Security news that informs and inspires

All Articles

2239 articles:

Decipher Podcast: Larry Cashdollar

Larry Cashdollar, a senior security researcher at Akamai, joins Dennis Fisher to talk about 20 years of vulnerability research and the many different ways that things can go sideways.

Podcast

Universal Health Services Network Knocked Offline

A security incident at Universal Health Services has taken the network of the large health system offline.

Ransomware

Framework Outlines How Companies Should Talk About Breaches

Organizations are increasingly developing incident response playbooks to plan out in advance what steps to take in case of a security breach—such as an employees accessing files without authorization, a lost computer, or a server compromised by outside attackers. A team of academics from the UK's University of Kent and University of Warwick outlined a comprehensive playbook on how organizations should communicate after a security incident.

Data Breaches, Incident Response

Attackers Actively Targeting Zerologon Flaw, Microsoft Warns

The Zerologon vulnerability Microsoft patched in Windows Server last month is actively being exploited in several attacks, Microsoft warned.

Patch, Microsoft

Compromised Credentials Used in Attack Against Federal Agency

An intruder breached a federal agency’s internal network and accessed data files using compromised credentials and custom malware, the Cybersecurity and Infrastructure Security Agency said in an Analysis Report.

Government, Data Breaches

LokiBot Activity Spikes, CISA Warns

CISA alerted administrators that activity from the LokiBot information stealing trojan has been increasingly sharply since July.

Malware

SAFE DATA Act Joins Crowded Field of Privacy Bills

The SAFE DATA Act is the latest attempt to pass a national privacy law, but it relies on notice-and-consent and does not apply to federal agencies.

Privacy

CISA Orders Agencies to Patch Zerologon Flaw

Federal agencies have until the end of Monday to install fixes for a recently-fixed elevation of privilege vulnerability in Windows which could be used to take control of the entire network, CISA said in an emergency directive.

Patch, Windows, Government

MITRE Releases FIN6 Emulation Plan

MITRE’s latest project is a public library of detailed plans replicating tactics and techniques used by known attack groups. The first set of adversary emulation plans released this week describe the behavior of cybercrime group FIN6.

Cybercrime, Attacker, Attack Simulations

Tech, Privacy Groups Urge Senators to Oppose EARN IT Act

A large coalition of privacy and civil liberty groups have sent a letter urging senators to oppose the EARN IT Act.

Privacy, Encryption

US Charges Five Alleged Members of APT41 Group

The Department of Justice has charged five men with hacking offenses in connection with operations by the APT41 group from China.

Government

House Passes IoT Security Bill

The House of Representatives has unanimously passed a bipartisan bill setting minimum security requirements for Internet of Things devices connected to federal networks. The next step: get the Senate to vote on its version of the bill.

Iot Security

Chinese State-Sponsored Attackers Target F5, VPN Flaws

CISA says attackers affiliated with China's Ministry of State Security have been targeting public vulnerabilities in VPN appliances and F5 networking gear.

Government, China

Attackers Verify O365 Credentials On Microsoft Entra ID

Attackers are cross-checking stolen Office 365 credentials on Microsoft Entra ID in real-time after victims type them into a malicious phishing page, researchers from Armorblox said.

Phishing, Office 365, Azure, Azure AD, Active Directory

Raccoon Attack Can Compromise Some TLS Connections

A new technique called the Raccoon attack can break the confidentiality of some TLS connections under certain circumstances.

Encryption, Vulnerability