In The News
January 31, 2023

Three lessons for DevOps from the CircleCI breach

For development teams that are still struggling to dig out from the mess caused by the hack of CircleCI in December, recent days brought some good news.
January 17, 2023

Mitigating the North Korean Cybersecurity Threat

Cybersecurity firm Kaspersky recently published an analysis that detailed how a North Korean threat actor, which it called the BlueNoroff group, is stealing cryptocurrency by bypassing the “Mark of the Web” flag security feature within the Windows operating system.
January 13, 2023

Deserialized web security roundup – Slack and Okta breaches, lax US government passwords report, and more

Slack suffered a security breach recently, “involving unauthorized access to a subset of Slack’s code repositories” according to the messaging platform.
January 10, 2023

Supply Chain Security: A Closer Look at the IconBurst and Material Tailwind Attacks

Earlier this month, ReversingLabs published a report on the current state of software supply chain security.
December 19, 2022

Dark Reading: Malicious Python Trojan Impersonates SentinelOne Security Client

A fully functional SentinelOne client is actually a Trojan horse that hides malicious code within; it was found lurking in the Python Package Index repository ecosystem.
December 19, 2022

SecurityWeek: Malicious PyPI Module Poses as SentinelOne SDK

Security researchers with ReversingLabs warn of a new supply chain attack using a malicious PyPI module that poses as a software development kit (SDK) from the cybersecurity firm SentinelOne.