• ⚡ Weekly Recap: VPN Exploits, Oracle’s Silent Breach, ClickFix Comeback and More

    ⚡ Weekly Recap: VPN Exploits, Oracle’s Silent Breach, ClickFix Comeback and More

    Today, every unpatched system, leaked password, and overlooked plugin is a doorway for attackers. Supply chains stretch deep into the code we trust, and malware hides not just in shady apps — but in job offers, hardware, and cloud services we rely on every day. Hackers don’t need sophisticated exploits anymore. Sometimes, your credentials and…

    Read More

  • Security Theater: Vanity Metrics Keep You Busy – and Exposed

    Security Theater: Vanity Metrics Keep You Busy – and Exposed

    After more than 25 years of mitigating risks, ensuring compliance, and building robust security programs for Fortune 500 companies, I’ve learned that looking busy isn’t the same as being secure.  It’s an easy trap for busy cybersecurity leaders to fall into. We rely on metrics that tell a story of the tremendous efforts we’re expending…

    Read More

  • PoisonSeed Exploits CRM Accounts to Launch Cryptocurrency Seed Phrase Poisoning Attacks

    PoisonSeed Exploits CRM Accounts to Launch Cryptocurrency Seed Phrase Poisoning Attacks

    A malicious campaign dubbed PoisonSeed is leveraging compromised credentials associated with customer relationship management (CRM) tools and bulk email providers to send spam messages containing cryptocurrency seed phrases in an attempt to drain victims’ digital wallets. “Recipients of the bulk spam are targeted with a cryptocurrency seed phrase poisoning attack,” Silent Push said in an

    Read More

  • Slideshow: The Gorge joins national Hands Off! protest events

    Slideshow: The Gorge joins national Hands Off! protest events

    HOOD RIVER — An estimated 1,500 people from around the Gorge rallied on April 5 in Hood River to take part in the national Hands Off! day of protest coordinated by 50501, the national Indivisible group, MoveOn.org, and more than…

    Read More

  • Salt & Straw unveils cookbook, newest location

    Salt & Straw unveils cookbook, newest location

    Cofounder Tyler Malek will publish a cookbook this month, and the gourmet ice cream chain adds a New England story.

    Read More

  • Microsoft Credits EncryptHub, Hacker Behind 618+ Breaches, for Disclosing Windows Flaws

    Microsoft Credits EncryptHub, Hacker Behind 618+ Breaches, for Disclosing Windows Flaws

    A likely lone wolf actor behind the EncryptHub persona was acknowledged by Microsoft for discovering and reporting two security flaws in Windows last month, painting a picture of a “conflicted” individual straddling a legitimate career in cybersecurity and pursuing cybercrime. In a new extensive analysis published by Outpost24 KrakenLabs, the Swedish security company unmasked the…

    Read More

  • North Korean Hackers Deploy BeaverTail Malware via 11 Malicious npm Packages

    North Korean Hackers Deploy BeaverTail Malware via 11 Malicious npm Packages

    The North Korean threat actors behind the ongoing Contagious Interview campaign are spreading their tentacles on the npm ecosystem by publishing more malicious packages that deliver the BeaverTail malware, as well as a new remote access trojan (RAT) loader. “These latest samples employ hexadecimal string encoding to evade automated detection systems and manual code audits,…

    Read More

  • Spotting the Difference Between Malware and Ransomware

    Spotting the Difference Between Malware and Ransomware

    Malware and ransomware are two types of bad software. They can damage your computer or steal your data. Downloading this harmful software comes with serious consequences. In 2024, there were more than 60 million new strains of malware found on the internet.  This is why it’s critical to understand the difference between them. This article…

    Read More

  • Malicious Python Packages on PyPI Downloaded 39,000+ Times, Steal Sensitive Data

    Malicious Python Packages on PyPI Downloaded 39,000+ Times, Steal Sensitive Data

    Cybersecurity researchers have uncovered malicious libraries in the Python Package Index (PyPI) repository that are designed to steal sensitive information. Two of the packages, bitcoinlibdbfix and bitcoinlib-dev, masquerade as fixes for recent issues detected in a legitimate Python module called bitcoinlib, according to ReversingLabs. A third package discovered by Socket, disgrasya, contained a

    Read More

  • Oregon chipmakers feel tariff pain, despite US exemption

    Oregon chipmakers feel tariff pain, despite US exemption

    Semiconductors are exempt from Trump tariffs, but many companies remain vulnerable.

    Read More