“Cold River” hackers, ransomware updates and Operation Aurora’s legacy
Welcome to Changelog for 1/8/23, published by Synack! It’s me, Blake, hoping you all had a restful holiday season.
Disappearing SBOMs, a bevy of zero-days and the Father Christmas Worm
Welcome to Changelog for 12/18/22, published by Synack! Nate here, delivering your last edition of the year.
2022 was the year of crippling ransomware attacks on small countries
The country of Vanuatu is the latest victim in a string of crippling ransomware attacks on small countries this year. Experts say various motives underlie these incidents but disagree on whether this trend reflects a shift in threat actors away from well-resourced Western nations.
Log4j’s anniversary, Apple security moves and risky Exchange servers
Welcome to Changelog for 12/11/22, published by Synack! Blake here, excited to share that I’ll be co-hosting Season 2 of the WE’RE IN! cybersecurity podcast alongside Bella DeShantz-Cook.
Pipeline cyber rules, a Coinbase extortion attempt and World Cup scammers
Grudging kudos to the Netherlands for besting the U.S. in the World Cup on Saturday. Now I’m rooting for France to win it all.
SBOMs are billed as a balm for supply chain risks. What’s the holdup?
The fallout of the Log4Shell vulnerability accelerated efforts to require a software bill of materials (SBOM) for the apps, libraries and other digital tools we rely on, but when it comes to generating and using this information, obstacles abound.
Iran’s Log4j foray, Meta’s “Oops” and a looming ban on ransomware payments
Welcome to Changelog for 11/20/22, published by Synack! Blake here, delivering the week’s news alongside README senior editor Nathaniel Mott. A quick programming note before we dive in: Changelog won’t publish next Sunday as we take a Thanksgiving break.
Cybercrime is more of a threat than nation-state hackers
Back-to-back security conferences detailed the latest threats posed by malicious nation-states on the one hand and cybercriminals on the other. One takeaway is that cybercrime volumes are more massive and more persistent than the higher profile advanced persistent threats.
A crypto implosion, Twitter shakeups and Patch Tuesday takeaways
Welcome to Changelog for 11/13/22, published by Synack! It’s me, Blake, bringing you the latest news with a boost from README senior editor Nathaniel Mott.