Security news that informs and inspires

All Articles

2237 articles:

SolarWinds Attackers Accessed Mimecast Source Code

The attackers behind the SolarWinds breach also gained access to and downloaded some Mimecast source code repositories.

Solarwinds, Email

Decipher Podcast: Andrew Morris

Andrew Morris, founder of GreyNoise, joins Dennis Fisher to talk about the unique origins of the company and the security case for removing all of the background noise from the Internet to find what really matters.

Podcast

Microsoft Releases One-Click Mitigation for Exchange Flaw

Microsoft has published a new tool that installs a mitigation for the CVE-2021-26855 Exchange ProxyLogon flaw.

Microsoft

Number of Exchange Servers Vulnerable to ProxyLogon Declines

The number of Exchange servers vulnerable to the ProxyLogon flaws is continuing to drop, but there are still more than 60,000 online.

Microsoft

DearCry Ransomware Hitting Exchange Servers

Attackers are installing the DearCry ransomware on some vulnerable Exchange servers.

Ransomware, Microsoft

Decipher Podcast: Joe Slowik

Joe Slowik, senior security researcher at Domaintools, joins Dennis Fisher to discuss the Exchange vulnerabilities, the exploitation activity timeline, and the question of attribution.

Podcast

Four Critical Flaws Hit F5 BIG-IP Boxes

F5 has patched four critical flaws in its BIG-IP appliances, all of which can lead to remote code execution.

F5, Networking

ThreatFox Aims to Simplify IOC Sharing

The new ThreatFox platform from Abuse.ch is designed to allow researchers to share IOCs freely and easily without the need to register or subscribe to a feed.

Threat Intelligence

GitHub Fixes Bug That Could Have Routed Authenticated Sessions to Other Users

GitHub has patched a flaw in a backend system that in rare cases could have routed one user's authenticated session to another user's browser.

Software Security

Microsoft Fixes IE 0-Day Used in Attacks on Researchers

Microsoft has patched a zero day in Internet Explorer and Edge that was used in attacks against security researchers.

Microsoft

Attacks on Exchange Servers Spread

Attacks on the Exchange server flaws disclosed last week are being exploited by multiple threat actors and targeting a wide range of companies.

Microsoft

‘The Whole World is Built on Software’

MiIke Hanley, the new GitHub CSO, sees myriad opportunities to have a positive influence on software security.

Software Development

Exchange Attacks Hitting Broad Range of Organizations

Attackers are using the four Microsoft Exchange zero days to target organizations from SMBs to government agencies and banks.

Microsoft

Hafnium Attack Group Exploiting Four Exchange Zero Days

A Chinese attack group called Hafnium has exploited for zero days in Microsoft Exchange to steal data from inboxes and take control of compromised servers.

Microsoft, China

ObliqueRAT Delivered Via Rigged Image Files

The ObliqueRAT malware is now being delivered through malicious image files hosted on compromised websites.

Malware