Microsoft has seen a surge in malware campaigns using HTML smuggling to distribute banking malware and remote access trojans (RAT). While HTML smuggling is not a...
The maintainers of GoCD, a widely used, open source tool that automates the continuous delivery (CD) of software, have addressed three vulnerabilities that, if chained, could lead to...
Security researchers have discovered a high-impact vulnerability on some versions of the widely used Palo Alto GlobalProtect Firewall/VPN that leaves enterprise networks open to attack. The vulnerability (CVE 2021-3064; with...
The Pentagon will formally launch a new office dedicated to expediting the adoption of a new zero trust cybersecurity model. The Department of Defense’s (DoD) chief...
The Department of Homeland Security (DHS) has requested public input on the topic of artificial intelligence (AI), including facial recognition. In a notice recently published in...
Developers must use safer tools, a recent report concluded. After the SolarWinds and Kaseya attacks spread malware far and wide across government and business networks, Palo...
The effort aims to create a user-friendly label to educate consumers about their purchases. The National Institute of Standards and Technology is looking for input on...
An open source toolkit designed to detect and thwart dependency confusion attacks was unveiled at Black Hat Europe 2021 yesterday. Developed by DevSecOps vendor Apiiro, Dependency Combobulator can be embedded...
A security researcher has released details of a high-impact, but long-since patched vulnerability in Google’s GSuite that allowed an attacker to add themselves as a super...
Security researchers have detailed how backdoors can be concealed within JavaScript by Unicode characters that are either invisible or readily confused with other characters. As a result, they...