Security news that informs and inspires

2376 articles by

Citrix ADC Exploits Appear With No Patch Available Yet

Exploits for the CVE-2019-19781 Citrix ADC vulnerability are available on GitHub while patches are still a week away.

Citrix

Microsoft Patches Flaw in Windows Cryptography Component

Microsoft fixed a vulnerability in a cryptography component used by Windows 10 and Windows Server. If exploited, attackers would be able to pass off malicious software as legitimate, thus undermining digital trust.

Patch, Microsoft

Industry Groups Don’t Like Commerce Department’s Supply Chain Security Rules

Multiple business groups have pushed back on the Department of Commerce's proposed supply chain rules on information and communications technology supply chain security due to vague language and undefined scope.

Supply Chain, Government

‘We Can’t Be Complacent’ About the Crypto Debate

The encryption debate is as old as the Internet, and Jennifer Granick warns that giving ground now could have serious long-term effects.

Encryption, Privacy

Microsoft Mines Events Logs for RDP Brute-Force Attacks

Microsoft looked at Windows Events Log to understand what RDP brute-force attacks looked like in the enterprise, and found that attackers frequently space out the login attempts over several days to avoid detection.

RDP, Malware, Remote Access Attacks