README

NIST vulnerability bottleneck underscores fragility of software security
Read more

Changelog for 4/25/2024

Changelog: Hello to LockBitSupp and goodbye to Changelog
Read more

Changelog for 4/18/2024

Changelog: Sandworm becomes APT44
Read more

Changelog for 4/12/2024

A sudden halt to the ranking of vulnerability severity has left government agencies and some companies without an approved source of ranking and prioritization.

Changelog for 4/11/2024

Changelog: Kaspersky is the new TikTok
Read more

Changelog for 4/10/2024

CISA cyber reporting mandate faces tough road
Read more

A coalition of organizations has asked CISA to extend the public comment period on new cyberattack reporting rules proposed in response to CIRCIA.

Changelog for 4/04/2024

Changelog: Cyber review board is all bark, no bite on Microsoft
Read more

Changelog for 3/28/2024

Changelog: The U.S. and U.K. expose APT31
Read more

Exploits Explained

Exploits Explained: ZIP embedding attack on Google Chrome extensions
Read more

Malcolm Stagg recounts the discovery of CVE-2024-0333, a vulnerability in Google Chrome that could have been exploited to install malicious extensions.

Changelog for 3/21/2024

Changelog: TikTok is the new Kaspersky
Read more

Welcome to Changelog for 3/21/2024, published by Synack! README senior editor Nathaniel Mott here with a reluctant defense of TikTok following the passage of a bill looking to ban it.