Top takeaways from ShmooCon: Less moose, more cyberthreats
ShmooCon 2023 has come and gone. Now it’s time to consider what the most laid-back infosec conference of the year — boasting the quirky tagline, “Less Moose Than Ever” — can tell us about the security industry heading into 2023.
ShmooCon highlights, T-Mobile’s API security woes and the government’s unfinished cyber business
Welcome to Changelog for 1/22/23, published by Synack! Hello from ShmooCon 2023! Nate Mott here, delivering you a special edition from the celebrated hacker conference in Washington, D.C., which ends today. We’ll get right to it:
“Cold River” hackers, ransomware updates and Operation Aurora’s legacy
Welcome to Changelog for 1/8/23, published by Synack! It’s me, Blake, hoping you all had a restful holiday season.
Disappearing SBOMs, a bevy of zero-days and the Father Christmas Worm
Welcome to Changelog for 12/18/22, published by Synack! Nate here, delivering your last edition of the year.
2022 was the year of crippling ransomware attacks on small countries
The country of Vanuatu is the latest victim in a string of crippling ransomware attacks on small countries this year. Experts say various motives underlie these incidents but disagree on whether this trend reflects a shift in threat actors away from well-resourced Western nations.
Log4j’s anniversary, Apple security moves and risky Exchange servers
Welcome to Changelog for 12/11/22, published by Synack! Blake here, excited to share that I’ll be co-hosting Season 2 of the WE’RE IN! cybersecurity podcast alongside Bella DeShantz-Cook.
Pipeline cyber rules, a Coinbase extortion attempt and World Cup scammers
Grudging kudos to the Netherlands for besting the U.S. in the World Cup on Saturday. Now I’m rooting for France to win it all.
SBOMs are billed as a balm for supply chain risks. What’s the holdup?
The fallout of the Log4Shell vulnerability accelerated efforts to require a software bill of materials (SBOM) for the apps, libraries and other digital tools we rely on, but when it comes to generating and using this information, obstacles abound.
Iran’s Log4j foray, Meta’s “Oops” and a looming ban on ransomware payments
Welcome to Changelog for 11/20/22, published by Synack! Blake here, delivering the week’s news alongside README senior editor Nathaniel Mott. A quick programming note before we dive in: Changelog won’t publish next Sunday as we take a Thanksgiving break.