**NIST vulnerability bottleneck underscores fragility of software security**  
[Read More](https://readme.synack.com/nist-vulnerability-bottleneck-underscores-fragility-of-software-security)

Welcome to Changelog for 1/18/2024, published by Synack! README senior editor Nathaniel Mott here with the week’s top security news.

### Changelog: Russian hackers pick up new tricks  
[Read More](https://readme.synack.com/changelog-russian-hackers-pick-up-new-tricks)

**Nathaniel Mott**  
*January 18, 2024*

### Changelog: Ivanti discloses the biggest zero-days of the year so far  
[Read More](https://readme.synack.com/changelog-ivanti-discloses-the-biggest-zero-days-of-the-year-so-far)

**Nathaniel Mott**  
*January 11, 2024*

### Changelog: A bleak start to the new year  
[Read More](https://readme.synack.com/changelog-a-bleak-start-to-the-new-year)

**Nathaniel Mott**  
*January 04, 2024*

### Changelog: A look back at 2023 and ahead to 2024  
[Read More](https://readme.synack.com/changelog-a-look-back-at-2023-and-ahead-to-2024)

**Robert Lemos**  
*December 21, 2023*

### Zero-days aren't just for nation-states anymore  
[Read More](https://readme.synack.com/zero-days-arent-just-for-nation-states-anymore)  
In 2023, attackers continue to wield more zero-day exploits against companies and individuals, using them for ransomware, surveillance and espionage.

### Commit 12_19_2023: FBI bamboozles BlackCat  
[Read More](https://readme.synack.com/commit-12-19-2023-fbi-bamboozles-blackcat)  
Welcome to Commit 12_19_2023! README senior editor Nathaniel Mott here with the final installment of the year.

### Commit 12_18_2023: Predatory Sparrow dives again  
[Read More](https://readme.synack.com/commit-12-18-2023-predatory-sparrow-dives-again)  
Welcome to the penultimate Commit of 2023! README senior editor Nathaniel Mott here with the security news of the moment.

### Changelog: Russia doubles down on Ukrainian telecom attacks  
[Read More](https://readme.synack.com/changelog-russia-doubles-down-on-ukrainian-telecom-attacks)  
Welcome to Changelog for 12/14/2023, published by Synack! README senior editor Nathaniel Mott here to bring you the latest cybersecurity news in the penultimate installment of the year.

### CVSS 4.0 is shaking up vulnerability management. Here’s what’s changed  
[Read More](https://readme.synack.com/cvss-4-is-shaking-up-vulnerability-management.-heres-whats-changed)  
CVSS 4.0 urges companies to go beyond base scores, allowing them to more accurately judge the threat posed by particular vulnerabilities.
