Security news that informs and inspires

All Articles

2327 articles:

FBI: BlackByte Ransomware Targeted Critical Infrastructure

The ransomware-as-a-service (RaaS) group has compromised organizations across the government, financial and food and agriculture sectors since November.

Ransomware, Critical Infrastructure

Decipher Podcast: Source Code 2/11

Welcome back to Source Code, Decipher’s weekly news podcast with input from our sources.

Podcast, Source Code

Apple Fixes Zero Day in iOS, macOS

Apple has fixed a WebKit zero day in iOS and macOS that attackers are exploiting.

Apple

Bill Would Mandate Critical Infrastructure Cyber Incident Reporting

A newly introduced legislative package would require cyber incident reporting for critical infrastructure entities.

Critical Infrastructure

Decipher Podcast: Allan Liska

Allan Liska, with Recorded Future, talks about the challenges that organizations face in implementing security measures against ransomware, and how ransomware actors are evolving their tactics.

Podcast, Ransomware

EARN IT Act Revival Renews Debate Over Online Privacy

Senators discussed the controversial act during a Judiciary Committee meeting on Thursday.

Privacy, Encryption

CISA Warns of Intensifying Ransomware Threat

CISA, the FBI, and international partners warned that ransomware groups are increasingly diversifying and targeting a wider range of organizations.

Ransomware

Microsoft to Block Macros by Default in Office Apps

Microsoft is blocking macros by default for Office, which it hopes will make abuse by cybercriminals more difficult.

Microsoft, Spear Phishing, Email

Collaboration Key to Log4j Response

The cooperative efforts of the private sector and CISA's Joint Cyber Defense Collaborative helped limit the damage of the recent Log4j vulnerability.

Log4j, Government

DoJ Seizes $3.6 Billion in Bitcoin Stolen From Bitfinex Hack

U.S. officials arrested two individuals and seized $3.6 billion in bitcoin related to the 2016 Bitfinex hack.

Cryptocurrency, Cyberattack

Microsoft Details Malware Attacks on Ukrainian Organizations

Microsoft said the Actinium threat group (also known as Gamaredon) has been observed targeting government, military and law enforcement organizations in Ukraine with spear-phishing emails.

Malware, Russia

Attackers Use SEO Poisoning to Spread Malware, Steal Credentials

SEO-friendly websites promising Zoom or TeamViewer application installations are actually attacker-owned and deploy malware.

Malware, Credentials

Decipher Podcast: Source Code 2/4

Welcome back to Source Code, Decipher’s weekly news podcast with input from our sources.

Source Code, Podcast

DHS Launches Cyber Safety Review Board

The board, tasked with identifying and sharing lessons learned from “significant cybersecurity events," will first assess the Log4j logging library flaw.

DHS, Government Agencies, Government

Critical Samba Remote Code Execution Flaw Fixed

A Samba bug could allow remote attackers without authentication to execute arbitrary code as root on impacted systems.

Vulnerability, Samba