Uncategorized

Trivy Supply Chain Attack Triggers Self-Spreading CanisterWorm Across 47 npm Packages

Trivy Supply Chain Attack Triggers Self-Spreading CanisterWorm Across 47 npm Packages 2026-03-21 at 13:44 By The threat actors behind the supply chain attack targeting the popular Trivy scanner are suspected to be conducting follow-on attacks that have led to the compromise of a large number of npm packages with a previously undocumented self-propagating worm dubbed […]

Trivy Supply Chain Attack Triggers Self-Spreading CanisterWorm Across 47 npm Packages Read More »

CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026

CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026 2026-03-21 at 13:44 By The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added five security flaws impacting Apple, Craft CMS, and Laravel Livewire to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch them by April

CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026 Read More »

Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager

Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager 2026-03-21 at 12:24 By Oracle has released security updates to address a critical security flaw impacting Identity Manager and Web Services Manager that could be exploited to achieve remote code execution. The vulnerability, tracked as CVE-2026-21992, carries a CVSS score of 9.8 out of a

Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager Read More »

Payment biz pulls plug on open source charity after KYC spat

Payment biz pulls plug on open source charity after KYC spat 2026-03-21 at 11:30 By Liam Proven Free Software Foundation Europe says it was asked for supporters’ passwords; Nexi insists it only wanted test credentials to check cancellation flows The Free Software Foundation Europe says its electronic-payments provider Nexi Group unexpectedly “cancelled” its account –

Payment biz pulls plug on open source charity after KYC spat Read More »

Cryptographers engage in war of words over RustSec bug reports and subsequent ban

Cryptographers engage in war of words over RustSec bug reports and subsequent ban 2026-03-21 at 02:52 By Thomas Claburn Rust security maintainers contend Nadim Kobeissi’s vulnerability claims are too much Since February, cryptographer Nadim Kobeissi has been trying to get code fixes applied to Rust cryptography libraries to address what he says are critical bugs.

Cryptographers engage in war of words over RustSec bug reports and subsequent ban Read More »

Sorry, Amazon, you couldn’t pick a worse time to bring a phone to market: IDC analyst

Sorry, Amazon, you couldn’t pick a worse time to bring a phone to market: IDC analyst 2026-03-21 at 02:52 By O’Ryan Johnson The market is contracting Right product, wrong time? Amazon is reported to be developing a new smartphone, its first since 2014, and, according to industry tracker IDC, it will face entrenched competition with

Sorry, Amazon, you couldn’t pick a worse time to bring a phone to market: IDC analyst Read More »

Salesforce snaps up the team who built calendar app Clockwise to work on Agentforce

Salesforce snaps up the team who built calendar app Clockwise to work on Agentforce 2026-03-20 at 21:16 By O’Ryan Johnson Just the team, not the tech Salesforce’s Agentforce team is getting an infusion of new talent by hiring the team behind Clockwise, a calendar scheduling app, but the app itself isn’t sticking around.… This article

Salesforce snaps up the team who built calendar app Clockwise to work on Agentforce Read More »

Trivy Security Scanner GitHub Actions Breached, 75 Tags Hijacked to Steal CI/CD Secrets

Trivy Security Scanner GitHub Actions Breached, 75 Tags Hijacked to Steal CI/CD Secrets 2026-03-20 at 21:16 By Trivy, a popular open-source vulnerability scanner maintained by Aqua Security, was compromised a second time within the span of a month to deliver malware that stole sensitive CI/CD secrets. The latest incident impacted GitHub Actions “aquasecurity/trivy-action” and “aquasecurity/setup-trivy,”

Trivy Security Scanner GitHub Actions Breached, 75 Tags Hijacked to Steal CI/CD Secrets Read More »

Google Adds 24-Hour Wait for Unverified App Sideloading to Reduce Malware and Scams

Google Adds 24-Hour Wait for Unverified App Sideloading to Reduce Malware and Scams 2026-03-20 at 19:32 By Google on Thursday announced a new “advanced flow” for Android sideloading that requires a mandatory 24-hour wait period to install apps from unverified developers in an attempt to balance openness with safety. The new changes come against the

Google Adds 24-Hour Wait for Unverified App Sideloading to Reduce Malware and Scams Read More »

