The folks at Koi discovered GlassWorm, the world's first worm targeting VS Code extensions on OpenVSX marketplace.
www.koi.ai/blog/glasswo...
@turngate.bsky.social
Turngate simplifies logs so anyone can investigate, so you can understand activities in your enterprise in seconds. https://www.turngate.io/
The folks at Koi discovered GlassWorm, the world's first worm targeting VS Code extensions on OpenVSX marketplace.
www.koi.ai/blog/glasswo...
In case you didn't hear, F5 has reported that a "nation-state threat actor maintained long-term, persistent access to, and downloaded files from, certain F5 systems,β including source code and vulnerability info.
www.helpnetsecurity.com/2025/10/15/f...
F5's statement:
my.f5.com/manage/s/art...
GoAnywhere MFT is warning users to install a new patch that fixes a deserialization vulnerability in the License Servlet that allows threat actors to run command injection attacks.
www.techradar.com/pro/security...
When building an insider risk program, practicality is key. That is why our latest blog post lays out a middle-ground approach that is budget friendly and allows you to spot problems early with clarity, and without creating a jumbo-sized project.
www.turngate.io/blog/insider...
The Google Threat Intelligence Group has published a report about the BRICKSTORM malware that has been allowing backdoor access across sectors for the last year.
cloud.google.com/blog/topics/...
Good security investigations are about strategy, not spectacle. In our latest blogpost, we lay out a seven step budget- and user-friendly approach on setting up a SOC without a SIEM to make the most of your log data.
www.turngate.io/blog/seven-s...
The Cloud Security Alliance announced the launch of the SaaS Security Capability Framework (SSCF), a new technical framework that defines configurable, consumable, and customer-facing security controls provided by SaaS vendors to their customers.
cloudsecurityalliance.org/artifacts/sa...
If you have been wanting more information on the Salesforce Drift breach, Tom Uren breaks down the authorization sprawl attack as well as the responses from the victim organizations.
www.lawfaremedia.org/article/expl...
This week Turngate hosted a mixer where we discussed current OAuth concerns. This article by Bill Batchelor, Eyal Rafian, and Nathaniel Quist expands on that with their own insights on OAuth token risks and best practices organizations can implement.
unit42.paloaltonetworks.com/third-party-...
If you were affected by the Cloudflare outage last Friday, they released a blogpost this weekend detailing how a bug in the dashboard caused repeated, unnecessary calls to the Tenant Service API which ultimately overwhelmed the service.
blog.cloudflare.com/deep-dive-in...
We found an interesting article about the risks associated with the growing tech debt within the SaaS world.
www.techradar.com/pro/secure-a...
So, as we are new here we wanted to introduce ourselves! If you want to know more, check out turngate.io
02.09.2025 18:49 β π 0 π 0 π¬ 0 π 1Hello, World!
25.08.2025 19:42 β π 2 π 0 π¬ 0 π 0