New versions of Emotet have been dropping Cobalt Strike beacons directly, rather than relying on intermediate payloads such as Trickbot.
Starting in February 2020, attackers have leveraged weaknesses that occur “by design” in OAuth 2.0 implementations from Microsoft and GitHub.
Wade Baker and Ben Edwards of the Cyentia Institute join Dennis Fisher to discuss the process of designing and interpreting the data from the Cisco Security Outcomes study, what surprised them from the data, and how organizations can use the study.
The Moobot botnet has been infecting popular surveillance cameras and using them in distributed denial-of-service (DDoS) attacks.
Google has taken down servers associated with the huge Glupteba botnet and also sued two alleged operators of the network.
Microsoft has disrupted "a key piece of infrastructure" used by the China-based threat group known as Nickel or APT15.
New guidance from the White House requires CISA to develop policies for federal agencies to move toward automated security incident reporting.
Researchers have linked a malware loader, called CeeLoader, to the threat group behind the SolarWinds supply-chain attack.
This week's Source Code podcast by Decipher takes a look behind the scenes at top news with input from our sources.
Several new Security Directives, released by the TSA, aim to improve the security postures of rail and aviation entities.
CISA and the FBI are warning that APT groups are exploiting a critical flaw (CVE-2021-44077) in the ManageEngine ServiceDesk Plus tool.
A threat actor has been deploying web browser credential stealers, an undocumented backdoor and new Google Chrome malicious extension in an ongoing campaign.
Mozilla has fixed a critical buffer overflow in its NSS cryptographic library that had been lurking in the code for several years.
Three APTs have been observed using RTF template injection, and researchers warn more threat groups may adopt the new tactic.
The sentencing comes as the FCC grapples with how it can better safeguard consumers against SIM hijacking attempts.