Plus récents

Fraudsters distribute fake letters, often through WhatsApp, that carry the 👮 South African Police Service (saps.gov.za) logo alongside the names of real officers and police stations to appear legitimate. [ citizen.co.za/news/south-afric ]

🕰 « Future changes may take various forms, ranging from new funding partnerships to revised usage policies to expanded collaboration with governments & enterprises »  [ openssf.org/blog/2025/09/23/op ]

Authentication & secure publishing practices — In direct response to this incident, GitHub has taken swift & decisive action. [ github.blog/security/supply-ch ]

Afficher le fil de discussion

The 🇺🇸 U.S. Secret Service (secretservice.gov) dismantled a network of electronic devices located throughout the 🇺🇸 New York (nyc.gov) tristate area that were used to conduct multiple telecommunications-related threats directed towards senior 🇺🇸 U.S. government officials, which represented an imminent threat to the agency’s protective operations. This investigation is currently ongoing. [ secretservice.gov/newsroom/rel ]

🇯🇵 Online banking fraud surged to about 💴 ¥4220000000 in the first half of 2025, a roughly +🔺73% jump from last year & the fastest pace on record for the period [ japantimes.co.jp/news/2025/09/ ]

Afficher le fil de discussion

🇷🇺 КрасАвиа (krasavia.ru) reported a failure of its information systems on Sept. 18, 2025 warning passengers of potential disruptions across its network.  bitdefender.com/en-us/blog/hot ]

« The RubyGems & Bundler teams — including myself — have had their GitHub access taken away aside from a small number of people working for Ruby Central. I refuse to be associated with this. The decision to leave RubyGems was made for me, despite the objections of the entire team. » ( puppy weirder.earth ) [ pup-e.com/goodbye-rubygems.pdf ]

CopyCop : At least +200 new fictional media websites targeting the 🇺🇸 🇨🇦 🇫🇷, in addition to websites impersonating media brands and political parties and movements. [ recordedfuture.com/research/co ]

Généralisation de la carte vitale dématérialisée / France Identité ↦ Carte Vitale Numérique [ assemblee-nationale.fr/dyn/ope ]

Le Conseil constitutionnel avait censuré […] « Il est donc nécessaire de réintroduire cette réforme.

Afficher le fil de discussion

☣️ Shai-Hulud : It includes a self-propagating mechanism that automatically infects downstream packages, creating a cascading compromise across the ecosystem.  [ stepsecurity.io/blog/ctrl-tiny ]

🦠 « A supply chain attack that conducts a supply chain attack. » ( Nicholas Weaver )

Afficher le fil de discussion

Attackers targeted a wide variety of repositories, many of which had PyPI tokens stored as GitHub secrets, modifying their workflows to send those tokens to external servers. PyPI was not compromised. [ blog.pypi.org/posts/2025-09-16 ]

Plus anciens