Security news that informs and inspires

All Articles

1900 articles:

Q&A: Bryan Willett

Bryan Willett, CISO at Lexmark, talks about why a “silver bullet” doesn’t exist in security and what he describes as a “multi-pronged” approach to building out a security program.

Ciso Q&a

LastPass Attacker Compromised Employee’s Personal Machine

An attacker who stole corporate and customer data from LastPass in 2022 gained initial access by compromising an engineer's personal computer.

Lastpass, Data Breach

CISA Director: ‘Strong Security Has to Be a Standard Feature’

CISA Director Jen Easterly called on technology companies to focus on building products more securely and to stop shifting the burden for safety to customers.

Government, Sbom, Software Security

Possible New Lazarus Group Backdoor Found

A new backdoor called WinorDLL that is potentially the work of the Lazarus Group has been found onn victim machines in several countries.

North Korea, Lazarus Group

New Attack Group Focuses on Asian Medical and Shipping Companies

A newly identified attack group known as Hydrochasma has targted medical and shipping companies in Asia with spear phishing campaigns that use freely available tools.


Fortinet Fixes Critical Flaw in FortiNAC

Fortinet has patched a critical remote code execution bug in its FortiNAC product.


Critical RCE Bug Fixed in ClamAV

A critical remote code execution vulnerability has been fixed in the ClamAV anti-malware engine.


Q&A: J Wolfgang Goerlich

J Wolfgang Goerlich, Advisory CISO for Cisco Secure, talks about why relationships are so important for CISOs when interacting with organizational leadership teams.

Ciso Q&a

ESXiArgs Ransomware Infections Spike

A new spike in ESXiArgs ransomware infections has emerged in the last couple of days, targeting servers in the UK and Europe.

Vmware, Ransomware

Microsoft Patches Three Actively Exploited Bugs

In its February patch release, Microsoft fixed three vulnerabilities in Windows that have been actively exploited.


CISA Warns of Ongoing Ransomware Attacks by North Korean Actors

CISA, the FBI, and NSA are warning about ongoing ransomware attacks by North Korean groups that target government agencies and defense companies.

North Korea, Ransomware

‘We Are at the Time’s Up Phase for Industrial Security’

New data from Dragos shows that ransomware attacks against ICS systems are increasing, and sophisticated malware designed for those environments is now a reality.

Ransomware, Ics

Attacker Accessed Some Reddit Code, Business Systems

A phishing attack allowed an attacker to steal a Reddit employee's credentials and gain access to some internal company systems last week.


U.S., U.K. Governments Sanction Alleged Members of Trickbot Malware Group

The U.S. and U.K. governments have sanctioned seven Russian men whom they allege are members of the Trickbot cybercrime group.

Ransomware, Russia

Fortra Patches Actively Exploited Zero Day in GoAnywhere MFT

Fortra has released version 7.12 of its GoAnywhere mFT file transfer tool to fix a zero day that has been under active attack.

Zero Day