This Week in Security: Target Coinbase, Leaking Call Records, and Microsoft Hotpatching

We know a bit more about the GitHub Actions supply chain attack from last month. Palo Alto’s Unit 42 has been leading the charge on untangling this attack, and they’ve …read more Continue reading This Week in Security: Target Coinbase, Leaking Call Records, and Microsoft Hotpatching

This Week in Security: The Github Supply Chain Attack, Ransomware Decryption, and Paragon

Last Friday Github saw a supply chain attack hidden in a popular Github Action. To understand this, we have to quickly cover Continuous Integration (CI) and Github Actions. CI essentially …read more Continue reading This Week in Security: The Github Supply Chain Attack, Ransomware Decryption, and Paragon

This Week in Security: The X DDoS, The ESP32 Basementdoor, and the camelCase RCE

We would be remiss if we didn’t address the X Distributed Denial of Service (DDoS) attack that’s been happening this week. It seems like everyone is is trying to make …read more Continue reading This Week in Security: The X DDoS, The ESP32 Basementdoor, and the camelCase RCE

This Week in Security: Zen Jailbreak, Telegram Exploit, and VMware Hyperjack

The fine researchers at Google have released the juicy details on EntrySign, the AMD Zen microcode issue we first covered about a month ago. And to give away the punchline: …read more Continue reading This Week in Security: Zen Jailbreak, Telegram Exploit, and VMware Hyperjack