Meet SparklingGoblin, a member of the Winnti family

The post The SideWalk may be as dangerous as the CROSSWALK appeared first on WeLiveSecurity

Who is actually paying the ransom demand? – Be careful about what you throw away – Records from a terrorist watchlist exposed online

The post Week in security with Tony Anscombe appeared first on WeLiveSecurity

Japanese cryptocurrency exchange Liquid suspends cryptocurrency deposits and withdrawals and moves its assets into cold storage

The post Hackers swipe almost $100 million from major cryptocurrency exchange appeared first on WeLiveSecurity

Ransomware payments may have greater implications than you thought – and not just for the company that gave in to the attackers’ demands

The post Are you, the customer, the one paying the ransomware demand? appeared first on WeLiveSecurity

Fraudsters impersonate vaccine manufacturers and authorities overseeing vaccine distribution efforts, INTERPOL warns

The post Health authorities in 40 countries targeted by COVID‑19 vaccine scammers appeared first on WeLiveSecurity

The secret list was exposed online for three weeks, allowing anyone to access it without any kind of authentication

The post Nearly 2 million records from terrorist watchlist exposed online appeared first on WeLiveSecurity

One man’s trash is another man’s treasure – here’s why you should think twice about what you toss in the recycling bin

The post Dumpster diving is a filthy business appeared first on WeLiveSecurity

How IISpy spies on its victims and stays under the radar – IISerpent tampers with search engine results – How to avoid falling prey to ransomware

The post Week in security with Tony Anscombe appeared first on WeLiveSecurity

As employees split their time between office and off-site work, there’s a greater potential for company devices and data to fall into the wrong hands

The post Examining threats to device security in the hybrid workplace appeared first on WeLiveSecurity

 

As an active member of the open source software (OSS) community, Google recognizes the growing threat of software supply chain attacks against OSS we use and develop. Building on our efforts to improve OSS security with an end-to-end framework (SLSA), metrics (Scorecards), and coordinated vulnerability disclosure (guide), we are excited to announce Allstar.


Allstar is a GitHub app that continuously enforces security policy settings through selectable automated enforcement actions. Allstar is already filing and closing security issues for Envoy and GoogleContainerTools, with more organizations and repositories lined up. 

See the OpenSSF announcement for more information on Allstar.