Security news that informs and inspires

All Articles

2244 articles:

Pair of Serious Flaws Patched in BIND 9

A pair of serious vulnerabilities have been fixed in the widely deployed BIND 9 DNS server.

DNS

Apple Fixes Trio of Actively Exploited Bugs

The three zero days (CVE-2023-41991, CVE-2023-41992 and CVE-2023-41993) impact various versions of macOS, iOS, iPadOS and watchOS.

Apple, Zero Day

Decipher Podcast: Source Code 9/22

Welcome back to Source Code, Decipher's weekly news wrap podcast with input from our sources.

Source Code, Podcast

DHS Wants to Simplify Mishmash of Cyber Incident Reporting Guidelines

The DHS proposed a single cyber incident reporting portal in an effort to make the process of reporting a cyberattack easier.

DHS

New Threat Group Targets Middle Eastern Telcos

A new attack group named ShroudedSnooper is targeting telecom providers in Middle Eastern countries with custom tools called HTTPSnoop and PipeSnoop.

Malware

The Emergence of Security Flaws as a ‘National Resource’ in China

An Atlantic Council report looks at the impact of China's regulation - in effect now for two years - that requires organizations to submit notice of a software vulnerability to the Chinese government within two days of discovery.

China

Iranian Threat Group Targets Cloud With Password Spraying Attacks

An Iran state-backed group called Peach Sandstorm is using password spraying attacks to target cloud environments in organizations across many industries.

Microsoft, Iran

DBatLoader Leverages OneDrive to Deliver Commodity Malware

The malware loader was recently observed in almost two dozen email campaigns that appeared to target English speakers and involved lures related to shipping orders and billing, invoice and purchase requests or inquiries.

Malware

Caesars Says Cyberattack Stemmed From Third-Party Vendor Compromise

Public disclosure of the Caesars cyberattack comes as MGM Resorts continues to face disruption across its hotels and casinos due to a separate cyber incident.

Cyberattack, Ransomware

Decipher Podcast: Source Code 9/15

Welcome back to Source Code, Decipher's weekly news wrap podcast with input from our sources.

Podcast, Source Code

Microsoft Warns of Teams-Based Phishing Campaign

Microsoft is warning enterprises about a recent Teams-based phishing campaign operated by a developing thrat group known as Storm-0342.

Microsoft, Phishing

Microsoft Warns of Two Zero Day Flaws

The Microsoft flaws join a rash of zero days disclosed over the past week by various companies, including Apple, Google and Adobe.

Microsoft, Patch Tuesday

CISA Outlines Plans to Tackle Open Source Software Security

In an Open Source Software Security Roadmap released on Tuesday, the agency said it wants to build up the capabilities to better understand the complex open source ecosystem and create visibility around the security risks in this landscape.

Log4j, Cisa

Adobe Patches Actively Exploited Reader Zero Day

Adobe is warning Acrobat and Acrobat Reader users about an actively exploited vulnerability in those products.

Adobe

Google Fixes Critical Chrome Zero Day

Google said that the flaw was reported by Apple’s Security Engineering and Architecture team and Citizen Lab on Sept. 6.

Google Chrome