Every story tagged Malware Distribution, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.
2 stories · open in the command center
Security firms Checkmarx and Bitwarden fell victim to a sophisticated supply-chain attack originating from compromised development tools, demonstrating how attackers are weaponizing security infrastructure itself as both a target and distribution mechanism for malware and credential theft. The cascading breaches—compounded by ransomware extortion and incomplete remediation—highlight a critical vulnerability: security tools with privileged access across wide customer bases represent high-value targets for access brokers who sell credentials to ransomware gangs, creating downstream risks across entire customer ecosystems. For IT organizations, this underscores the urgent need to reassess trust assumptions around security vendors and implement enhanced monitoring of third-party tool integrity, as traditional supplier relationships with security providers no longer guarantee protection.
Hundreds of subdomains across 34+ universities, including prestigious institutions like Berkeley and Columbia, are serving malicious content and pornography due to poor DNS record management—specifically the failure to remove CNAME records when subdomains are decommissioned. This security lapse exploits a common operational gap where organizations lack comprehensive subdomain inventories and regular audits, allowing threat actors to hijack expired domains and leverage university brands for search engine visibility. For IT organizations, this represents a critical governance and security risk that demands immediate attention to DNS hygiene practices and decentralized resource management.