SC Media
20 articles
AWS patches flaw in 7 SDKs
The flaw allowed for the redirection of API calls by manipulating the region field within the SDK's hostname template.
ShinyHunters claims social engineering attack against ReliaQuest
The attack involved threat actors calling employees and attempting to trick them into accessing a fake ReliaQuest single sign-on (SSO) page hosted on a looka...
Senate bill aims to prepare U.S. electric grid for quantum computing threats
The Quantum-GUARD Act directs the Federal Energy Regulatory Commission (FERC) to consider quantum computing threats when reviewing reliability standards for ...
WordPress plugin vulnerabilities allow admin account takeover
The vulnerabilities, tracked as CVE-2026-61979 and CVE-2026-15981, can be chained together to bypass authentication.
Metal Gear Online 3 vulnerability allowed remote code execution
The vulnerability, discovered by researcher Alice Cecchetto and detailed by CERT/CC, stemmed from a heap-based buffer overflow in the game's player-removal m...
TikTok agrees to $400 million settlement over child privacy
The settlement addresses claims that TikTok illegally collected data from users under 13 and knowingly allowed them to create accounts, violating the Childre...
Developer alleges Alibaba uses audio fingerprinting for web tracking
Software engineer Matt Callaghan discovered that Alibaba's website employed obfuscated audio scripts that generated a waveform and analyzed its output.
How to catch what background checks aren’t built to see
Too often today the hiring funnel becomes the attack surface – here’s how to catch insider threats before they escalate.
Microsoft says Entra ID identity software not exploited, revises CVE
While the urgency has changed, security pros say teams should still review Entra ID logs for anything suspicious before the patch.
CISA adds Zimbra Collaboration Suite bug to exploited vulnerabilities list
Experts warn that it’s the fifth time Zimbra made the KEV this year.
CMMC Phase 2 suspended: What defense contractors need to know
CMMC Phase 2 is paused, but defense contractors must keep meeting existing cybersecurity requirements.
How to Build an Injection and Data Handling Security Program
How to Build an Executive Attack Surface Risk Reporting Program
The OWASP LLM Top 10: What Application Security Teams Need to Know About LLM Vulnerabilities
AI Risk Classification: NIST AI RMF and EU AI Act
Premier League introduces new cybersecurity rules for football clubs
The Premier League has established new mandatory cybersecurity standards for its 20 clubs, moving from a non-prescriptive baseline to enforceable rules with ...
Iran-linked hackers target UK power plant and US water infrastructure
The UK power plant, which was not named due to security concerns, was offline for four days before being restored by staff.