**NIST vulnerability bottleneck underscores fragility of software security**  
[NIST vulnerability bottleneck underscores fragility of software security](https://readme.synack.com/nist-vulnerability-bottleneck-underscores-fragility-of-software-security)

### Changelog: Hello to LockBitSupp and goodbye to Changelog

**Nathaniel Mott**  
April 25, 2024  
[Changelog: ArcaneDoor campaign targets Cisco devices](https://readme.synack.com/changelog-arcanedoor-campaign-targets-cisco-devices)

Welcome to Changelog for 4/25/2024, published by Synack! README senior editor Nathaniel Mott here with all the doom and gloom you need this fine Spring day.

### Changelog: Sandworm becomes APT44

**Nathaniel Mott**  
April 18, 2024  
[Changelog: Sandworm becomes APT44](https://readme.synack.com/changelog-sandworm-becomes-apt44)

Welcome to Changelog for 4/18/2024, published by Synack! README senior editor Nathaniel Mott here with the week’s leading security news.

### NIST vulnerability bottleneck underscores fragility of software security

**Robert Lemos**  
April 12, 2024  
[NIST vulnerability bottleneck underscores fragility of software security](https://readme.synack.com/nist-vulnerability-bottleneck-underscores-fragility-of-software-security)

A sudden halt to the ranking of vulnerability severity has left government agencies and some companies without an approved source of ranking and prioritization.

### Changelog: Kaspersky is the new TikTok

**Nathaniel Mott**  
April 11, 2024  
[Changelog: Kaspersky is the new TikTok](https://readme.synack.com/changelog-kaspersky-is-the-new-tiktok)

Welcome to Changelog for 4/11/2024, published by Synack! README senior editor Nathaniel Mott “enjoying” those April showers and bringing you the top security news of the week.

### CISA cyber reporting mandate faces tough road

**Shaun Waterman**  
April 10, 2024  
[CISA cyber reporting mandate faces tough road](https://readme.synack.com/cisa-cyber-reporting-mandate-faces-tough-road)

A coalition of organizations has asked CISA to extend the public comment period on new cyberattack reporting rules proposed in response to CIRCIA.

### Changelog: Cyber review board is all bark, no bite on Microsoft

**Nathaniel Mott**  
April 04, 2024  
[Changelog: Cyber review board is all bark, no bite on Microsoft](https://readme.synack.com/changelog-cyber-review-board-is-all-bark-no-bite-on-microsoft)

Welcome to Changelog for 4/4/2024, published by Synack! README senior editor Nathaniel Mott here after a long weekend with the week’s leading security news.

### Changelog: The U.S. and U.K. expose APT31

**Nathaniel Mott**  
March 28, 2024  
[Changelog: The U.S. and U.K. expose APT31](https://readme.synack.com/changelog-the-us-and-uk-expose-apt31)

Welcome to Changelog for 3/28/2024, published by Synack! README senior editor Nathaniel Mott here with the week’s leading security news.

### Exploits Explained: ZIP embedding attack on Google Chrome extensions

**Malcolm Stagg**  
March 28, 2024  
[Exploits Explained: ZIP embedding attack on Google Chrome extensions](https://readme.synack.com/exploits-explained-zip-embedding-attack-on-google-chrome-extensions)

Malcolm Stagg recounts the discovery of CVE-2024-0333, a vulnerability in Google Chrome that could have been exploited to install malicious extensions.

### Changelog: TikTok is the new Kaspersky

**Nathaniel Mott**  
March 21, 2024  
[Changelog: TikTok is the new Kaspersky](https://readme.synack.com/changelog-tiktok-is-the-new-kaspersky)

Welcome to Changelog for 3/21/2024, published by Synack! README senior editor Nathaniel Mott here with a reluctant defense of TikTok following the passage of a bill looking to ban it.
