Security news that informs and inspires

2376 articles by

Lazarus Group Affiliate Uses Trojanized Open Source Apps in New Campaigns

Zinc, a Lazarus group offshoot, is using trojanized versions of open source apps such as KiTTY and PuTTY in a new phishing campaign.

North Korea, Microsoft

New Chaos Malware Targets Windows and Linux Devices

A new piece of malware known as Chaos that is built for Windows and Linux systems is infecting home routers, enterprise servers, and other devices and launching DDoS attacks.

Malware, Botnet, China

Phishing Attack Targets Microsoft Flaw to Deliver Cobalt Strike

The attack was first discovered in August after victims received phishing emails containing malicious document attachments.

Phishing

Node.js Update Fixes High Severity Flaws

An update for the Node.js framework includes fixes for DNS rebinding and HTTP smuggling vulnerabilities.

Vulnerabilities, Javascript

Watchdog Report Highlights Nuclear Agency’s Security Shortcomings

The Government Accountability Office criticized the National Nuclear Security Administration's mixed risk management practices around operational technology devices and its lax oversight of subcontractor cybersecurity practices.

Government, Government Agencies