Over 23,000 organizations may be at risk following a supply chain attack affecting tj-actions/changed-files GitHub Action, say researchers at StepSecurity. GitHub Actions is a CI/CD service that allows developers to automate software builds and testing. Workflows run in response to specific events, such as committing new code to a repository. With adoption in over 23,000 repositories, tj-actions/changed-files is a GitHub Action designed to retrieve all files and directories. Last Friday, a malicious commit in the Action was uncovered whereby bad actors modified its code and retroactively updated multiple version tags to reference the malicious commit. The supply chain compromise has…
Kirsten Doyle
As APIs become more integral to both everyday digital services and complex AI systems, concerns over their security are growing — and not without good reason. APIs are the connective tissue of modern software, but without strong governance, they can also represent serious vulnerabilities. Recent research by Kong, called “API Security Perspectives 2025”, highlights that API security is increasingly seen as a critical concern for IT teams, as AI-enhanced threats push the boundaries of traditional cybersecurity defenses. Kong also forecasts a staggering 548% increase in API attacks by 2030, underscoring that API security risks are expected to accelerate significantly in…
FCC Chairman Brendan Carr has announced the creation of a new Council on National Security within the agency, which he says aims at strengthening US defenses against foreign technology threats — particularly those from China. According to the FCC, the Council will use the full scope of the FCC’s regulatory, investigatory, and enforcement powers to protect US networks, technology, and supply chains. Carr also appointed Adam Chan, his National Security Counsel, as the first Director of the Council. “Today, the country faces a persistent and constant threat from foreign adversaries, particularly the CCP,” said Carr. “These bad actors are always…
The next generation of artificial intelligence (AI), known as “agents,” may open the door to new cyber threats, experts are warning. AI agents are advanced tools that can carry out tasks on their own, such as browsing the internet, writing emails, or even interacting with websites. While they are designed to help people automate mundane jobs, they can also be used by malicious actors to carry out cyberattacks more easily. A New Tool for Malefactors? Until now, threat actors have used AI to help craft convincing phishing emails or write malicious code, but these tools needed people to operate them…
The US Cybersecurity and Infrastructure Security Agency (CISA) has flagged three newly discovered Ivanti Endpoint Manager (EPM) vulnerabilities—CVE-2024-13159, CVE-2024-13160, and CVE-2024-13161—to its Known Exploited Vulnerabilities (KEV) Catalog, warning federal agencies and entities of active exploitation attempts. The flaws stem from absolute path traversal weaknesses that allow remote, unauthenticated attackers to fully compromise vulnerable Ivanti EPM servers. The vulnerabilities were first reported in October 2023 by Horizon3.ai researcher Zach Hanley and patched by Ivanti on 13 January. However, just over a month later, Horizon3.ai released proof-of-concept (PoC) exploits demonstrating how these vulnerabilities could be used in relay attacks to coerce Ivanti…
Arctic Wolf has warned the industry about ongoing malicious activity targeting the management interfaces of FortiGate firewall devices, which are exposed to the public internet. According to the company, bad actors have been actively exploiting these interfaces since early December last year. While the total extent of the attacks is still being investigated, entities that use these products should review and tighten their security practices immediately. Management interfaces on firewalls are a known target for malicious actors trying to gain initial access to company networks. They often lead to ransomware and other malicious acts. Arctic Wolf stressed that similar attack…
The latest Global Threat Index from Check Point Software Technologies has revealed a sharp rise in AsyncRAT attacks, pushing this stealthy remote access Trojan (RAT) into the top four most prevalent malware strains worldwide. This is a concerning trend: malicious actors are increasingly eyeing and exploiting trusted platforms to slip through security nets and gain a toehold in company networks. A Growing Global Menace According to researchers, AsyncRAT is being deployed in sophisticated phishing campaigns, often disguised behind Dropbox and TryCloudflare links to bypass conventional security solutions. Once a user clicks, a multi-stage infection chain unfolds, involving LNK, JavaScript, and…
Microsoft Threat Intelligence has discovered a new variant of XCSSET, a sophisticated modular macOS malware that targets Xcode projects. The malware was found in the wild during routine threat hunting and is the first known XCSSET variant to surface since 2022. This new version of XCSSET features stronger obfuscation methods, updated techniques to maintain persistence on infected machines, and new ways of infecting systems. These improvements help the malware steal and exfiltrate files, as well as sensitive system and user information, including digital wallet data and personal notes. XCSSET is designed to infect Xcode projects and executes when a developer…
In a recent investigation, Tenable researchers explored how DeepSeek, a large language model (LLM) built by a Chinese company, can be exploited to generate malware, including keyloggers and ransomware, despite its initial refusal to engage in harmful activities. Unlike popular AI models like GPT-4 or Claude, DeepSeek is fully open-source, so anyone can download and use it for free. It’s trained on large datasets, including code, making it very powerful — yet potentially dangerous. From Guardrails to Jailbreaks Mainstream GenAI platforms like ChatGPT and Gemini also have well-documented protections against malicious use. Reports like OpenAI’s “Disrupting malicious uses of AI…
OpenAI has officially called on US lawmakers to exempt it from complying with state-level AI regulations, instead urging a unified approach under federal AI rules. It argues that a consistent, nationwide framework is critical to maintain US leadership in AI development and deployment. In a newly released policy proposal, the company outlines what it calls a “freedom-focused” strategy, emphasizing that only a national approach will allow American innovation to flourish without being slowed by fragmented, state-specific requirements. Key Elements of OpenAI’s Policy Proposal: Shaping the Future Regulatory Landscape If these proposals are adopted, they could shape the future regulatory landscape.…
