Security news that informs and inspires
scrambled headshot of Dennis Fisher

Dennis Fisher

Editor in Chief

Dennis Fisher is an award-winning journalist who has been covering information security and privacy since 2000.

He is one of the co-founders of Threatpost and previously wrote for TechTarget and eWeek, when magazines were still a thing that existed. Dennis enjoys finding the stories behind the headlines and digging into the motivations and thinking of both defenders and attackers. His work has appeared in The Boston Globe, The Improper Bostonian, Harvard Business School’s Working Knowledge, and most of his kids’ English papers.

Featured Articles

1175 articles by Dennis Fisher

New OpenSSH CVE-2024-6409 Flaw Emerges

A week after the disclosure of the regreSSHion CVE-2024-6387 flaw in OpenSSH, researchers have found a related flaw (CVE-2024-6409) in some recent versions of the library.

Openssh

Decipher Podcast: Chris Hughes

Chris Hughes, co-founder of Aquia and a Cyber Innovation Fellow at the Cybersecurity and Infrastructure Security Agency, joins Dennis Fisher to talk about the challenges of supply chain security, working with the government to address systemic issues, and the importance of collaboration.

Podcast, Government, CISA

Researchers Warn of Widespread Polyfill Supply Chain Attack

The popular polyfill.io JavaScript library has been used to inject malicious code into thousands of sites in the last few days.

Vulnerabilitiy, Supply Chain Security

Chinese APT Moves to Ransomware in Some Intrusions

A Chinese APT known as ChamelGang has been deploying the CatB ransomware in some intrusions around the world.

China

Serious Flaws Fixed in ExpressionEngine CMS

Packet Tide has fixed a group of XSS vulnerabilities and an open HTTP redirection bug in its ExpressionEngine content management system, some of which could give an attacker admin access.

Vulnerabilities