Mirai botnet loves exploiting your unpatched TP-Link routers, CISA warns Oracle and Apache holes also on Uncle Sam's list of big bad abused bugs Patches02 May 2023 | 1
Google adds account sync for Authenticator, without E2EE in brief Also: Your Salesforce Community site might be leaking; a new CPU side-channel; and this week's critical vunls Security01 May 2023 | 7
Menaced by miscreants, critical infrastructure needs a good ETHOS. Ah, here's one RSA Conference OT firms construct handy early-warning info-sharing system Spotlight on RSA25 Apr 2023 | 5
US cyber chiefs warn AI will help crooks, China develop nastier cyberattacks faster It's not all doom and gloom because ML also amplifies defensive efforts, probably CSO12 Apr 2023 | 13
40% of IT security pros say they've been told not to report a data leak In Brief Plus: KFC, Pizza Hut owner spills more beans on ransomware hit... latest critical flaws... and more Cyber-crime11 Apr 2023 | 16
It's this easy to seize control of someone's Nexx 'smart' home plugs, garage doors Netizens urged to disconnect kit after 40,000-plus devices found riddled with dumb bugs Security07 Apr 2023 | 41
CISA unleashes Untitled Goose Tool to honk at danger in Microsoft's cloud Not a headline we expected to write today CSO24 Mar 2023 | 11
Critical infrastructure gear is full of flaws, but hey, at least it's certified Security researchers find bugs, big and small, in every industrial box probed CSO23 Mar 2023 | 20
CISA joins forces with Women in CyberSecurity to break up the boy's club in brief Also, the FBI just admitted to bypassing warrants by buying cellphone location data, and this week's actionable items Security13 Mar 2023 | 17
EPA orders US states to check cyber security of public water supplies Don’t let miscreants poison the wells Security06 Mar 2023 | 8
US cybersecurity chief: Software makers shouldn't lawyer their way out of security responsibilities SCSW Who apart from Microsoft is happy with the ship now, oh just fix it later approach? Security28 Feb 2023 | 30
ESXiArgs ransomware fights off Team America's data recovery script Want a clue to what you’re dealing with? Check the ransom note Security16 Feb 2023 | 1
Among the thousands of ESXiArgs ransomware victims? FBI and CISA to the rescue Evil code hits more than 3,800 servers globally, according to the Feds Security08 Feb 2023 | 1
CISA sends schools back to the classroom on security Oy, teacher, protect those kids online Government Tech Week25 Jan 2023 | 1
Homeland Security, CISA builds AI-based cybersecurity analytics sandbox High-spec system is crucial to defending against the latest threats Government Tech Week10 Jan 2023 | 5
FBI warns about Cuba, no, not that one — the ransomware gang Critical infrastructure attacks ramping up Security02 Dec 2022 | 1
US military goes zero-trust on software and government gets busy CISA updates security framework, tech industry calls it 'confusing' Software23 Nov 2022 | 13
LockBit suspect cuffed after ransomware forces emergency services to use pen and paper In Brief Plus: CISA has a flowchart for patching, privacy campaign goes after face search engine Cyber-crime12 Nov 2022 | 13
Biden now wants to toughen up chemical sector's cybersecurity Control panels facing the internet? Data stolen? You gotta keep an ion this stuff CSO27 Oct 2022 | 6
Alert: This ransomware preys on healthcare orgs via weak-ass VPN servers FBI, CISA warn of Daixin gang after OakBend Medical Center hit Cyber-crime24 Oct 2022 | 1
CISA warns of security holes in industrial Advantech, Hitachi kit When we concede that everything has bugs, we wish it wasn't quite everything Patches20 Oct 2022 | 2
It’s 2022 and netizens are only now getting serious about cybersecurity US folks start to get the message about protecting themselves online Security10 Oct 2022 | 12
Foreign spies hijacking US mid-terms? FBI, CISA are cool as cucumbers about it I think we can handle one little Russia. We sent two units, they're bringing any attempts down now Security06 Oct 2022 | 40
Cyber-snoops broke into US military contractor, stole data, hid for months Tell us it’s Russia without telling us it’s Russia Security05 Oct 2022 | 14
Uncle Sam orders federal agencies to step up scans for govt IT security holes Good time to be selling automation tools Security04 Oct 2022 | 2
Atlassian, Microsoft bugs on CISA’s must-patch list after exploitation spree Some days, security just feels like a total illusion. OK, most days... Patches04 Oct 2022 | 7
National Cybersecurity Awareness program 18 years on: Don't click that Technology is addressing many of the cyberthreats, but the human element will always be a factor Security03 Oct 2022 | 3
US school year opens with reading, writing, and ransomware FBI warns that Vice Society threat group is ramping up attacks on the education sector Cyber-crime07 Sep 2022 | 8
Microsoft: The deadline to get off Basic Auth is approaching Exchange Online face Halloween deadline OSes05 Sep 2022 | 50
80,000 internet-connected cameras still vulnerable after critical patch offered Just more IoT conscripts for the botnet armies Patches24 Aug 2022 | 15
If you haven't patched Zimbra holes by now, assume you're toast Here's how to detect an intrusion via vulnerable email systems Patches23 Aug 2022 |
