+ Most pandemic-era ransomware raids conducted by two gangs; Cert authority issued multiple rogue TLS credentials for Cloudflare DNS; and more
Can't view this message? Click here to view it online.
iTnews

WEEKLY SECURITY WRAP

Tuesday September 9, 2025

  Security  

Phishing attack nets enormous npm supply chain compromise

Developers targeted in new hacking campaign.

By Juha Saarinen

 

Latest Security News


Most pandemic-era ransomware raids conducted by two gangs
  Security  

Most pandemic-era ransomware raids conducted by two gangs

Criminals evolve into professional as-a-service operators.

By Juha Saarinen

 
Cert authority issued multiple rogue TLS credentials for Cloudflare DNS
  Security  

Cert authority issued multiple rogue TLS credentials for Cloudflare DNS

Internal testing brought on external failures.

By Juha Saarinen

 
How North Korean hackers are using fake job offers to steal cryptocurrency
  Security  

How North Korean hackers are using fake job offers to steal cryptocurrency

At least 230 victims of 'Contagious Interview' threat identified.

By AJ Vicens and Raphael Satter

 
Salesloft hacked via GitHub and AWS in March, Mandiant finds
  Security  

Salesloft hacked via GitHub and AWS in March, Mandiant finds

Incident root cause clarified.

By Juha Saarinen

 
Academic researchers created AI-powered "PromptLock" ransomware
  Security  

Academic researchers created AI-powered "PromptLock" ransomware

Shows why AI-enabled threats should be taken seriously, engineers say.

By Juha Saarinen

 
 
 
 
Melbourne dev finds gift card PINs can be brute-forced
  Security  

Melbourne dev finds gift card PINs can be brute-forced

Cards sold at supermarkets open to redemption robbery.

By Juha Saarinen

 
Agentic cyber security AI abused for Citrix Netscaler attacks
  Security  

Agentic cyber security AI abused for Citrix Netscaler attacks

Check Point listens in on "dark web chatter".

By Juha Saarinen

 
Researchers detail novel cryptomining attack
  Security  

Researchers detail novel cryptomining attack

Targets retail and ecommerce.

By Juha Saarinen

 
Jaguar Land Rover hit by cyber incident
  Security  

Jaguar Land Rover hit by cyber incident

Disrupts production, sales.

By Staff Writer

 
VicRoads to phase out passwords in favour of passkeys
  Security  

VicRoads to phase out passwords in favour of passkeys

Plans to mandate passkey adoption by end of this year.

By Eleanor Dickinson

 
Service NSW centralises security, networking in mammoth CloudOps overhaul
  Cloud  

Service NSW centralises security, networking in mammoth CloudOps overhaul

Undertakes significant cost optimisation program.

By Eleanor Dickinson

 
 
 
 

Featured whitepaper


 
 

MOST POPULAR


Melbourne dev finds gift card PINs can be brute-forced
  Security  

Melbourne dev finds gift card PINs can be brute-forced

By Juha Saarinen

Service NSW centralises security, networking in mammoth CloudOps overhaul
  Cloud  

Service NSW centralises security, networking in mammoth CloudOps overhaul

By Eleanor Dickinson

Department of Health to centralise SecOps model
  Security  

Department of Health to centralise SecOps model

By Eleanor Dickinson

Jaguar Land Rover hit by cyber incident
  Security  

Jaguar Land Rover hit by cyber incident

By Staff Writer

Zero-click Apple and WhatsApp bug combo used to drop gov spyware
  Security  

Zero-click Apple and WhatsApp bug combo used to drop gov spyware

By Juha Saarinen

 
 
unsubscribe