Ad image

Fake Banking SDK on NuGet Steals Credentials and PFX Certificates

A fraudulent Sicoob.Sdk NuGet package steals client IDs and PFX certificates, potentially allowing attackers to impersonate Brazilian banking API integrations.

The Latest

Breaking News and Alerts

Anthropic Security Plugin Monitors AI Code Edits for Vulnerabilities in Real Time

Anthropic's new security-guidance plugin for Claude Code reviews code edits, model outputs, and commits across three checkpoints to catch vulnerabilities before they reach production.

Spotlight

Cybersecurity Profiles and Stories

Microsoft Defender for Endpoint Gains Automatic Network Isolation for Hacked Workstations

The new capability automatically cuts network access to compromised workstations during ransomware attacks while preserving the device's connection to Microsoft's security telemetry service.

Notepad++ Urgent Update Fixes Two Critical Code Execution Flaws

The update patches three flaws including two critical arbitrary code execution vulnerabilities that could let attackers silently run malicious programs.

ISC Warns of Remote Exploit Risks in BIND 9 DNS Software

ISC has documented multiple BIND 9 flaws including a critical memory corruption vulnerability in the DNS-over-HTTPS implementation that could allow remote code execution.

Evaluating Static Application Security Testing Platforms for Modern DevSecOps Pipelines

Modern SAST tools analyze uncompiled code for vulnerabilities and integrate into CI/CD pipelines, helping security teams catch flaws early without slowing development.

Features

Research and Thought Leadership