
Browse all articles
December 15, 2021
NIST records fifth straight year of record-breaking vulnerability counts
A graph recently released by the National Institute of Standards and Technology (NIST) shows that for the fifth year in a row, there have been a record-breaking number of reported vulnerabilities.
December 15, 2021
Malicious Notepad++ installers drop StrongPity malware
Notepad++, one of the most popular, and free, text and source code editors for Windows systems, is being used by attackers to distribute malware.
December 15, 2021
Emotet, in new tactic, deploys Cobalt Strike directly
The notorious Emotet malware, which recently returned from a hiatus after its botnet was dismantled by a joint task force early this year, has begun installing Cobalt Strike directly — a deviation from its typical tactic of installing a trojan like TrickBot or Qbot and then delivering Cobalt Strike through it.
December 13, 2021
Critical Apache Log4j vulnerability discovered — here's what you need to know
Late last week, a critical zero-day vulnerability in the popular Java logging library Log4j surfaced when attackers were observed exploiting Minecraft servers via the game’s chat box. It has since become clear that the vulnerability in question poses perhaps the largest security threat we’ve seen in years.Details are still unfolding, but here’s what we know now.
December 13, 2021
Log4j zero-day poses an internet-wide threat
A critical remote code execution (RCE) vulnerability (CVE-2021-44228) in the Log4j Java library is affecting most Java applications, including VMWare vCenter, Minecraft, Twitter, iCloud, and ElasticSearch.
December 09, 2021
FBI: Cuba operators receive $44 million in ransomware payments
A recent report from the FBI shows that Cuba ransomware has scored at least $43.9 million in total ransom payments after successful attacks on 49 different targets in five critical infrastructure sectors.
December 08, 2021
Coronavirus-related phishing lures rise amid Omicron fears
Fear of the recent Omicron COVID-19 variant is providing fuel for phishing threats — like one U.K.-based campaign that makes use of a fake NHS website.






