search

Sections

Cyber Security

2432 articles

Malicious MCP Server on npm postmark-mcp Harvests Emails
cybersecurity

Malicious MCP Server on npm postmark-mcp Harvests Emails

Urgent security alert: On September 25, 2025, the npm package ‘postmark-mcp’ was compromised, secretly exfiltrating email contents. Learn about the incident timeline, impact, and immediate mitigation steps, including uninstalling, rotating credentials, and scanning with Snyk’s MCP-Scan.

Blog RSS Feed | Snyk ·
Accelerating adoption of AI for cybersecurity at DEF CON 33
cybersecurity

Accelerating adoption of AI for cybersecurity at DEF CON 33

Elie Bursztein and Marianna Tishchenko from Google’s Privacy, Safety and Security Team emphasize the importance of using AI to strengthen cybersecurity. At DEF CON 33, they hosted the GenSec Capture the Flag (CTF) event in partnership with Airbus, focusing on human-AI collaboration. Nearly 500 participants engaged, with many using AI tools for the first time. Positive feedback highlighted the effectiveness of AI in cybersecurity workflows. Sec-Gemini, Google’s Cybersecurity AI, received commendations for its utility. The event’s success and community input will guide future improvements.

Google Online Security Blog ·
Snyk Ranked #51 on 2025 Forbes Cloud 100 List
cybersecurity

Snyk Ranked #51 on 2025 Forbes Cloud 100 List

We’re thrilled to share that Snyk has, for the sixth time and fifth consecutive year, been named to the Forbes Cloud 100 ranked at #51, recognizing the world’s most innovative private cloud companies.

Blog RSS Feed | Snyk ·
Supporting Rowhammer research to protect the DRAM ecosystem
cybersecurity

Supporting Rowhammer research to protect the DRAM ecosystem

Rowhammer is a hardware vulnerability in DRAM that allows attackers to cause data corruption by repeatedly accessing memory rows. This can lead to unauthorized data access, privilege escalation, or denial of service. While vendors have implemented mitigations like Target Row Refresh (TRR) for DDR5, recent findings reveal these defenses can be bypassed by sophisticated attacks. Google’s collaboration with researchers has resulted in new testing platforms and insights into effective countermeasures, highlighting the need for ongoing improvements to DRAM security, including potential future standards like PRAC.

Google Online Security Blog ·