Security news that informs and inspires

All Articles

2234 articles:

Mobile Zero-Day, Phishing Attacks on the Rise

A recent report found that phishing attacks and zero-day exploits that target mobile devices have crept up over the past year.

Mobile, Phishing

Qakbot Email Thread Hijacking Attacks Drop Multiple Payloads

Researchers have observed attackers leveraging email thread hijacking tactics to spread the Qakbot malware, which in turn deploys multiple payloads.

Malware, Email

Decipher Podcast: Source Code 3/11

This week's Source Code podcast by Decipher takes a look behind the scenes at top news with input from our sources.

Source Code, Podcast

NetWalker Ransomware Suspect Sent to U.S.

A Canadian man who U.S. authorities allege is part of the NetWalker ransomware operation has been extradited to the U.S.

Ransomware

Online Contact Forms Used in BazarLoader Attacks

Threat actors are attempting to gain the trust of victims by pretending to be a potential customer and filling out an online contact form before launching the BazarLoader attack.

Malware, Email

Alleged REvil Operator Extradited to U.S.

A Ukrainian man charged with using the REvil ransomware in the attack on Kaseya last summer has been extradited to the U.S. and arraigned in Texas.

Ransomware

SEC Proposes Four-Day Security Incident Reporting Mandate

Beyond the SEC, lawmakers and federal agencies at a broader level are examining cyberattack reporting deadlines.

Cyberattack, Federal Cybersecurity

FBI Warns of Ragnar Locker Attacks on Critical Infrastructure

The FBI says that the Ragnar Locker ransomware group has compromised more than 50 critical infrastructure organizations in the U.S.

Ransomware

Q&A: Runa Sandvik

Runa Sandvik, who provides consultation services to journalists for cybersecurity, explains the unique challenges that newsrooms face in securing their environments.

Q&a, Privacy

Critical RCE Flaws Impact Medical Devices

Patches are available for three critical-severity remote code execution flaws that affect more than 150 devices, including medical imaging and laboratory products.

Vulnerability, Medical Devices

Decipher Podcast: Runa Sandvik

Runa Sandvik discusses her work helping journalists to secure their devices and how more newsrooms are recognizing the need for better cybersecurity measures.

Podcast

APT41 Compromised Six U.S. State Government Networks

The prolific APT group compromised state government networks by exploiting the Log4j flaw and a vulnerability in an animal health emergency reporting system.

Log4j, China, Government Agencies, State Government

Mozilla Fixes Two Firefox Flaws Under Attack

Two critical Firefox use-after-free zero-day vulnerabilities have been fixed.

Firefox, Mozila, Vulnerability

Serious ‘Dirty Pipe’ Bug Patched in Linux Kernel

A serious kernel bug (CVE-2022-0847) that allows an attacker to write any data to an arbitrary file has been fixed in Linux and Android.

Linux

Trio of Flaws Allows Remote Takeover of Some APC UPS Devices

Three vulnerabilities in some models of APC UPS devices can allow an attacker to upload a malicious firmware image and use the devices for further network attacks.

ICS Security