Java Crypto Bug Allows Forging of Signatures, Certificates
A critical bug in Java's implementation of ECDSA (CVE-2022-21449) can allow an attacker to forge a signature or certificate to...
He is one of the co-founders of Threatpost and previously wrote for TechTarget and eWeek, when magazines were still a thing that existed. Dennis enjoys finding the stories behind the headlines and digging into the motivations and thinking of both defenders and attackers. His work has appeared in The Boston Globe, The Improper Bostonian, Harvard Business School’s Working Knowledge, and most of his kids’ English papers.
A critical bug in Java's implementation of ECDSA (CVE-2022-21449) can allow an attacker to forge a signature or certificate to...
The U.S. government and military is looking to attract and retain more talented cyber operators to keep pace with the evolving...
The U.S. has indicted four Russians it alleges are affiliated with the FSB and GRU units responsible for the Triton and...
The takedown of the infamous Hydra market has had lasting effects on the cybercrime underground and cryptocurrency laundering ecosystem.
The Russian government's tolerance and sometime cooperation with the cybercriime groups in the country makes the threat from both factions even more serious, US officials say.
A newly disclosed zero day in some versions of Atlassian Confluence and Data Center is under attack and being used to install webshells on target servers.
The Karakurt data extortion group is stealing sensitive information from enterprises and holding it for ransom, CISA warns.
A zero day flaw (CVE-2022-30190) in Windows and Office is under active attack and MIcrosoft has not issued a patch yet.