FBI, NSA, CISA & NCSC Issue Joint Advisory on Russian SVR Activity
The report provides additional details on tactics of Russia's Foreign Intelligence Service following public attribution of the group to last year's SolarWinds attack.Government agencies from the United States and...
How North Korean APT Kimsuky Is Evolving Its Tactics
Researchers find differences in Kimsuky's operations that lead them to divide the APT into two groups: CloudDragon and KimDragon.Sara Peters contributed to this reporting.
North Korean APT group Kimsuky is...
Cloud-Native Businesses Struggle With Security
More companies moved to cloud-native infrastructure in the past year, and security incidents and malware moved right along with them.Companies increasingly moved their applications and infrastructure to the cloud...
CISA Publishes Analysis on New ‘FiveHands’ Ransomware
Enterprise VulnerabilitiesFrom DHS/US-CERT's National Vulnerability Database
CVE-2021-27941PUBLISHED: 2021-05-06
Unconstrained Web access to the device's private encryption key in the QR code pairing mode in the eWeLink mobile application (through 4.9.2 on...
New Techniques Emerge for Abusing Windows Services to Gain System Control
Organizations should apply principles of least privilege to mitigate threats, security researcher says.Several new techniques have become available recently that give attackers a way to abuse legitimate Windows services...
Troy Hunt: Organizations Make Security Choices Tough for Users
The Have I Been Pwned founder took the virtual stage at Black Hat Asia to share stories about his work and industrywide challenges.Data breach notification website Have I Been...











