README (12)
NIST Vulnerability Bottleneck Underscores Fragility of Software Security
New Strategies, “Soul-Searching” Needed to Secure Critical Infrastructure
At this year’s S4 conference in Miami Beach, top industrial control system experts offered various solutions that could replace the increasingly obsolete security through obscurity method for protecting ICS. Read more
Stalkerware Worries, a WebKit Zero-Day and Chris Inglis’s Departure
Welcome to Changelog for 2/19/23, published by Synack! Nate Mott here, writing from the cold-once-again boonies of upstate New York with this week’s cyber news: Read more
AI-Powered Phishing: Chatbot Hazard or Hot Air?
ChatGPT’s launch last November has captivated the security industry, as the artificially intelligent chatbot’s detailed responses seem ripe for abuse by scammers and cybercriminals. What’s the real threat? Read more
Trickbot Sanctions, Hypervisor Woes and Ransomware by Any Other Name
Welcome to Changelog for 2/12/23, published by Synack! The weather’s been nice here in upstate New York, but that hasn’t warmed my heart quite as much as international efforts to make life a little bit harder for some cybercriminals. Read more
Cybercrime is More of a Threat than Nation-State Hackers
Back-to-back security conferences detailed the latest threats posed by malicious nation-states on the one hand and cybercriminals on the other. One takeaway is that cybercrime volumes are more massive and more persistent than the higher-profile advanced persistent threats. Read more
Feds Eye Virtual Reality as the Next Privacy and Security Battleground
At the Federal Trade Commission’s annual PrivacyCon this week, a top regulator and outside experts zeroed in on digital risks posed by the nascent virtual reality industry. Read more
From Programmer to Pwner: My Zero-Day Journey to Pwn2Own
Security researcher Vera Mens and her colleagues on Claroty’s Team82 took on some of the toughest challenges in the industrial cybersecurity field at Pwn2Own Miami. Read more
Steep Costs, Troubling Questions Roil DOD Cybersecurity Program Rollout
About 80,000 companies that sell to the U.S. military will need to pass a cybersecurity audit before they can bid for business under rules the Defense Department plans to impose next year. But many small defense contractors aren’t prepared for the brave new world of the Cybersecurity Maturity Model Certification (CMMC) program. Read more
Web3's Security Dilemma, AcidRain Malware and a Cyber Defamation Case
Welcome to Changelog for 4/3/22, published by Synack! I’m your host, Blake, and I can’t believe this is already edition №10. Read more