Scroll down for all the latest web application security news and information.
Subscribe to our weekly newsletter for the latest in industry news, expert insights, dedicated information security content and online events.
A new campaign involving 19 malicious Visual Studio Code extensions used a legitimate npm package to embed malware in dependency folders
December’s Patch Tuesday sees the release of patches for over 50 CVEs including three zero-days
New phishing domains point to a campaign from the notorious Scattered Lapsus$ Hunters collective
Trustwave SpiderLabs has observed new banking Trojan Eternidade Stealer targeting Brazil using WhatsApp for propagation and data theft
The UK’s National Cyber Security Centre has urged users of its Web Check and Mail Check services to find alternatives
A previously unknown cyber actor UNK_SmudgedSerpent has been observed targeting academics with phishing and malware, merging techniques from Iranian groups