Java Crypto Bug Allows Forging of Signatures, Certificates
A critical bug in Java's implementation of ECDSA (CVE-2022-21449) can allow an attacker to forge a signature or certificate to...
He is one of the co-founders of Threatpost and previously wrote for TechTarget and eWeek, when magazines were still a thing that existed. Dennis enjoys finding the stories behind the headlines and digging into the motivations and thinking of both defenders and attackers. His work has appeared in The Boston Globe, The Improper Bostonian, Harvard Business School’s Working Knowledge, and most of his kids’ English papers.
A critical bug in Java's implementation of ECDSA (CVE-2022-21449) can allow an attacker to forge a signature or certificate to...
The U.S. government and military is looking to attract and retain more talented cyber operators to keep pace with the evolving...
The U.S. has indicted four Russians it alleges are affiliated with the FSB and GRU units responsible for the Triton and...
Google has patched a zero day in the V8 engine in Chrome that is under active attack.
A recent campaign targeted Azure developers with malicious npm packages designed to look like legitimate tools.
The U.S. has indicted four Russians it alleges are affiliated with the FSB and GRU units responsible for the Triton and Dragonfly attacks against critical infrastructure in the United States and abroad.
The Lapsus$ hacking and extortion group claims to have had access to internal Okta systems since January, but the company said it looked into the incident at a third party and it was contained.
A new initial access broker known as Exotic Lily has used exploits for zero days and sells network access to cybercrime teams such as FIN12 for ransomware deployment.