Dennis Fisher talks with Katie Moussouris, Rich Mogull, Kymberlee Price, and Thomas Ptacek about the unique and inspiring life and legacy of hacker Dan Kaminsky.
Apple has fixed four zero days in WebKit for iOS, macOS, and Safari that were under active attack.
The high-severity Dell flaws could allow local attackers to gain kernel-mode privileges.
Cybercriminals have rewritten the Buer malware loader in the Rust programming language, in an attempt to avoid detection.
PulseSecure has released patches for several flaws in its Connect Secure VPN appliance, one of which has been used in active attacks for some time.
Researchers shed light on the FiveHands ransomware, which was deployed after a threat group exploited a now-patched SonicWall flaw in January.
More than 25 memory allocation flaws have been discovered in real time operating systems from Google, Amazon, and many other vendors that are used in IoT devices.
A ransomware task force has proposed a variety of technical, policy, and regulatory means for disrupting ransomware, including tracking Bitcoin transactions more closely and mandating ransom payment disclosures.
A threat campaign is relying on cross-site scripting attacks to deliver malware to and steal credentials from online shops.
The Ghostwriter influence campaign has expanded its targeting and TTPs, with researchers linking parts of it to the UNC1151 threat group.
The Naikon APT group attributed to China has been using a new backdoor known as Nebulae in attacks against military organizations in Asia.
The macOS vulnerability allowed attackers to bypass Apple’s core security defenses with specially-crafted application bundles.
An uninstall process, pushed out to infected devices as part of the takedown of Emotet by law enforcement, has been triggered to kill the malware.
An attacker was able to compromise the update mechanism for the Click Studios Passwordstate password manager and insert a malicious DLL that harvested victims' usernames and passwords.
Researchers from RiskIQ have identified 18 additional C2 servers used by the APT29 attackers in their operation against SolarWinds and its customers.