Federal audit reveals NIST’s NVD is plagued by poor planning and duplication

A report from the Commerce Inspector General details how mismanagement allowed a backlog of 27,000 unprocessed security flaws to grow unchecked, while the agency duplicated work with a similar CISA program.

The post Federal audit reveals NIST’s NVD is plagued by poor planning and duplication appeared first on CyberScoop.

Continue reading Federal audit reveals NIST’s NVD is plagued by poor planning and duplication

Zapier fixes bug chain that researchers say risked widespread account takeover

A five-step flaw chain in the popular automation service, now patched, could have let a single attacker act as any signed-in user across thousands of connected apps.

The post Zapier fixes bug chain that researchers say risked widespread account takeover appeared first on CyberScoop.

Continue reading Zapier fixes bug chain that researchers say risked widespread account takeover

CrowdStrike disrupts Glassworm botnet that preyed on open-source supply chain

CrowdStrike has dismantled the Glassworm botnet in an operation aided by Google and Shadowserver, stripping the operators’ access to infrastructure that helped threat actors infect hundreds of pieces of open-source software with malware since early 2025, the company said Tuesday.  The coordinated effort involved the simultaneous takedown of four attacker-controlled servers that were designed to […]

The post CrowdStrike disrupts Glassworm botnet that preyed on open-source supply chain appeared first on CyberScoop.

Continue reading CrowdStrike disrupts Glassworm botnet that preyed on open-source supply chain

Apple open-sources quantum-resistant encryption code

The release includes implementations of two quantum-secure algorithms and demonstrates how formal verification caught bugs that traditional testing would have missed.

The post Apple open-sources quantum-resistant encryption code appeared first on CyberScoop.

Continue reading Apple open-sources quantum-resistant encryption code

Anthropic: Mythos finds more than 10,000 software flaws in first month

Early results show a tenfold jump in bug discovery at some partners, and a widening gap between finding flaws and fixing them.

The post Anthropic: Mythos finds more than 10,000 software flaws in first month appeared first on CyberScoop.

Continue reading Anthropic: Mythos finds more than 10,000 software flaws in first month

Lawmakers from both parties say CISA cuts have gone too far

Reps. Don Bacon, R-Neb., and James Walkinshaw, D-Va., found rare bipartisan agreement that the agency tasked with defending civilian networks has been diminished at a moment when threats from China and others are growing.

The post Lawmakers from both parties say CISA cuts have gone too far appeared first on CyberScoop.

Continue reading Lawmakers from both parties say CISA cuts have gone too far

The readiness paradox: Why a false sense of cyber confidence is becoming a liability

As AI expands the attack surface and alert fatigue grows, cyber exposure management offers a clearer path to understanding where risk truly concentrates and how to reduce it before a crisis hits.

The post The readiness paradox: Why a false sense of cyber confidence is becoming a liability appeared first on CyberScoop.

Continue reading The readiness paradox: Why a false sense of cyber confidence is becoming a liability

GitHub says internal repositories were taken in poisoned VS Code extension attack

GitHub said late Tuesday that internal repositories were exfiltrated after an employee device was compromised through a poisoned Visual Studio Code extension, an incident that underscores the growing risks facing software development platforms and the ecosystems built around third-party developer tools. The Microsoft-owned company said in posts on X that it detected and contained the […]

The post GitHub says internal repositories were taken in poisoned VS Code extension attack appeared first on CyberScoop.

Continue reading GitHub says internal repositories were taken in poisoned VS Code extension attack

Mini Shai-Hulud returns, compromising hundreds of npm packages

Another malware wave is washing through open-source software repos, stealing publishing tokens, installing OS‑level backdoors and persisting in developer tools and CI pipelines.

The post Mini Shai-Hulud returns, compromising hundreds of npm packages appeared first on CyberScoop.

Continue reading Mini Shai-Hulud returns, compromising hundreds of npm packages

The Canvas breach proved that prevention is no longer enough

Cybercriminals brought down the most widely used learning platform in North America. The Canvas breach is a blueprint for how SaaS attacks now work — and a warning about how unprepared most organizations still are.

The post The Canvas breach proved that prevention is no longer enough appeared first on CyberScoop.

Continue reading The Canvas breach proved that prevention is no longer enough