README
NIST vulnerability bottleneck underscores fragility of software security
Read more
Changelog for 4/25/2024
Changelog: Hello to LockBitSupp and goodbye to Changelog
Read more
Changelog for 4/18/2024
Changelog: Sandworm becomes APT44
Read more
Changelog for 4/12/2024
A sudden halt to the ranking of vulnerability severity has left government agencies and some companies without an approved source of ranking and prioritization.
Changelog for 4/11/2024
Changelog: Kaspersky is the new TikTok
Read more
Changelog for 4/10/2024
CISA cyber reporting mandate faces tough road
Read more
A coalition of organizations has asked CISA to extend the public comment period on new cyberattack reporting rules proposed in response to CIRCIA.
Changelog for 4/04/2024
Changelog: Cyber review board is all bark, no bite on Microsoft
Read more
Changelog for 3/28/2024
Changelog: The U.S. and U.K. expose APT31
Read more
Exploits Explained
Exploits Explained: ZIP embedding attack on Google Chrome extensions
Read more
Malcolm Stagg recounts the discovery of CVE-2024-0333, a vulnerability in Google Chrome that could have been exploited to install malicious extensions.
Changelog for 3/21/2024
Changelog: TikTok is the new Kaspersky
Read more
Welcome to Changelog for 3/21/2024, published by Synack! README senior editor Nathaniel Mott here with a reluctant defense of TikTok following the passage of a bill looking to ban it.