The NSA and FBI have exposed a previously unknown malware tool called Drovorub that the agencies say has been deployed by APT28.
Microsoft on Tuesday patched flaws in Internet Explorer an Windows that have been used in active attacks.
The United States is trying to hammer out another data transfer agreement with the European Union after the EU Court of Justice struck down the EU-US Privacy Shield framework last month for “inadequate” privacy protections.
Amazon has patched five vulnerabilities in its AWS Encryption Client, including a CBC padding oracle flaw.
Read about Google’s SameSite update, which changes how the Chrome web browser handles third-party cookies for improved security.
Dennis Fisher is joined by Robert Hansen, CTO of Bit Discovery, to talk about finding forgotten network assets, breaking things, and building a business.
Facebook has open-sourced Python Static Analyzer, an internally-developed static code analyzer for finding and fixing flaws in Python code. Pysa analyzes how data flows through the application to identify security issues that result when data winds up in an area of the application is shouldn't be able to reach.
Reverse engineering to find the root cause of vulnerabilities can be a frustrating task, but even the analyses that go wrong can produce lessons and new skills.
Dennis Fisher is joined by Brian Donohue, Chris Brook, and Mike Mimoso to discuss the experience of watching the Black Hat talks online this year and what progress the industry has made in keeping people secure.
Security researchers have demonstrated in the past how implanted medical devices such as insulin pumps and pacemakers can be compromised. A team from Virginia Polytechnic Institute and State University investigated how these devices could be used to compromise secure facilities used to work on classified information.
Adoption of DNS over HTTPS (DoH) continues to rise, but so do concerns about network visibility and centralization of DNS services.
Dennis Fisher, Zoe Lindsey, and Pete Baker got tired of waiting for Hollywood to make sequels to some of our favorite hacker movies, so we came up with some pitches for the sequels we'd like to see.
A group of Congressional lawmakers urged the Federal Trade Commission to investigate ad-tech companies and data brokers who collect and sell consumers’ personal information.
The US government has published a detailed analysis of the Taidoor trojan it says is used by the Chinese government in network compromises.
The shift from payment cards with magnetic stripes to EMV chips was supposed to stomp out card cloning, except cybercriminals appear to have figured out a workaround.