In the latest Decipher Memory Safe episode, Casey Ellis, founder and CTO of Bugcrowd, talks about everything from imposter syndrome to the security concept of “building it like it’s broken.”
A new phishing campaign by a subset of the Iranian threat group Mint Sandstorm is targeting universities and research organizations with custom backdoors.
For patching, VMware said that "this situation qualifies as an emergency change."
The flaw (CVE-2023-7028) stems from the fact that user account password reset emails can be delivered to unverified email addresses.
An unidentified APT group is actively exploiting the two recently disclosed Ivanti Pulse Secure and Connect Secure vulnerabilities (CVE-2023-46805 and CVE-2024-21887).
A new Python-based hacking tool is leveraged by cybercriminals to target cloud and SaaS platforms, and payment services, like AWS, Office365, PayPal and Twilio.
Welcome back to Source Code, Decipher's weekly news wrap podcast with input from our sources.
Patches will be released starting Jan. 22, but until then Ivanti urges customers to apply mitigations.
Cisco Talos researchers also said that Dutch law enforcement has identified and apprehended the threat actor behind Babuk Tortilla operations.
Organizations based in the U.S., EU and Latin America have been targeted over the past few weeks.
Threat actors are targeting a critical flaw in the Apache OFBiz platform that was disclosed in late December.
James Doggett, CISO of Semperis and a longtime executive in the financial and insurance industries, joins Dennis Fisher to discuss his career arc and the challenges of being a CISO in today's highly scrutinized and pressure-filled environment.
2023 was one of the crazier years in recent memory for security news, and we did our best to make sense of it all. We gathered some of our friends to talk about what the biggest stories of the year were and what we learned from them.
In addition to creating the decryption tool, law enforcement agencies have also gained visibility into the ransomware group’s network and have seized several attacker-operated websites.
Our annual holiday book recommendation guide is here to help you discover what to read during your holiday downtime.