30 Apr

FBI steps in amid rash of politically charged swattings

A spate of high-profile swatting incidents in the US recently forced the FBI into action with its latest awareness campaign about the occasionally deadly practice.

Author rabih
30 Apr

Ghost in the shell script: Boffins reckon they can catch bugs before programs run

Shell scripting may finally get a proper bug-checker. A group of academics has proposed static analysis techniques aimed at improving the correctness and reliability of

Author rabih
30 Apr

TheWizards APT group uses SLAAC spoofing to perform adversary-in-the-middle attacks

In this blogpost, ESET researchers provide an analysis of Spellbinder, a lateral movement tool for performing adversary-in-the-middle attacks, used by the China-aligned threat actor that

Author rabih
30 Apr

Cloud doesn’t mean secure: How Intruder finds what others miss

Sponsored post You’d be naïve to believe that the cloud is secure by default, and while most hosting services provide basic defenses, it’s not always

Author rabih
29 Apr

Watch out for any Linux malware sneakily evading syscall-watching antivirus

A proof-of-concept program has been released to demonstrate a so-called monitoring “blind spot” in how some Linux antivirus and other endpoint protection tools use the

Author rabih
29 Apr

Enterprise tech dominates zero-day exploits with no signs of slowdown

Pullquote text Google says that despite a small dip in the number of exploited zero-day vulnerabilities in 2024, the number of attacks using these novel

Author rabih
29 Apr

China now America’s number one cyber threat – US must get up to speed

RSAC Russia used to be considered America’s biggest adversary online, but over the past couple of years China has taken the role, and is proving

Author rabih
29 Apr

Infosec pros tell Trump to quit bullying Chris Krebs – it’s undermining security

The Electronic Frontier Foundation (EFF) and numerous infosec leaders are lobbying US President Donald Trump to drop his enduring investigation into Chris Krebs, claiming that

Author rabih
29 Apr

This month in security with Tony Anscombe – April 2025 edition

From the near-demise of MITRE’s CVE program to a report showing that AI outperforms elite red teamers in spearphishing, April 2025 was another whirlwind month

Author rabih
29 Apr

China is using AI to sharpen every link in its attack chain, FBI warns

RSAC The biggest threat to US critical infrastructure, according to FBI Deputy Assistant Director Cynthia Kaiser, can be summed up in one word: “China.” In

Author rabih
29 Apr

The one interview question that will protect you from North Korean fake workers

RSAC Concerned a new recruit might be a North Korean stooge out to steal intellectual property and then hit an org with malware? There is

Author rabih
29 Apr

Swiss boffins admit to secretly posting AI-penned posts to Reddit in the name of science

Researchers from the University of Zurich have admitted to secretly posting AI-generated material to popular Subreddit r/changemyview in the name of science. As the researchers

Author rabih
29 Apr

Open source text editor poisoned with malware to target Uyghur users

Researchers at Canada’s Citizen Lab have spotted a phishing campaign and supply chain attack directed at Uyghur people living outside China, and suggest it’s an

Author rabih
29 Apr

Ex-Disney employee gets 3 years in the clink for goofy attacks on mousey menus

Former Disney employee Michael Scheuer was sentenced to 36 months in prison and fined almost $688,000 for screwing up a software application the entertainment giant

Author rabih
28 Apr

Cybersecurity CEO accused of running malware on hospital PC blabs about it on LinkedIn

An Oklahoma City cybersecurity professional accused of installing spyware on a hospital PC confirmed on LinkedIn key details of the drama. Jeffrey Bowie, whom court

Author rabih
28 Apr

How to survive as a CISO aka ‘chief scapegoat officer’

RSAC Chief security officers should negotiate personal liability insurance and a golden parachute when they start a new job – in case things go sideways

Author rabih
28 Apr

Admission impossible: NSA, CISA brass absent from RSA Conf

RSAC There’s a notable absence from this year’s RSA Conference that kicked off today in San Francisco: The NSA’s State of the Hack panel. The

Author rabih
28 Apr

The future of AI in cybersecurity in a word: Optimistic

Sponsored post AI is reshaping cybersecurity in real time, raising the stakes on both sides of the battlefield. For defenders, it brings speed, precision, and

Author rabih
Load moreLoadingAll items loaded