TechCrunch (Cybersecurity)

TechCrunch (Cybersecurity)

Publication
2 followers

Technology news publisher with a dedicated cybersecurity section covering security startups and breach incidents.

Hackers Have Compromised Dozens of Popular Open Source Packages in an Ongoing Supply-Chain Attack
News•May 19, 2026

Hackers Have Compromised Dozens of Popular Open Source Packages in an Ongoing Supply-Chain Attack

Hackers have launched a new supply‑chain assault, hijacking a developer account to publish over 630 malicious versions across 317 open‑source packages in just 20 minutes. Cybersecurity firms StepSecurity and SafeDep flagged the rapid rollout, which targets credential‑stealing code embedded in...

By TechCrunch (Cybersecurity)
US Cyber Agency CISA Exposed Reams of Passwords and Cloud Keys to the Open Web
News•May 19, 2026

US Cyber Agency CISA Exposed Reams of Passwords and Cloud Keys to the Open Web

U.S. Cybersecurity and Infrastructure Security Agency (CISA) discovered that a contractor employee inadvertently published spreadsheets on GitHub containing plaintext passwords, cloud access tokens, and other credentials for CISA and Department of Homeland Security systems. Security researcher Guillaume Valadon identified the exposure,...

By TechCrunch (Cybersecurity)
NYC Health + Hospitals Says Hackers Stole Medical Data and Fingerprints During Breach Affecting at Least 1.8 Million People
News•May 18, 2026

NYC Health + Hospitals Says Hackers Stole Medical Data and Fingerprints During Breach Affecting at Least 1.8 Million People

NYC Health + Hospitals disclosed a breach that exposed personal, medical and biometric data for at least 1.8 million patients. Hackers infiltrated the network through a third‑party vendor and remained undetected from November 2025 until February 2026, copying files that included health records,...

By TechCrunch (Cybersecurity)
Google Launches New Android Security Feature to Help Uncover Spyware Attacks
News•May 12, 2026

Google Launches New Android Security Feature to Help Uncover Spyware Attacks

Google has begun rolling out an opt‑in feature called Intrusion Logging to Android devices running the December 16 update or later. The tool, part of Advanced Protection Mode, creates encrypted daily logs of system events—unlock attempts, app installs, ADB connections,...

By TechCrunch (Cybersecurity)
Exaforce Raises $125M Series B to Build AI for Catching and Stopping Cyberattacks as They Happen
News•May 12, 2026

Exaforce Raises $125M Series B to Build AI for Catching and Stopping Cyberattacks as They Happen

Exaforce announced a $125 million Series B round, valuing the three‑year‑old AI cybersecurity startup at $725 million and bringing total funding to $200 million. The company’s AI agents, called “Exabots,” automate security operations, reportedly cutting manual analyst work by up to 90 percent. Its product,...

By TechCrunch (Cybersecurity)
Hackers Hack Victims Hacked by Other Hackers
News•May 7, 2026

Hackers Hack Victims Hacked by Other Hackers

SentinelOne discovered a new hacking campaign, dubbed PCPJack, that targets systems already compromised by the cyber‑crime group TeamPCP. The attackers evict TeamPCP, remove its tools, and deploy a self‑spreading worm to steal credentials and exfiltrate data. PCPJack scans for exposed...

By TechCrunch (Cybersecurity)
AI Evaluation Startup Braintrust Confirms Breach, Tells Every Customer to Rotate Sensitive Keys
News•May 6, 2026

AI Evaluation Startup Braintrust Confirms Breach, Tells Every Customer to Rotate Sensitive Keys

AI evaluation startup Braintrust disclosed an unauthorized access incident in one of its AWS accounts that exposed customer API keys. The company sent an email urging every client to revoke and rotate those keys, noting that only one customer has...

By TechCrunch (Cybersecurity)
Some Kids Are Bypassing Age-Verification Checks with a Fake Mustache
News•May 6, 2026

Some Kids Are Bypassing Age-Verification Checks with a Fake Mustache

Governments in the U.S. and U.K. are tightening age‑verification laws to keep minors off adult sites, forcing platforms to adopt document uploads or biometric checks. A survey by Internet Matters found half of 1,000 children could easily bypass these controls,...

By TechCrunch (Cybersecurity)
Paragon Is Not Collaborating with Italian Authorities Probing Spyware Attacks, Report Says
News•Apr 28, 2026

Paragon Is Not Collaborating with Italian Authorities Probing Spyware Attacks, Report Says

Paragon Solutions, the Israeli‑American maker of Graphite spyware, has failed to answer a formal information request from Italian prosecutors investigating a 2024 hacking campaign that targeted journalists and activists. The company previously promised to assist the probe but instead cancelled...

By TechCrunch (Cybersecurity)
Vercel Says some of Its Customers’ Data Was Stolen Prior to Its Recent Hack
News•Apr 23, 2026

Vercel Says some of Its Customers’ Data Was Stolen Prior to Its Recent Hack

Vercel disclosed that hackers accessed a small number of customer accounts before its widely reported April breach, indicating a longer‑running intrusion. The company traced the initial entry to a Context AI app that infected an employee’s workstation with infostealer malware,...

By TechCrunch (Cybersecurity)
Surveillance Vendors Caught Abusing Access to Telcos to Track People’s Phone Locations, Researchers Say
News•Apr 23, 2026

Surveillance Vendors Caught Abusing Access to Telcos to Track People’s Phone Locations, Researchers Say

Security researchers at the Citizen Lab disclosed two distinct spying campaigns that exploited long‑standing weaknesses in global telecom signaling protocols to locate individuals’ phones. The attackers masqueraded as legitimate carriers—using 019Mobile, Tango Networks U.K., and Airtel Jersey—to piggyback on SS7...

By TechCrunch (Cybersecurity)
UK Government Says 100 Countries Have Spyware that Can Hack People’s Phones
News•Apr 22, 2026

UK Government Says 100 Countries Have Spyware that Can Hack People’s Phones

The UK National Cyber Security Centre disclosed that 100 countries now have access to commercial spyware, up from 80 last year, lowering the barrier for state‑backed surveillance. Tools such as NSO Group’s Pegasus and Paragon’s Graphite can infiltrate phones and...

By TechCrunch (Cybersecurity)
Man Who Hacked US Supreme Court Filing System Sentenced to Probation
News•Apr 17, 2026

Man Who Hacked US Supreme Court Filing System Sentenced to Probation

Nicholas Moore pleaded guilty to infiltrating the U.S. Supreme Court’s electronic filing system, as well as the networks of AmeriCorps and the Department of Veterans Affairs, using stolen credentials. He publicly bragged about the breaches on an Instagram account, posting...

By TechCrunch (Cybersecurity)
Fashion Retailer Express Left Customers’ Personal Data and Order Details Exposed to the Internet
News•Apr 16, 2026

Fashion Retailer Express Left Customers’ Personal Data and Order Details Exposed to the Internet

Express, a major U.S. fashion retailer, patched a website flaw that let anyone view other shoppers’ order confirmations. The vulnerability exposed names, contact details, addresses, purchase items and partial credit‑card data for at least a dozen customers, all accessible by...

By TechCrunch (Cybersecurity)
TechCrunch (Cybersecurity) | Pulse