Token Exfiltration Campaign via GitHub Actions Workflows

11 months ago

SummaryI recently responded to an attack campaign where malicious actors injected code into GitHub Actions workflows attempting to steal PyPI…

An Explainer Guide on Multi-Perspective Issuance Corroboration (MPIC)

11 months ago

Internet security is leveling up with MPIC. While your organization likely won’t need to do anything to prepare, here’s what…

‘World Quantum Readiness Day’ Returns with the Latest in PQC

11 months ago

Sept. 10: Get actionable insights from 20+ global experts as they discuss PQC readiness assessments, migration plans, and other practical…

Preventing Domain Resurrection Attacks

12 months ago

SummaryPyPI now checks for expired domains to prevent domain resurrection attacks,a type of supply-chain attack where someone buys an expired…

PyPI now serves project status markers in API responses

1 year ago

PyPI now serves project status markers in its standardindex APIs. This allows downstream consumers (like Python package installers andindex mirrors)…

<div>Email Certificate Standards Updated to Support ACME Automation & Future PQC Security</div>

1 year ago

Changes to the S/MIME Certificate Baseline Requirements add support for automated mailbox validation (via the ACME protocol) and post-quantum cryptography…

Critical Infrastructure Protection: Securing Essential Systems Against Cyber Threats

1 year ago

From cyber attacks on emergency call centers to electric and telecom network infiltrations, here’s what to know about the threats…

<div>Social Engineering Statistics 2025: When Cyber Crime & Human Nature Intersect</div>

1 year ago

These 30 social engineering attack statistics reveal human vulnerabilities and how bad guys love to exploit them (to your detriment)…

Chrome: New SSL Certificates Can’t Support Client Authentication Starting June 15, 2026

1 year ago

Google’s Chrome Root Store Policy (v1.6) update encourages CAs not to wait to shift to PKI hierarchies that support server…

Monitoring Should Take Center Stage as Let’s Encrypt Abandons SSL Expiration Notifications

1 year ago

Let’s Encrypt will stop sending SSL/TLS expiration emails effective June 4 — now’s the time to ensure you have SSL…

This website uses cookies.