Security news that informs and inspires

All Articles

2239 articles:

CISOs Navigate Legal Risks After Former Uber Executive’s Conviction

High-profile legal cases have set CISOs on edge about the liabilities they face while working through major security incidents at organizations.

CISO, Ciso Concerns

Decipher Podcast: Source Code RSA Conference Edition

This week at the RSA Conference, software supply-chain security, CISO liabilities and public-private sector partnerships were some of the key topics.

Podcast, Source Code

PaperCut Flaws Exploited to Deploy Clop, LockBit Ransomware

Microsoft has attributed exploitation attempts of CVE-2023-27350 and CVE-2023-27351 to a Clop ransomware affiliate.

Ransomware, Lockbit, Clop, Microsoft

Google Disrupts Massive CryptBot Malware Operation

A new court order allows Google to take down current and future domains tied to the distribution of the CryptBot infostealer.

Malware

Software Supply Chain Security: ‘An Everybody Problem’

At the RSA Conference this week, government officials and cybersecurity executives mulled over the multiple layers of challenges in securing the software supply chain.

Software Security, Supply Chain Security, Rsa Conference

Decipher Podcast: Chris Wysopal and Cris Thomas

Chris Wysopal and Cris Thomas of the L0pht join Dennis Fisher to talk about the 25-year-anniversary of the group's landmark Senate testimony, what's changed since then, and Cris's new book, How the Hackers Known as L0pht Changed the World.

Podcast

International Cooperation Key to Ransomware Fight

Top cybersecurity officials from the U.S., U.K., and other allies say international cooperation among intelligence and law enforcement agencies has been a key factor in successful operations against ransomware groups.

RSA, Government, Ransomware

Mirai Botnet Attackers Exploit TP-Link Router Bug

Researchers began to detect exploit attempts in the wild targeting the patched, high-severity flaw in TP-Link routers starting on April 11.

Mirai, Malware, Exploit

Iranian Hackers Blocked After Gaining Access to 2020 Municipal Election Infrastructure

Government officials talked about how agencies have partnered to address election security, the SolarWinds cyberattack and the Hafnium threat group's exploitation of Exchange servers.

Rsac, Solarwinds, Election Security

New MacOS Malware Emerges in North Korean APT Attacks

A new macOS malware, called "RustBucket," is used in a multi-stage attack.

Lazarus, North Korea

Decipher Podcast: Source Code 4/21

Welcome back to Source Code, Decipher's weekly news wrap podcast with input from our sources.

Source Code, Podcast

Ransomware Groups Use New AuKill Tool to Slip Under the Radar

Ransomware actors are utilizing a tool that abuses an out-of-date Windows driver in order to kill security software.

Malware, Ransomware

Decipher Podcast: Casey Ellis Returns

Casey Ellis, founder and CTO of Bugcrowd, joins Dennis Fisher to discuss the newly formed Hacking Policy Council, the challenges of influencing security research policy and legislation, and what the council hopes to achieve.

Podcast

Earlier Supply Chain Attack Led to 3CX Intrusion

An intrusion at a separate company led to the supply chain attack on 3CX that was disclosed last month, investigators said.

Supply Chain Security

Google Fixes Chrome Zero-Day Flaw

The Chrome flaw is the second zero-day bug in a week that Google has addressed.

Google, Google Chrome, Chromeos Security, Zero Day