The Ducktail information stealer has been updated with new capabilities and the threat actors that use it have been expanding their operation, according to WithSecure, formerly known as F-Secure Business.
Microsoft Releases Out-of-Band Update After Security Patch Causes Kerberos Issues
Microsoft has released an out-of-band update after learning that a recent Windows security patch started causing Kerberos authentication issues.
Cisco Secure Email Gateway Filters Bypassed Due to Malware Scanner Issue
An anonymous researcher has disclosed several methods that can be used to bypass some of the filters in Cisco’s Secure Email Gateway appliance and deliver malware using specially crafted emails.
US Offshore Oil and Gas Infrastructure at Significant Risk of Cyberattacks
The offshore oil and gas infrastructure faces cybersecurity risks that the Department of Interior should immediately address, the US Government Accountability Office (GAO) notes in a new report.
California County Says Personal Information Compromised in Data Breach
The County of Tehama, California, has started informing employees, recipients of services, and affiliates that their personal information might have been compromised in a data breach.
33 Attorneys General Send Letter to FTC on Commercial Surveillance Rules
Attorneys general in 33 US states are urging the Federal Trade Commission (FTC) to take into consideration consumer risks as it looks into creating rules to crack down on commercial surveillance.
Google Making Cobalt Strike Pentesting Tool Harder to Abuse
Google has announced the release of YARA rules and a VirusTotal Collection to help detect Cobalt Strike and disrupt its malicious use.
PoC Code Published for High-Severity macOS Sandbox Escape Vulnerability
A security researcher has published details and proof-of-concept (PoC) code for a macOS vulnerability that could be exploited to escape a sandbox and execute code within Terminal.
Security Researchers Looking at Mastodon as Its Popularity Soars
Cybersecurity researchers are increasingly looking at Mastodon now that the decentralized social media platform’s popularity has soared, and they have started finding vulnerabilities and other security issues.
Atlassian Patches Critical Vulnerabilities in Bitbucket, Crowd
Atlassian informed customers this week that it has patched critical vulnerabilities in its Crowd and Bitbucket products.












