SecurityWeek reports the attackers behind the Nx supply chain incident published more than 6,700 previously private repositories from hundreds of organizations. Beyond source code exposure, teams face heightened risks of credentials or secrets inadvertently stored in repos—review access controls, rotate tokens, and audit commit history and CI/CD integrations immediately.
Source: SecurityWeek
Wealthsimple discloses data breach tied to supply chain incident
Canadian fintech Wealthsimple says a third-party supply chain attack led to exposure of information for some customers, but accounts and funds remain secure. Organizations should expect follow-on phishing and credential-harvesting attempts and re-validate vendor access scopes and monitoring across connected SaaS platforms.
Source: SecurityWeek
Talos IR: How to stop ransomware before it starts
Cisco Talos distills lessons from two years of pre-ransomware incident response, highlighting the indicators, controls, and playbook steps that reliably disrupt attacks before encryption. The guidance emphasizes early-stage detection and hardening measures that blunt affiliate tradecraft and reduce time-to-containment.
Source: Cisco Talos
Silent Push uncovers new domains linked to Chinese APTs Salt Typhoon/UNC4841
Researchers identified previously unreported domains tied to closely linked Chinese threat actors, including Salt Typhoon, urging defenders to check telemetry and hunt for suspicious resolutions. Proactive blocking and retro-hunting for these indicators can surface dormant footholds and C2 infrastructure in enterprise environments.
Source: SilentPush
Czech NUKIB warns of Chinese espionage risks to critical infrastructure
The Czech National Cyber and Information Security Agency flagged growing risks from Chinese-linked technologies and the APT31 threat group across sectors like energy, healthcare, transport, and government. The advisory underscores the need for targeted risk assessments, supplier scrutiny, and mitigations for devices and services in critical environments.
Source: Security Affairs
Linux Kernel Runtime Guard hits 1.0 with broader distro support
LKRG 1.0.0 brings major updates to the runtime kernel integrity module that detects tampering and attempts to exploit kernel flaws. As a loadable module, it now supports a wide range of kernels—from legacy RHEL7 variants to current mainline and distro releases—offering defenders another layer of Linux hardening.
Source: Help Net Security
From phishing to “onboarding”: attackers pose as new hires
The Hacker News highlights a growing threat model where adversaries pass background checks and “onboard” as employees or contractors, weaponizing identity and access from day one. The trend elevates the importance of strong identity proofing, contractor vetting, least-privilege access, and continuous monitoring throughout the joiner–mover–leaver lifecycle.
Source: TheHackerNews
You May Also Be Interested In...
InterceptSuite: Open-source network traffic interception tool
AI moves fast, but data security must move faster
Salesloft Drift Breach Traced to GitHub Compromise and Stolen OAuth Tokens