3 Things We Still Don’t Know About the XZ Backdoor
The XZ Utils backdoor was a very subtle operation that took several years to pull off, and while some of the technical details are
He is one of the co-founders of Threatpost and previously wrote for TechTarget and eWeek, when magazines were still a thing that existed. Dennis enjoys finding the stories behind the headlines and digging into the motivations and thinking of both defenders and attackers. His work has appeared in The Boston Globe, The Improper Bostonian, Harvard Business School’s Working Knowledge, and most of his kids’ English papers.
The XZ Utils backdoor was a very subtle operation that took several years to pull off, and while some of the technical details are
The Cyber Safety Review Board cited a string of internal failures in Microsoft's security culture as contributing factors for the
The U.S. has announced sanctions against a Chinese state-backed company and two individuals, as well as indictments against seven
CISA and the FBI are warning that APT groups are exploiting a critical flaw (CVE-2021-44077) in the ManageEngine ServiceDesk Plus tool.
Mozilla has fixed a critical buffer overflow in its NSS cryptographic library that had been lurking in the code for several years.
The TA505 threat group known for using the Clop ransomware and Dridex trojan is now using a new P2P RAT.
VirusTotal has added a Collections feature to enable better real-time sharing of IOCs and context around malicious files and URLs.
Apple has sued NSO Group for allegedly abusing the company's iCloud servers and injuring its customers.