hadn’t properly disclosed…
AWS’ support for Iceberg materialized views on Redshift could help lower analytics costs
AWS has added support for Iceberg materialized views to its managed cloud data warehouse service, Amazon Redshift, in an effort to help enterprises lower analytics costs. Materialized views are precomputed,…
Encrypted instructions trick Copilot CLI into spilling developer secrets
GitHub Copilot CLI can be made to read sensitive files from a developer’s machine and send their contents to an attacker from a single web page. Security researchers at Adversa…
FortiBleed still a bleeding nuisance as FBI confirms ongoing attacks
The FBI and US Secret Service (USSS) say criminals using credentials linked to the FortiBleed campaign are locking organizations out of their Fortinet firewalls. The agencies published a joint advisory…
