Attackers can chain the vulnerabilities to gain full remote code execution.
Follow Dark Reading:
 December 20, 2023
LATEST SECURITY NEWS & COMMENTARY
Microsoft Outlook Zero-Click Security Flaws Triggered by Sound File
Attackers can chain the vulnerabilities to gain full remote code execution.
Feds Snarl ALPHV/BlackCat Ransomware Operation
Dark Web chatter indicates that Scattered Spider worked with the FBI to take down the BlackCat/ALPHV operation.
Microsoft: Multiple Perforce Server Flaws Allow for Network Takeover
The most critical of the bugs gives attackers privileged access to the local Windows system, paving the way for unauthenticated RCE and installing backdoors.
Fresh Qakbot Sightings Confirm Recent Takedown Was a Temporary Setback
Microsoft and several others have reported seeing the noxious malware surfacing again in a campaign targeting the hospitality industry.
Comcast Xfinity Breached via CitrixBleed; 35M Customers Affected
A trove of personal data belonging to millions of Americans is just the latest bullet point in a bad year for Citrix customers.
Unsung GitHub Features Anchor Novel Hacker C2 Infrastructure
More and more hackers are choosing to host their malicious campaigns from public services, and they're pioneering new ways of doing it.
Why I Chose Google Bard to Help Write Security Policies
Large language models (LLMs) like Bard and ChatGPT can help produce simpler, more readable security documentation in a fraction of the time it takes to do it manually.
Changing How We Think About Technology
To make real change, organizations need to augment logical thinking with critical thinking.
MORE NEWS / MORE COMMENTARY
HOT TOPICS
Pro-Israeli Hacktivists Attack Iranian Gas Stations
Iranian officials blame a software issue for the "disruption" to gasoline pumps.

Adapting to the Post-SolarWinds Era: Supply Chain Security in 2024
Three years after the SolarWinds attack, new revelations show more must be done to help prevent such a drastic security breach from happening again.

Name That Toon: Just for Kicks
Feeling creative? Submit your caption and our panel of experts will reward the winner with a $25 Amazon gift card.

MORE
PRODUCTS & RELEASES
EDITORS' CHOICE
Millions of Microsoft Accounts Power Lattice of Automated Cyberattacks
Crimeware-as-a-service (CaaS) gang flies past CAPTCHAs, creating fraudulent accounts to sell to the likes of Scattered Spider; Microsoft mounts a counterattack.
LATEST FROM THE EDGE

How States Help Municipalities Build Their Cyber Defenses
State CISOs and cybersecurity task forces are grappling with the best ways to use federal grant money to keep their citizens safe online.
LATEST FROM DR TECHNOLOGY

Bugcrowd Announces Vulnerability Ratings for LLMs
The update to the company's Vulnerability Rating Taxonomy offers vulnerability researchers a framework for assessing and prioritizing vulnerabilities in large language models.
LATEST FROM DR GLOBAL

Israel Blames Iran for Hospital Data Breach
Israeli intelligence said a cyber unit of Hezbollah also was involved in the cyberattack.
WEBINARS
WHITE PAPERS
FEATURED REPORTS
View More Dark Reading Reports >>
Dark Reading Daily
-- Published By Dark Reading
Informa Tech Holdings LLC | Registered in the United States
with number 7418737 | 605 Third Ave., 22nd Floor, New York, New York 10158, USA
To opt-out of any future Dark Reading Daily Newsletter emails, please respond here.
Thoughts about this newsletter? Give us feedback.
Keep This Newsletter Out Of Your SPAM Folder
Don't let future editions go missing. Take a moment to add the newsletter's address to your anti-spam white list:
If you're not sure how to do that, ask your administrator or ISP. Or check your anti-spam utility's documentation.
We take your privacy very seriously. Please review our Privacy Statement.