Security news that informs and inspires

All Articles

2349 articles:

After Microsoft Macro Malware Crackdown, Attackers Explore New Options

After Microsoft started blocking macros obtained from the internet by default, email attackers are exploring alternative techniques to distribute Emotet, Qakbot, IcedID and other payloads.

Malware, Microsoft

U.S. Offers $15M in Rewards for Conti Ransomware Group Information

The U.S. government is offering monetary rewards for information about Conti's leaders, affiliates and operators.

Ransomware

Exploits Emerge for Critical F5 Flaw

Exploits for the critical F5 BIG-IP flaw (CVE-2022-1388) are now circulating online and malicious actors are scanning for it.

F5

New Law Aims to Revamp Federal Cybercrime Tracking

The Better Cybercrime Metrics Act aims to help streamline the consistent reporting of cybercrime incidents.

Government, Fbi

Decipher Podcast: Source Code 5/6

This week's Source Code podcast by Decipher takes a look behind the scenes at top news with input from our sources.

Podcast, Source Code

New Malware Framework Distributed Via Pay-Per-Install Service

The malware framework contains a loader, dropper and a remote access trojan with its own network communication protocol.

Malware

GitHub to Require 2FA for All Users

GitHub will require 2FA for all users who contribute code on the platform by the end of 2023.

Github, 2fa

Decipher Podcast: Jonathan Reiber

Lindsey O'Donnell-Welch speaks with Jonathan Reiber, vice president, Cybersecurity Strategy and Policy at AttackIQ.

Podcast

Threat Actor Increases Dwell Time By Targeting Opaque Devices

A newly discovered suspected espionage threat actor is targeting companies that focus on corporate development, mergers and acquisitions and large corporate transactions.

APT

Curl Flaw Could Allow Authentication Bypass

Several versions of curl and the curl library contain a pair of security flaws.

Vulnerability

Man Convicted in Phishing Scam That Cost U.S. DoD $23.5M

A $23.5 million phishing scheme was carried out in 2018 that impacted the U.S. Department of Defense.

Phishing

Breaking Down the CISA Budget Proposal: Critical Infrastructure, Federal Security Investments

Overall, the proposed fiscal year 2023 budget represents an 18 percent increase over the requested budget for fiscal year 2022, reflecting a "significantly increased investment" in CISA.

CISA, Government Agencies

Decipher Podcast: Source Code 4/29

This week's Source Code podcast by Decipher takes a look behind the scenes at top news with input from our sources.

Podcast, Source Code

New Bumblebee Malware Loader in Active Development

Researchers speculate that the emerging loader is a replacement for the BazaLoader malware.

Malware

Behind the Rapidly Shifting Ransomware Ecosystem

Many of the top ransomware groups in 2021 have disappeared, while several new groups have emerged with high levels of activity.

Ransomware