Thousands of Secrets Leaked on Code Formatting Platforms

JSONFormatter and CodeBeautify users exposed credentials, authentication keys, configuration information, private keys, and other secrets.
The post Thousands of Secrets Leaked on Code Formatting Platforms appeared first on SecurityWeek.
Continue reading Thousands of Secrets Leaked on Code Formatting Platforms

Alumni, Student, and Staff Information Stolen From Harvard University

A phone phishing attack led to the compromise of a system containing information about alumni, donors, students, staff, and other individuals.
The post Alumni, Student, and Staff Information Stolen From Harvard University appeared first on SecurityWeek.
Continue reading Alumni, Student, and Staff Information Stolen From Harvard University

Fluent Bit Vulnerabilities Expose Cloud Services to Takeover

Five flaws in the open source tool may lead to path traversal attacks, remote code execution, denial-of-service, and tag manipulation.
The post Fluent Bit Vulnerabilities Expose Cloud Services to Takeover appeared first on SecurityWeek.
Continue reading Fluent Bit Vulnerabilities Expose Cloud Services to Takeover

640 NPM Packages Infected in New ‘Shai-Hulud’ Supply Chain Attack

The new self-replicating worm iteration has destructive capabilities, erasing home directory contents if it cannot spread to more repositories.
The post 640 NPM Packages Infected in New ‘Shai-Hulud’ Supply Chain Attack appeared first on Sec… Continue reading 640 NPM Packages Infected in New ‘Shai-Hulud’ Supply Chain Attack

Microsoft Highlights Security Risks Introduced by New Agentic AI Feature

Without proper security controls, AI agents could perform malicious actions, such as data exfiltration and malware installation.
The post Microsoft Highlights Security Risks Introduced by New Agentic AI Feature appeared first on SecurityWeek.
Continue reading Microsoft Highlights Security Risks Introduced by New Agentic AI Feature