Threat actors have deployed two different ransomware variants against victims, including AvosLocker, Diamond, Hive, Karakurt, LockBit, Quantum and Roya.
Progress Software has fixed a critical pre-authentication remote code execution bug in its WS_FTP Server product.
Welcome back to Source Code, Decipher's weekly news wrap podcast with input from our sources.
The flaw is the second Chrome zero day fixed by Google this month.
The full impact of the flaw is still being mapped out, but current estimates show that 2,120 organizations have been impacted by MoveIT Transfer exploits - resulting in the data of at least 62 million individuals being compromised.
U.S. authorities warn that cooperative efforts between state-sponsored actors and cybercrime groups make life more difficult for defenders and law enforcement.
Software development company JetBrains is urging customers to apply updates that fix a critical-severity authentication bypass flaw in the TeamCity CI/CD server.
A pair of serious vulnerabilities have been fixed in the widely deployed BIND 9 DNS server.
The three zero days (CVE-2023-41991, CVE-2023-41992 and CVE-2023-41993) impact various versions of macOS, iOS, iPadOS and watchOS.
Welcome back to Source Code, Decipher's weekly news wrap podcast with input from our sources.
The DHS proposed a single cyber incident reporting portal in an effort to make the process of reporting a cyberattack easier.
A new attack group named ShroudedSnooper is targeting telecom providers in Middle Eastern countries with custom tools called HTTPSnoop and PipeSnoop.
An Atlantic Council report looks at the impact of China's regulation - in effect now for two years - that requires organizations to submit notice of a software vulnerability to the Chinese government within two days of discovery.
An Iran state-backed group called Peach Sandstorm is using password spraying attacks to target cloud environments in organizations across many industries.
The malware loader was recently observed in almost two dozen email campaigns that appeared to target English speakers and involved lures related to shipping orders and billing, invoice and purchase requests or inquiries.