After scanning all 5.6 million public repositories on GitLab Cloud, a security engineer discovered more than 17,000 exposed secrets across over 2,800 unique domains.
Cyber Dispatch™️
After scanning all 5.6 million public repositories on GitLab Cloud, a security engineer discovered more than 17,000 exposed secrets across over 2,800 unique domains.
Luke Marshall used the TruffleHog open-source tool to check the code in the repositories for sensitive credentials like API keys, passwords, and tokens.
The researcher previously scanned Bitbucket, where he found 6,212 secrets spread over 2.6 million repositories. He also checked the Common Crawl dataset that is used to train AI models, which exposed 12,000 valid secrets.
The researcher previously scanned Bitbucket, where he found 6,212 secrets spread over 2.6 million repositories. He also checked the Common Crawl dataset that is used to train AI models, which exposed 12,000 valid secrets.
CISA added a real-world exploited flaw in OpenPLC ScadaBR to its Known Exploited Vulnerabilities list.
Hackers used the bug (CVE-2021-26829) to deface a fake water plant system in under 26 hours — disabling logs and alarms.
Hackers used the bug (CVE-2021-26829) to deface a fake water plant system in under 26 hours — disabling logs and alarms.
If You Get This WhatsApp Message, Your Phone Is Being Hacked.
This warning is very simple. Android users are now under attack from dangerous new malware that will steal crypto and steal banking credentials to empty accounts. The threat is delivered by a WhatsApp message — if you see it, you delete it.
This warning is very simple. Android users are now under attack from dangerous new malware that will steal crypto and steal banking credentials to empty accounts. The threat is delivered by a WhatsApp message — if you see it, you delete it.
A sophisticated new Android malware family dubbed “Albiriox” has emerged on the cybercrime landscape, offering advanced remote access capabilities as a Malware-as-a-Service (MaaS).
The Shai Hulud 2.0 worm has compromised nearly 1,200 organizations, including major banks, government bodies, and Fortune 500 technology firms.
KawaiiGPT emerges as an accessible, open-source tool that mimics the controversial WormGPT, providing unrestricted AI assistance via jailbroken large language models.
Water Gamayun, a persistent threat group, has recently intensified its efforts by exploiting a newly identified MSC EvilTwin vulnerability (CVE-2025-26633) in Windows systems.
India has asked all smartphone makers to preload all new devices with a state-owned cyber security app that cannot be deleted.
Not all "E2E" encryption claims are equal.
Big Tech loves to sell privacy snake oil by claiming encryption and privacy, when in reality they hold the master key and can access your data on a whim. - Cyber Dispatch
Big Tech loves to sell privacy snake oil by claiming encryption and privacy, when in reality they hold the master key and can access your data on a whim. - Cyber Dispatch
Google Patches 107 Android Flaws, Including Two Framework Bugs Exploited in the Wild.
French Football Federation faces own-goal after club software data breach.
Google deletes X post after getting caught using a ‘stolen’ AI recipe infographic.
Stealthy browser extensions waited years before infecting 4.3M Chrome, Edge users with backdoors and spyware.
New Albiriox MaaS Malware Targets 400+ Apps for On-Device Fraud and Screen Control.