Security news that informs and inspires

2339 articles by

CISA Issues Emergency Directive For Ivanti Flaws, Warns of ‘Widespread Exploitation’

CISA said its new emergency directive for Ivanti zero-days is “based on widespread exploitation of vulnerabilities by multiple threat actors."

CISA, Ivanti

Exploitation of Recently Patched VMware Bug Started in 2021

Threat actors exploited a critical-severity VMware flaw for almost two years before patches were released in October.

Exploit, Vulnerability

Decipher Podcast: Source Code 1/19

Welcome back to Source Code, Decipher's weekly news wrap podcast with input from our sources.

Source Code, Podcast

Russian COLDRIVER Group Uses New Backdoor to Target Governments

The Russian APT known as COLDRIVER is using a new backdoor called SPICA in phishing campaigns against NGOs and governments.

Russia, Phishing

Citrix Discloses Actively Exploited NetScaler ADC and Gateway Flaws

Flaws in Citrix NetScaler and ADC Gateway have historically been targeted by threat actors, though researchers don't believe the impact of these two bugs to match that of CitrixBleed.

Zero Day, Citrix, Citrix Netscaler