readme/
218 pages · Updated July 26, 2026
Pages
- README | Policy
- The problems with vulnerability reporting
- Commit 12_19_2023: FBI bamboozles BlackCat
- Why we’re investing in cybersecurity journalism by launching README
- A new voice in the cybersecurity conversation
- README | Jay Kaplan
- Award-winning cybersecurity journalist Blake Sobczak joins README as managing editor
- README (15)
- README | Michael B. Farrell
- README (14)
- index-2.html
- README (13)
- README | Commit (2)
- README (12)
- README | Commit
- README | Commit
- README | Commit (3)
- README (11)
- README (10)
- README | Commit
- deep-rooted-firmware-cyberthreats-put-defenders-in-a-bind.html
- README (8)
- ai-code-assistants-need-security-training
- README (9)
- hacking-in-tongues-malware-authors-shake-up-their-programming-languages.html
- CISA can’t succeed in the Pentagon’s shadow
- Inside the Conti leaks rattling the cybercrime underground
- back-to-back-industrial-cyberthreats-alarm-global-energy-sector.html
- README (7)
- README | Changelog (6)
- README (6)
- One hacker vs. the Hermit Kingdom
- A national cyber strategy, EPA cyber regulations and one giant leap for space hacking
- index-2.html
- Criminals robbing criminals: exit scams fuel dark web paranoia
- DARPA’s quest for the (almost) unhackable
- Web3's security dilemma, AcidRain malware and a cyber defamation case
- Clicking QR codes, Ukraine DDoS attacks and tracking Snake
- Documents reveal depth of anxiety over possible Russian cyberattacks on U.S. grid
- Bracing for cyberattacks as Russia readies for war
- README | Changelog (7)
- index-2.html
- Ransomware is the existential threat that could reverse crypto’s rise
- Space hacking risks pose cyber policy test for Biden admin
- Researchers show how platforms can scrub COVID conspiracies, election lies and other misinformation
- Thousands of Pentagon contractors could buckle under cybersecurity push
- China’s U.S. agency hacking spree, zero-days galore and USB malware
- Snake’s takedown, irksome commercial surveillance and a federal data breach
- Postcards from Hacker Summer Camp 2023
- Sandworm’s kingpin, a CISA ransomware pilot and pandemic scams
- index-2.html
- A D.C. healthcare breach, ransomware updates and China’s “most active” cyberthreat
- A new iOS zero-click exploit, MOVEit sees mass exploitation and ransomware keeps on coming
- Tesla exploits, a hacker obituary and a look past Capitol Hill’s TikTok fixation
- 10 things we learned — and relearned — at DEF CON 29 (some that have nothing to do with security)
- Russia’s ‘Vulkan Files,’ a 3CX supply chain attack and White House action on spyware
- Hackers square off to close gaps in satellite cybersecurity
- U.S. cyber board’s Lapsus$ postmortem, CPU vulns and remembering Vim’s creator
- index-2.html
- Changelog: The calm before many AI storms
- Apple patches zero-days, MOVEit Transfer vuln leaks and the FBI gets cute
- Back-to-back Ivanti vulns, Microsoft woes and robocaller schadenfreude
- Space cyber wargame exposes satellite industry risks
- Israeli spyware revealed, a doozy of a Patch Tuesday and ransomware fallout
- Trickbot sanctions, hypervisor woes and ransomware by any other name
- Ransomware that cares, TLD concerns and the “Sangria Tempest” cyberthreat
- Stalkerware worries, a WebKit zero-day and Chris Inglis’s departure
- TrueBot rises, a major port gets ransomwared and EVs’ cyber problem
- Disruptive Chinese malware, Storm-0558 fallout and SEC cyber rules
- README (5)
- Cybercrime is more of a threat than nation-state hackers
- PaperCut vulnerabilities, DDoS amplification and jerks leaking info about schoolkids
- DEF CON spirit muted but unbowed by Covid
- RSAC 2023, supply chain problems and a broken ransomware record
- Big Tech is mandating MFA. Hackers have workarounds
- This vulnerability puts the future of U.S. warfighting at risk
- Ransomware struggles, a SolarWinds retrospective and a safety win for location trackers
- Changelog: Signal makes a quantum leap
- README | Changelog (4)
- Hacking space on the horizon for 2023
- Changelog: MGM outages mark new chapter of ransomware chaos
- README (4)
- README | Changelog (5)
- Changelog: AI will improve security—right after it stops making it worse
- README | Kim Crawley
- README | Payal Dhar
- Changelog: End times for Ragnar Locker and Trigona?
- Crying wolf over QR codes? Coinbase’s Super Bowl ad sparks infosec debate
- Google cuts the cord, Microsoft takes a security pay cut and the U.S. slaps spyware firms
- How digital ‘drifters,’ eager to turn an easy profit online, fuel the malware marketplace
- Changelog: The “C” in SEC stands for “cyber”
- README | Trends (4)
- From programmer to pwner: My zero-day journey to Pwn2Own
- Changelog: Another busy week for Beijing cyberthreats
- AI-powered phishing: Chatbot hazard or hot air?
- Changelog: Microsoft breaks down the Storm-0558 hack
- Home is where the hackers are: The dizzying task of securing remote work
- Changelog: Deja vu on the edge
- Changelog: Russian hackers pick up new tricks
- Commit 09_19_2023: ShroudedSnooper, ShadowDragon
- Changelog: Security teams caught between a rock and a hard place
- Changelog: There is no silver lining
- Commit 11_14_2023: Different TTPs for different times
- Honeypots for Dota cheats, Dole ransomware and Russia’s waning influence ops
- How I hacked my way to the top of DARPA’s hardware bug bounty
- Changelog: Volt Typhoon threat is the real deal
- README | Josephine Wolff
- Changelog: How to lose $2 billion
- As APIs proliferate, attackers follow
- Changelog: Spying via push notifications
- Changelog: Russia doubles down on Ukrainian telecom attacks
- Flawed choices: Developers continue to use vulnerable open-source dependencies
- Commit 09_18_2023: Hello, world!