Starship may chauffeur Orion to the Moon, as NASA mulls ditching SLS after Artemis V

Starship may chauffeur Orion to the Moon, as NASA mulls ditching SLS after Artemis V 2026-03-20 at 18:21 By Richard Speed SpaceX’s still-not-quite-orbital rocket tapped as lunar taxi. Musk’s minicab anyone? NASA is reportedly considering using SpaceX’s Starship to transport the Orion capsule to the Moon, with some sources calling it a done deal.… This

Starship may chauffeur Orion to the Moon, as NASA mulls ditching SLS after Artemis V Read More »

Critical Langflow Flaw CVE-2026-33017 Triggers Attacks within 20 Hours of Disclosure

Critical Langflow Flaw CVE-2026-33017 Triggers Attacks within 20 Hours of Disclosure 2026-03-20 at 17:15 By A critical security flaw impacting Langflow has come under active exploitation within 20 hours of public disclosure, highlighting the speed at which threat actors weaponize newly published vulnerabilities. The security defect, tracked as CVE-2026-33017 (CVSS score: 9.3), is a case

Critical Langflow Flaw CVE-2026-33017 Triggers Attacks within 20 Hours of Disclosure Read More »

Walmart’s AI move could lead to surge pricing — shoppers and experts are outraged: ‘This isn’t innovative, it’s exploitative’

Walmart’s AI move could lead to surge pricing — shoppers and experts are outraged: ‘This isn’t innovative, it’s exploitative’ 2026-03-20 at 16:01 By Brooke Steinberg “We don’t participate in surge pricing,” a spokeswoman said. This article is an excerpt from Latest Technology News | New York Post View Original Source

Walmart’s AI move could lead to surge pricing — shoppers and experts are outraged: ‘This isn’t innovative, it’s exploitative’ Read More »

Microsoft breaks Microsoft account sign-ins in Windows 11 with latest update

Microsoft breaks Microsoft account sign-ins in Windows 11 with latest update 2026-03-20 at 15:37 By Richard Speed OneDrive, Office, Teams Free users greeted with phantom ‘no internet’ errors, restart may help if you’re lucky Microsoft has broken account sign-ins in Windows 11 25H2 and 24H2 with a recent update, causing error messages in apps like

Microsoft breaks Microsoft account sign-ins in Windows 11 with latest update Read More »

UK police force presses pause on live facial recognition after study finds racial bias

UK police force presses pause on live facial recognition after study finds racial bias 2026-03-20 at 15:35 By Lindsay Clark Cams statistically more likely to ID Black people, says new research A UK police force has suspended its deployment of live facial recognition (LFR) technology after a study revealed it was statistically more likely to

UK police force presses pause on live facial recognition after study finds racial bias Read More »

Feds disrupt monster IoT botnets behind record-breaking DDoS attacks

Feds disrupt monster IoT botnets behind record-breaking DDoS attacks 2026-03-20 at 15:07 By Carly Page Millions of hijacked devices powered traffic floods targeting defense systems and beyond The US government has moved to disrupt a cluster of IoT botnets behind some of the largest DDoS attacks ever recorded, including traffic bursts topping 30 terabits per

Feds disrupt monster IoT botnets behind record-breaking DDoS attacks Read More »

The Importance of Behavioral Analytics in AI-Enabled Cyber Attacks

The Importance of Behavioral Analytics in AI-Enabled Cyber Attacks 2026-03-20 at 12:46 By Artificial Intelligence (AI) is changing how individuals and organizations conduct many activities, including how cybercriminals carry out phishing attacks and iterate on malware. Now, cybercriminals are using AI to generate personalized phishing emails, deepfakes and malware that evade traditional detection by impersonating

The Importance of Behavioral Analytics in AI-Enabled Cyber Attacks Read More »

Starmer’s digital ID reboot raises same old questions as its Blair-era ancestor

Starmer’s digital ID reboot raises same old questions as its Blair-era ancestor 2026-03-20 at 12:20 By SA Mathieson Audit trails aplenty, but no price tag – and no clue how long your data sticks around Opinion  Last week’s UK government consultation on its plans for digital identity had quite a few things missing. It did

Starmer’s digital ID reboot raises same old questions as its Blair-era ancestor Read More »

Scroll to Top