Malware Campaign Uses Ethereum Smart Contracts to Control npm Typosquat Packages

November 5, 2024 at 01:45AM A campaign targeting npm developers employs hundreds of typosquat packages to install cross-platform malware, utilizing Ethereum smart contracts for command-and-control. This approach complicates detection and takedown efforts, highlighting vulnerabilities in the open-source ecosystem. The attacker may be Russian-speaking, emphasizing the need for developer vigilance when downloading packages. ### Meeting Takeaways … Read more

Supply Chain Cybersecurity Beyond Traditional Vendor Risk Management

October 18, 2024 at 10:04AM Supply chain attacks are increasingly common, necessitating a shift from traditional vendor risk management to continuous, proactive security measures. Key strategies include real-time vendor monitoring, blockchain for transparency, zero-trust access protocols, and collaborative security practices. Organizations must adopt a comprehensive approach to protect their entire ecosystem from evolving threats. ### … Read more

Certificate Authority Market Size to Surpass $485M by 2033

October 11, 2024 at 05:15PM The Certificate Authority (CA) market is essential for issuing and managing digital certificates that authenticate identities and secure communications. Driven by cybersecurity integration and blockchain technology, North America leads the market, while the Asia-Pacific region experiences rapid growth. Notable recent developments include partnerships and innovations among major CA providers. ### … Read more

Worldcoin: Fighting Deepfakes and Bots With Global Permissionless Blockchain Identity

September 30, 2024 at 08:00AM SecurityWeek discusses the potential of a blockchain-based universal identity system. Tools for Humanity and Worldcoin are working on an identity solution that verifies living persons and thwarts bot activity. Leveraging iris scans and blockchain, the technology aims to provide a secure and privacy-oriented proof of unique humanity, addressing challenges posed … Read more

Data Security Firm ALTR Banks $25M Series C 

November 15, 2023 at 10:45AM Data security startup ALTR has raised $25 million in a Series C funding round led by John Stafford III. The funding will be used to expand ALTR’s market presence, enhance partner integrations, and develop channel relations. ALTR offers technology that helps with data access controls, data usage visibility, and data … Read more