README (12)

NIST Vulnerability Bottleneck Underscores Fragility of Software Security

Read more


New Strategies, “Soul-Searching” Needed to Secure Critical Infrastructure

At this year’s S4 conference in Miami Beach, top industrial control system experts offered various solutions that could replace the increasingly obsolete security through obscurity method for protecting ICS. Read more


Stalkerware Worries, a WebKit Zero-Day and Chris Inglis’s Departure

Welcome to Changelog for 2/19/23, published by Synack! Nate Mott here, writing from the cold-once-again boonies of upstate New York with this week’s cyber news: Read more


AI-Powered Phishing: Chatbot Hazard or Hot Air?

ChatGPT’s launch last November has captivated the security industry, as the artificially intelligent chatbot’s detailed responses seem ripe for abuse by scammers and cybercriminals. What’s the real threat? Read more


Trickbot Sanctions, Hypervisor Woes and Ransomware by Any Other Name

Welcome to Changelog for 2/12/23, published by Synack! The weather’s been nice here in upstate New York, but that hasn’t warmed my heart quite as much as international efforts to make life a little bit harder for some cybercriminals. Read more


Cybercrime is More of a Threat than Nation-State Hackers

Back-to-back security conferences detailed the latest threats posed by malicious nation-states on the one hand and cybercriminals on the other. One takeaway is that cybercrime volumes are more massive and more persistent than the higher-profile advanced persistent threats. Read more


Feds Eye Virtual Reality as the Next Privacy and Security Battleground

At the Federal Trade Commission’s annual PrivacyCon this week, a top regulator and outside experts zeroed in on digital risks posed by the nascent virtual reality industry. Read more


From Programmer to Pwner: My Zero-Day Journey to Pwn2Own

Security researcher Vera Mens and her colleagues on Claroty’s Team82 took on some of the toughest challenges in the industrial cybersecurity field at Pwn2Own Miami. Read more


Steep Costs, Troubling Questions Roil DOD Cybersecurity Program Rollout

About 80,000 companies that sell to the U.S. military will need to pass a cybersecurity audit before they can bid for business under rules the Defense Department plans to impose next year. But many small defense contractors aren’t prepared for the brave new world of the Cybersecurity Maturity Model Certification (CMMC) program. Read more


Web3's Security Dilemma, AcidRain Malware and a Cyber Defamation Case

Welcome to Changelog for 4/3/22, published by Synack! I’m your host, Blake, and I can’t believe this is already edition №10. Read more