Security news that informs and inspires

All Articles

2230 articles:

FBI, CISA Warn Healthcare Sector of Daixin Ransomware Attacks

The Daixin group has been targeting healthcare organizations with double extortion ransomware attacks, U.S. government agencies warned.

Healthcare, Cisa, Ransomware

New Data Exfiltration Tool Seen in BlackByte Ransomware Attacks

Threat actors are using customized exfiltration tools in hopes of increasing the speed for their ransomware attacks.

Ransomware

Decipher Podcast: Source Code 10/21

Welcome to Source Code: Decipher's behind the scenes look at the weekly news with input from our sources.

Source Code, Podcast

FBI Warns of Attacks From Iranian Threat Group Emennet Pasargad

The FBI is warning companies about hack-and-leak operations from Iranian threat actor Emennet Pasargad.

Fbi

CISOs, Board Members and the Search for Cybersecurity Common Ground

Boards of directors are on track to better understand cybersecurity and its impact on their companies - and interactions with CISOs play a key role in that evolution.

CISO

Decipher Podcast: Martin Roesch Returns

Martin Roesch, CEO of Netography, joins Dennis Fisher to talk about the evolution of network security, protecting hybrid computing environments, and where that Snort pig couch came from.

Podcast

‘Milestone’ Ursnif Variant Sheds Banking Trojan Features

Ursnif's newest variant, LDR4, has been reconstructed from a banking trojan into a generic backdoor.

Malware

Security Remains a ‘Living, Breathing Task’ Long After Incidents

A panel of CISOs from companies like SolarWinds and Kaseya discussed their efforts to rebuild company culture with security in mind on the heels of massive security incidents at their organizations.

CISO, Ciso Concerns

With Attacks Underway, Fortinet Urges Customers to Patch CVE-2022-40684

Fortinet said many of its customers still have not updated to fix CVE-2022-40684, which has been under active attack for two weeks.

Fortinet, Greynoise

Critical-Severity Flaw in Apache Commons Text Library Fixed

Details about the severity and scope of the vulnerability are still emerging, including the detection of any examples of real-world applications using vulnerable configurations of the impacted library.

Apache

Prestige Ransomware Hits Targets in Ukraine and Poland

A new ransomware called Prestige has hit organizations in Poland and Ukraine using a variety of deployment methods.

Russia, Ukraine

Black Basta Uses Qakbot, Brute Ratel in Ransomware Attacks

Researchers said the attack kill chain is the first time they observed Brute Ratel being used as a second-stage payload via a Qakbot infection.

Ransomware

Attackers Exploiting Critical Fortinet Authentication Bypass

Mass exploitation of a new Fortinet authentication bypass flaw (CVE-2022-40684) is ongoing and proof of concept exploits are available.

Vulnerability, Fortinet

Decipher Podcast: Source Code 10/14

Welcome back to Source Code, Decipher’s weekly news wrap podcast.

Source Code, Podcast

Budworm Threat Group Attacks Reveal ‘Change in Focus’

The Budworm espionage group leveraged the Log4j flaw to target a number of high-value organizations worldwide, including an unnamed U.S.-based state legislature.

Log4j