The critical flaw (CVE-2022-1680) can allow for account takeover in impacted installations that have not been upgraded.
A newly disclosed zero day in some versions of Atlassian Confluence and Data Center is under attack and being used to install webshells on target servers.
A threat cluster with significant overlap to the Evil Corp cybercriminal gang has started deploying the LockBit ransomware in an effort to evade U.S. sanctions.
The Karakurt data extortion group is stealing sensitive information from enterprises and holding it for ransom, CISA warns.
The average ransomware attack duration - from the initial access to the deployment of the ransomware payload at scale - was under four days in 2021.
Weeks after the disclosure of the vulnerability (CVE-2022-29464) in WSO2 products, attackers are leveraging the flaw to install Linux-compatible Cobalt Strike beacons, cryptocurrency miners and more.
The new Linux-based ransomware is only the latest to target VMware ESXi servers.
A zero day flaw (CVE-2022-30190) in Windows and Office is under active attack and MIcrosoft has not issued a patch yet.
Interpol and private-sector companies announced the arrest of the alleged leader of a well-known phishing and BEC group.
Despite the U.S. government adopting many recommendations by the Ransomware Task Force in combating ransomware, authorities still grapple with several challenges that enable the ransomware ecosystem to thrive.
Cisco has patched a flaw in IOS XR that can allow an attacker to write arbitrary files to the Redis instance.
Welcome back to Source Code, Decipher’s weekly news wrap podcast.
The Department of Justice's new policy changes further narrow the scope of the Computer Fraud and Abuse Act, which has long been criticized for being too vague.
QNAP is urging customers to remove NAS devices from the Internet amid a new wave of Deadbolt ransomware intrusions.
CISA is mandating federal agencies to apply updates that fix several serious VMware bugs.