News
  • "Cyber Attacks Against Middle East Governments Hide Malware in Windows Logo"

    In its attacks against Middle Eastern governments, an espionage-focused threat actor has been observed using a steganographic tactic to hide a previously unknown backdoor in a Windows logo. Broadcom's Symantec Threat Hunter Team attributed the updated…

  • "GSMA, IBM and Vodafone Establish Post-Quantum Telco Network Taskforce"

    The GSMA has announced the formation of the GSMA Post-Quantum Telco Network Taskforce, with IBM and Vodafone as initial members, to help in the definition of policy, regulation, and operator business processes for enhanced telecommunications protection…

  • "Less Than 5% Of Public Companies Use the Latest Email Security Standards"

    Phishing remains the most common type of cyberattack. The Anti-Phishing Working Group observed the most phishing attacks in history in the first quarter of 2022, as the quarterly volume of attacks surpassed 1 million for the first time. Organizations…

  • "Huijia Lin Proved That a Master Tool of Cryptography Is Possible"

    A long-desired holy grail in cryptography is about to change the way sensitive data is protected. Existing standard encryption schemes are all-or-nothing as data is inaccessible to anyone who does not have the secret key once it is scrambled. This has…

  • Pub Crawl #66

    ​Pub Crawl summarizes, by hard problems, sets of publications that have been peer reviewed and presented at SoS conferences or referenced in current work. The topics are chosen for their usefulness for current researchers.

  • "'Protestware' Is on the Rise, With Programmers Self-Sabotaging Their Own Code. Should We Be Worried?"

    The author of node-ipc, a software library with over a million downloads weekly, deliberately broke their code in March 2022. If the code detects that it is being executed within Russia or Belarus, it attempts to replace the contents of every file on the…

  • "Treasury Seeks Comment on How to Structure a Cyber Insurance Program"

    The US Treasury Department's Federal Insurance Office (FIO) wants to know if a national cyber insurance program should enforce that policyholders implement basic cybersecurity measures. In a request for comment set to be published in the Federal Register…

  • "Government, Union-Themed Lures Used to Deliver Cobalt Strike Payloads"

    Security researchers at Cisco Talos discovered a malicious campaign in August 2022 that relied on modularized attack techniques to deliver Cobalt Strike beacons and used them in follow–on attacks.  The researchers stated that the threat actors…

  • "XSS Flaw in Prevalent Media Imaging Tool Exposes Trove of Patient Data"

    Canon Medical's Vitrea View is a widely used tool for securely sharing medical images between radiologists, physicians, and other healthcare providers on a patient care team.  Researchers at Trustwave's SpiderLabs have recently discovered two…

  • "U of G Researchers Aim to Make 'Smart Farming' Work for Greater Food Security"

    According to researchers at the University of Guelph, Canada's wide-open farm fields are vulnerable to cyberattacks and data privacy attacks, as well as unethical data use. Dr. Rozita Dara, a professor in the College of Engineering and Physical Sciences…

  • "A Third of People Fall Victim to Cyberattacks Despite Training"

    The National Cybersecurity Alliance and CybSafe surveyed 3,000 people in the US, UK, and Canada, finding that while 58 percent of tech users who had access to cybersecurity training or education say they are better at recognizing phishing messages and…

  • "LSU Receives Elite Cyber Designation From the National Security Agency"

    The National Security Agency (NSA), the nation’s preeminent cybersecurity agency, has designated LSU as a Center of Academic Excellence in Cyber Operations, or CAE-CO. LSU joins only 21 other universities and colleges in the U.S. with the designation,…