US reveals 'Target' pic of Conti man with $10m reward offer Fashion Police chipping in on the bounty related to costliest strain of ransomware on record Security12 Aug 2022 | 6
Maui ransomware linked to North Korean group Andariel Attack origins point to April 2021 first strike on Japanese target Security10 Aug 2022 | 1
DuckDuckGo says Hell, Hell, No to those Microsoft trackers after web revolt In brief Plus: That Twitter privacy leak, scammers send Ubers for victims, critical flaw in Cisco gear, and more Security06 Aug 2022 | 38
US puts $10 million bounty on North Korean cyber-crews Kim will be shaking in his shoes Security27 Jul 2022 | 7
Security flaws in GPS trackers can be abused to cut off fuel to vehicles, CISA warns About '1.5 million' folks and organizations use these gadgets Security19 Jul 2022 | 29
Start using Modern Auth now for Exchange Online Before Microsoft shutters basic logins in a few months CSO29 Jun 2022 | 28
Don't ditch PowerShell to improve security, say infosec agencies from UK, US, and NZ Use it sensibly instead – which means turning on the useful bits Microsoft doesn't enable by default Security23 Jun 2022 | 20
OpenInfra Foundation talks about Directed Funding model for open source projects OpenInfra Berlin Notes rise of 'pay to play' where companies try to buy way into governance – and says this is not that PaaS + IaaS14 Jun 2022 |
Beijing-backed baddies target unpatched networking kit to attack telcos NSA, FBI and CISA issue joint advisory that suggests China hardly has to work for this – flaws revealed in 2017 are among their entry points Security08 Jun 2022 | 3
US cyber chiefs: Moving to Shields Down isn't gonna happen RSA Conference Promises new alert notices but warn 'we can sometimes predict thunderstorms but not lightning strikes' CSO08 Jun 2022 | 6
FBI, CISA: Don't get caught in Karakurt's extortion web Is this gang some sort of Conti side hustle? The answer may be yes CSO03 Jun 2022 | 7
Talos names eight deadly sins in widely used industrial software Entire swaths of gear relies on vulnerability-laden Open Automation Software (OAS) Patches27 May 2022 | 6
Patch your VMware gear now – or yank it out, Uncle Sam tells federal agencies Critical authentication bypass revealed, older flaws under active attack CSO19 May 2022 | 6
Software patching must work like car safety recalls, says US cyber boss Black Hat Asia Adds infosec regulation coming to more industries but with a light touch, more collaboration CSO13 May 2022 | 30
Data-wiper malware strains surge as Ukraine battles ongoing invasion Besides files being erased, another thing being deleted: Any sense this is a coincidence Research29 Apr 2022 | 11
Five Eyes nations reveal 2021's fifteen most-exploited flaws Malicious cyber actors go after 2021's biggest misses, spend less time on the classics Security28 Apr 2022 | 10
Five Eyes nations fear wave of Russian attacks against critical infrastructure If this is surprising to operators, we are doomed Cyber-crime21 Apr 2022 | 25
US warns North Korean Lazarus gang rising against cryptocurrency outfits Malware-laced recruitment emails are more Kim job ill than Kim Jong-un Security20 Apr 2022 | 5
Threat group builds custom malware to attack industrial systems US security agencies say the tools can give hackers control of ICS and SCADA devices Security14 Apr 2022 | 8
Microsoft dogs Strontium domains to stop attacks on Ukraine Software giant sinkholes systems used by Russian gang Security08 Apr 2022 | 33
China accused of cyberattacks on Indian power grid Beijing may have had a hand in attacks in Ukraine, too Security08 Apr 2022 | 24
Russia-linked attackers breach NGO by exploiting MFA, PrintNightmare vuln Patch flaws and enforce authentication policies, CISA and FBI warn Security16 Mar 2022 | 3
Analysis of leaked Conti files blows lid off ransomware gang Not only is this payback sweet, it gives network defenders valuable intelligence Security11 Mar 2022 | 21
China-linked malware targeted secure networks in 'multiple governments' 'Daxin' malware creates backdoors and may have been used since 2013 Security01 Mar 2022 | 3
CISA publishes list of free security tools for business protection Agency quiet on the selection criteria but at least the price is right Security18 Feb 2022 | 6
Russia 'stole US defense data' from IT systems Clearly no need for leet zero-day hax when you can spearphish and exploit months-old vulnerabilities Security17 Feb 2022 | 35
US govt: Here are another 15 security bugs under attack right now Best plug HiveNightmare if you haven't already, unless you like new admins Security11 Feb 2022 | 10
Sniff those Ukrainian emails a little more carefully, advises Uncle Sam in wake of Belarusian digital vandalism NotPetya started over there, don't forget Security19 Jan 2022 | 4
As CISA tells US govt agencies to squash Log4j bug by Dec 24, fingers start pointing at China, Iran, others Microsoft says cyber-spies linked to Beijing, Tehran are getting busy with security flaw along with world + dog Security15 Dec 2021 | 11
BlackMatter ransomware gang will target agriculture for its next harvest – Uncle Sam What was that about hackable tractors? Security19 Oct 2021 | 3
America enlists Big Tech to help it develop and execute cyber security plans Players in ‘Joint Cyber Defense Collaborative’ include Microsoft, AWS, and Google Security06 Aug 2021 | 14