In a new Cybersecurity Advisory (CSA), the Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and National Security Agency (NSA) are asking cybersecurity...
Corresponding Senate legislation doesn’t mention the federal chief information security officer but shares other key elements—including a shorter incident reporting window—with a discussion draft issued by...
A critical vulnerability in the Windows HTTP Protocol Stack presents a remote code execution (RCE) risk and could be “wormable”, Microsoft warns. The vulnerability (tracked as CVE-2022-21907)...
A session hijack vulnerability in the hugely popular e-learning platform Moodle enabled attackers to commandeer any user’s session and achieve remote code execution (RCE), security researchers have revealed....
Mozilla has patched a security issue in Firefox that could have allowed an attacker to spoof legitimate websites via a stealthily executed ‘full screen’ mode. The...
The OceanLotus group of state-sponsored hackers are now using the web archive file format (.MHT and .MHTML) to deploy backdoors to compromised systems. The goal is...
The warning comes as a military build-up occurs at the Russian-Ukrainian border. On Tuesday, three agencies issued a joint cybersecurity advisory warning relevant organizations of state-sponsored Russian cyber...
Electronic Arts (EA) has published an official response to numerous reports about hacked player accounts, confirming the problem and attributing it to phishing actors. As the...
Hackers believed to work for the North Korean government have compromised the email account of a staff member of Russia’s Ministry of Foreign Affairs (MID) and...
A senior senator continued a back-and-forth with auditors over the Defense Department’s now-canceled JEDI contract. Concerns regarding the Pentagon inspector general’s handling of a 2020 investigation...