3 Things We Still Don’t Know About the XZ Backdoor
The XZ Utils backdoor was a very subtle operation that took several years to pull off, and while some of the technical details are
He is one of the co-founders of Threatpost and previously wrote for TechTarget and eWeek, when magazines were still a thing that existed. Dennis enjoys finding the stories behind the headlines and digging into the motivations and thinking of both defenders and attackers. His work has appeared in The Boston Globe, The Improper Bostonian, Harvard Business School’s Working Knowledge, and most of his kids’ English papers.
The XZ Utils backdoor was a very subtle operation that took several years to pull off, and while some of the technical details are
The Cyber Safety Review Board cited a string of internal failures in Microsoft's security culture as contributing factors for the
The U.S. has announced sanctions against a Chinese state-backed company and two individuals, as well as indictments against seven
The FBI IC3 Internet Crime Report shows more than $1.7 billion in looses from BEC scams, far more than from any other kind of cybercrime activity it tracks.
Google has patched a critical Bluetooth flaw in Android that could give an attacker control of a vulnerable device without any user interaction.
The Department of Justice indicted four members of China's People's Liberation Army in connection with the Equifax data breach in 2017.
Cisco has patched five serious vulnerabilities that affect routers, switches, and IP phones and cameras with the Cisco Discovery Protocol enabled.
Web shell attacks have been on the rise in recent months, as many APT groups employ them against enterprises.