Wyden calls for probe of federal judiciary data breaches, accusing it of ânegligenceâ
Earlier this month court officials publicly acknowledged recent digital attacks âof a sophisticated and persistent nature on its case management systemâ had prompted them to boost their online defenses.
Critical Docker Desktop flaw lets attackers hijack Windows hosts
A critical vulnerability in Docker Desktop for Windows and macOS allows compromising the host by running a malicious container, even if the Enhanced Container Isolation (ECI) protection is active.
Defending against malware persistence techniques with Wazuh
Malware persistence keeps attackers in your systems long after reboots or resets. Wazuh helps detect and block hidden techniques like scheduled tasks, startup scripts, and modified system filesâbefore they turn into long-term compromise.
What Auditors Wish Every Company Knew About SOC 2 | CSA
Information Security Analyst Ishaan Gulati has worked with both internal and external auditors. His hard-earned lessons can help you prepare for a SOC 2 audit.
Chinese Developer Jailed for Deploying Malicious Code at US Company
A Chinese developer has been sentenced to four years in prison after being found to deploy malicious code in his employerâs network, including a âkill switchâ
Microsoft working on fix for ongoing Outlook email issues
âMicrosoft is working to resolve an Exchange Online issue causing email access problems for Outlook mobile users who use Hybrid Modern Authentication (HMA).
FTC warns tech giants not to bow to foreign pressure on encryption
The Federal Trade Commission (FTC) is warning major U.S. tech companies against yielding to foreign government demands that weaken data security, compromise encryption, or impose censorship on their platforms.
New Android malware poses as antivirus from Russian intelligence agency
A new Android malware posing as an antivirus tool software created by Russia's Federal Security Services agency (FSB) is being used to target executives of Russian businesses.
Murky Panda hackers exploit cloud trust to hack downstream customers
A Chinese state-sponsored hacking group known as Murky Panda (Silk Typhoon) exploits trusted relationships in cloud environments to gain initial access to the networks and data of downstream customers.
Friday Squid Blogging: Bobtail Squid - Schneier on Security
Nice short article on the bobtail squid. As usual, you can also use this squid post to talk about the security stories in the news that I havenât covered. Blog moderation policy.
I'm Spending the Year at the Munk School - Schneier on Security
This academic year, I am taking a sabbatical from the Kennedy School and Harvard University. (Itâs not a real sabbaticalâIâm just an adjunctâbut itâs the same idea.) I will be spending the Fall 2025 and Spring 2026 semesters at the Munk School at the University of Toronto. I will be organizing a reading group on AI security in the fall. I will be teaching my cybersecurity policy class in the Spring. I will be working with Citizen Lab, the Law School, and the Schwartz Reisman Institute. And I will be enjoying all the multicultural offerings of Toronto...