Open-source software used by over 23,000 organisations was compromised by attackers who accessed a maintainer account, injecting credential-stealing code. The corrupted package, part of tj-actions, was able to modify source code and potentially access secret variables. The breach exposed some organisations’ sensitive credentials in freely accessible logs, underlining the need for stringent security protocols in open-source environments.

‘Systemic gaps’ found private equity-backed healthcare companies’ cybersecurity preparedness
Private equity-backed healthcare companies have “systemic gaps” in their cybersecurity preparedness, according to a report from Clearwater Security. The findings revealed many such firms lack