Security news that informs and inspires

2339 articles by

Memory Safe: Casey Ellis

In the latest Decipher Memory Safe episode, Casey Ellis, founder and CTO of Bugcrowd, talks about everything from imposter syndrome to the security concept of “building it like it’s broken.”

Memory Safe, Video

Mint Sandstorm APT Targets Universities, Researchers

A new phishing campaign by a subset of the Iranian threat group Mint Sandstorm is targeting universities and research organizations with custom backdoors.

Iran

VMware Fixes Critical Aria Automation Bug

For patching, VMware said that "this situation qualifies as an emergency change."

Vmware

GitLab Patches Critical Account Takeover Flaw

The flaw (CVE-2023-7028) stems from the fact that user account password reset emails can be delivered to unverified email addresses.

Gitlab, Account Takeover

APT Group Targets Ivanti Flaws

An unidentified APT group is actively exploiting the two recently disclosed Ivanti Pulse Secure and Connect Secure vulnerabilities (CVE-2023-46805 and CVE-2024-21887).

Ivanti