CISA
CISA's going to name and shame vendors on insecure software
"When we see a vulnerability or intrusion campaign that could have been reasonably avoided if the software manufacturer had aligned to secure by design principles, we’ll call it out"
CISA
"When we see a vulnerability or intrusion campaign that could have been reasonably avoided if the software manufacturer had aligned to secure by design principles, we’ll call it out"
News
CISA has sounded the alarm over a pair of actively targeted vulnerabilities in Ivanti and Veeam software
Interviews
"We have gotten very smart on how to do business with agencies and build in flexibility into our contracting vehicles. We took an approach early on to divide and conquer..."
Citrix
Attackers dropped a webshell, collected and exfiltrated Active Directory data, then ran into some healthy obstacles...
Azure
Following a major security breach involving US federal agencies, Microsoft refuses to provide details on the incident
Cybersecurity
... and probably shot to high heaven with malware.
Cybersecurity
Phishing is key threat vector and a Blue Team bête noire...
Cybersecurity
A pre-auth RCE in IBM Aspera Faspex is being exploited in the wild
Cybersecurity
One of 14 new advisories on vulnerable ICS software...
Featured
And, um, do you know how to restore from backup without Active Directory?
Cybersecurity
POCs have circulated for years...
Cybersecurity
Knock Knock. Who's there? Multiple APTs, patch your shit.