Java Crypto Bug Allows Forging of Signatures, Certificates
A critical bug in Java's implementation of ECDSA (CVE-2022-21449) can allow an attacker to forge a signature or certificate to...
He is one of the co-founders of Threatpost and previously wrote for TechTarget and eWeek, when magazines were still a thing that existed. Dennis enjoys finding the stories behind the headlines and digging into the motivations and thinking of both defenders and attackers. His work has appeared in The Boston Globe, The Improper Bostonian, Harvard Business School’s Working Knowledge, and most of his kids’ English papers.
A critical bug in Java's implementation of ECDSA (CVE-2022-21449) can allow an attacker to forge a signature or certificate to...
The U.S. government and military is looking to attract and retain more talented cyber operators to keep pace with the evolving...
The U.S. has indicted four Russians it alleges are affiliated with the FSB and GRU units responsible for the Triton and...
Cisco has patched a flaw in IOS XR that can allow an attacker to write arbitrary files to the Redis instance.
QNAP is urging customers to remove NAS devices from the Internet amid a new wave of Deadbolt ransomware intrusions.
NVIDIA has released an update to fix a number of serious code-execution flaws in its GPU display driver that could be used to perform guest-to-host escapes.
NCC Group researchers have shown a novel relay attack against Bluetooth Low Energy proximity authentication systems.
Three serious flaws, including an authentication bypass, a shared hard-coded encryption key, and an open redirect, have been patched in the SonicWall SMA 1000 SSL VPNs.