CSO

The day's top cybersecurity news and in-depth coverage

CSO First Look

April 20, 2022

Spring4Shell: Assessing the risk

Spring4Shell does not affect most systems, so a calm, methodical approach to assessing the real threat is best. Read more ▶

Image: Sponsored by Juniper: Juniper Global Summit May 11: Demand more from your network.

Sponsored by Juniper: Juniper Global Summit May 11: Demand more from your network.

Join us in this 2-hour summit to hear from an all-star lineup of industry experts discussing their views on the future of networking and how AI, ML, and cloud-delivered automation and security is delivering better customer experiences.

Drones as an attack vector: Vendors need to step up

Growing commercial use and few built-in defenses make drones an attractive target for malicious actors.

Attack dwell times drop, ransomware TTPs evolve, China ramps up espionage activity

M-Trends 2022 report delivers detailed assessment of the evolving global cyber threat landscape highlighting prevalent attack vectors and most targeted industries.

Image: Why you should patch the latest critical Windows RPC vulnerability right now

Why you should patch the latest critical Windows RPC vulnerability right now

CVE-2022-26809 can allow attackers to compromise networks without user intervention, making it the most dangerous vulnerability fixed by Microsoft's April 12 Patch Tuesday update.

Spyware was used against Catalan targets and UK prime minister and Foreign Office

Researchers at the Citizen Lab says dozens of officials' phones were compromised by spyware sold by NSO Group or Candiru.

GitHub repositories compromised by stolen OAuth tokens

GitHub, Salesforce warn of data theft from private code repositories.

Karakurt data thieves linked to larger Conti hacking group

Data theft group has apparent ties to another, more prolific hacking crew, according to cybersecurity firm Tetra Defense.

CSO
Facebook Twitter LinkedIn
© 2022 CSO
140 Kendrick Street, Building B
Needham, MA 02494