As the commercial spyware market continues to grow, public and private sector organizations are considering all their options - from financial sanctions to a complete global moratorium.
Researchers and Ukraine’s governmental computer emergency response team are publishing details on new Turla malware used in espionage attacks against the defense sector in Ukraine and Eastern Europe.
The new U.S. Cyber Trust Mark program is meant as a seal of approval for IoT device security and could drive more secure development practices.
A financially motivated threat group is using a reworked version of its known backdoor to deploy the Noberus ransomware.
Adobe has released a patch for a critical bug in ColdFusion (CVE-2023-38203) and warns that a proof-of-concept analysis is available for it.
Onboarding and offboarding are operationally complex, time-consuming processes - and security frequently falls between the cracks.
Welcome back to Source Code, Decipher's weekly news wrap podcast with input from our sources.
The Zimbra Collaboration Suite version 8.8.15 has a cross-site scripting flaw that Google researchers say has been actively exploited.
The White House has dropped the long-awaited plan for executing its National Cybersecurity Strategy, which involves 65 initiatives and 18 government agencies.
Rockwell Automation discovered an exploit for its ControlLogix modules that was developed by an unnamed APT actor.
The threat group used forged authentication tokens - with an acquired Microsoft account consumer signing key - to access the email accounts of more than two dozen organizations.
Jackie Burns Koven, head of cyber threat intelligence at Chainalysis, talks about cryptocurrency-related cybercrime.
The Microsoft zero-day flaw (CVE-2023-36884) is being leveraged by a Russian-based cybercriminal group in phishing emails sent to defense and government entities in Europe and North America.
An undocumented malicious driver called RedDriver uses an open-source tool to forge signature timestamps, as a way to bypass Microsoft’s Windows driver signature enforcement policies.
A California man allegedly gained unauthorized access to a water treatment plant network, “causing a threat to public health and safety,” according to the DoJ.