- Top cyber takeaways from the Intelligence and National Security Summit
- Ukraine resistance, dark web scams and a new CISO for Colonial Pipeline
- Changelog: All eyes on China (and toothbrushes)
- README | Vulnerabilities (2)
- Commit 10_03_2023: Ransomware as far as the eye can see
- Changelog: Sandworm becomes APT44
- Commit 09_25_2023: Schrödinger's Scattered Spider
- Changelog: Law enforcement disrupts (and trolls) LockBit
- Commit 10_02_2023: Are we cyber-aware yet?
- Changelog: Change Healthcare finally bounces back weeks after cyberattack
- Changelog: Another cyber-enabled power outage
- Commit 10_10_2023: Predator targets journalists, politicians
- Changelog: The never-ending coordinated disclosure debate
- Changelog: Midnight Blizzard rolls over Microsoft and HPE
- Changelog: U.S. cyber leaders warn of China threat
- Changelog: Bad code is a national security concern
- Changelog: A look back at 2023 and ahead to 2024
- Commit 10_17_2023: The scourge of untrustworthy browser updates
- Changelog: A bleak start to the new year
- Commit 10_23_2023: Living in strange times
- Commit 11_6_2023: Were you expecting good news this month?
- Commit 10_31_2023: SolarWinds in the SEC’s hot seat
- Changelog: Cyber review board is all bark, no bite on Microsoft
- Commit 10_16_2023: Sandworm goes after Ukrainian telcos
- Changelog: Ivanti discloses the biggest zero-days of the year so far
- Commit 11_13_2023: Trouble in the land down under
- README | Vulnerabilities
- Memory safety is the first step, not the last, towards secure software
- Commit 10_24_2023: Stuff we Okta know
- Changelog: Hello to LockBitSupp and goodbye to Changelog
- Changelog: The U.S. and U.K. expose APT31
- README | Vulnerabilities
- Commit 12_05_2023: DNA, water and… spam?
- Changelog: TikTok is the new Kaspersky
- Commit 11_8_2023: Surprise! Ransomware gangs are exploiting that Confluence vuln
- “Meant to be devastating.” Wiper malware rattles Ukraine as Russia presses invasion
- Commit 12_04_2023: U.K. nuclear site hacked (or not)
- Commit 11_27_2023: Bringing 'secure by design' to AI
- Changelog: Kaspersky is the new TikTok
- Wartime muddies waters for 'hacktivist' threat
- Commit 12_18_2023: Predatory Sparrow dives again
- Commit 11_28_2023: The ransomware hydra
- Fungi fallout? Ore. psilocybin data bill draws cybersecurity scrutiny
- Commit 12_11_2023: A lot of hackin’ going on
- README (2)
- Commit 12_12_2023: Patch Tuesday mends a few scratches
- The internet is hooked on packages. Hackers have noticed
- Changelog: ArcaneDoor campaign targets Cisco devices
- README
- README | Vera Mens
- README | Trends
- Spyware vendors stagger as the U.S. and allies land a punch
- Russia-Ukraine cyber conflict splits APT groups, raises threat level
- README | Trends
- Dark Caracal: A bumbling, yet surprisingly effective, cyber mercenary group
- README
- README | Changelog (2)
- README | Trends (3)
- Changelog: How secure is America’s critical infrastructure?
- README | Trends (2)
- README | Malcolm Stagg
- README | Changelog (3)
- index-2.html
- Attackers are on the edge. Where are defenders?
- README | Changelog
- README (3)
- Death by digital: attacks on healthcare put people at risk
- Commit 09_26_2023: U.S. surveillance relies on private allies
- README | Changelog
- The SEC goes after SolarWinds, LockBit extorts TSMC and a high school password fail
- New strategies, “soul-searching” needed to secure critical infrastructure
- README | Blake Thompson Heuer
- NIST vulnerability bottleneck underscores fragility of software security
- CISA cyber reporting mandate faces tough road
- README | Robert Lemos
- MOVEit users extorted, Barracuda bitten and GoAnywhere woes not going anywhere
- Commit 10_30_2023: Malware and mysteries
- README | Cynthia Brumfield
- How I became a hacker before I finished high school
- Attackers see developers as low-hanging fruit
- Destructive malware is back in Ukraine. Will it usher in cyberconflict?
- Rapid7 vs JetBrains: A vulnerability disclosure process gone bad
- README | Policy (2)
- How defenders are experimenting with artificial intelligence
- exploits-explained-zip-embedding-attack-on-google-chrome-extensions.html
- AlphV’s bid to report its victim to the SEC could backfire
- README | Ally Petitt
- README | Shaun Waterman
- Uncertainty hits the cybersecurity jobs market
- README | Policy
- Bad torts: Law firms feel the heat from rising cyber threats
- README | Nathaniel Mott
- README | Vulnerabilities
- README
- README | Changelog
- README | Trends
- About README
- Feds eye virtual reality as the next privacy and security battleground
- CVSS 4.0 is shaking up vulnerability management. Here’s what’s changed
- Zero-days aren't just for nation-states anymore
- README | Incidents
- README | Policy
- AI’s peril and promise for policymakers and cyber defenders
- MOVEit Transfer saga shows danger of the 'Dark Middle'
- How AI could inflame one of the costliest cyber scams