fireeye Premier Cybersecurity Firm FireEye Suffers Major State-Sponsored Breach FireEye, a top cybersecurity company that investigates major hacks worldwide, reveals that it is now a victim of a sophisticated attack by a foreign government. The breach highlights that even the most advanced digital defenders remain highly vulnerable to elite nation-state threats.
fireeye Top-Tier Nation-State Hackers Breach Cybersecurity Firm FireEye, Steal Red Team Tools FireEye reveals that sophisticated nation-state hackers, widely believed to be aligned with Russia, breach their systems and steal specialized offensive security tools. The company sees no evidence yet that the stolen red team tools are being used in the wild.
solarwinds State-Sponsored Actors Compromise Thousands Through SolarWinds Supply Chain Attack A sophisticated supply chain attack involving trojanized SolarWinds Orion updates affects numerous government and private organizations globally. Cisco Talos actively monitors the situation and urges immediate patching following DHS guidance.
solarwinds GAO Details Massive SolarWinds Cyberattack and Ongoing Government Response The Government Accountability Office outlines how Russian intelligence executed the widespread SolarWinds breach and how federal agencies are responding. GAO is currently conducting a comprehensive review of the incident to release a public report later this year.
cisa Trump Ousts Cybersecurity Chief Over Election Security Statement President Trump fires CISA Director Chris Krebs after the agency declares the 2020 election the most secure in American history. Krebs previously leads an effort to debunk widespread voter fraud disinformation.
solarwinds Sophisticated Supply Chain Attack Targets Global Organizations via SolarWinds FireEye uncovers a widespread global intrusion campaign that uses trojanized SolarWinds Orion updates to distribute the SUNBURST backdoor. The highly evasive threat actors, now attributed to APT29, use advanced techniques to blend in with legitimate network traffic.
solarwinds SolarWinds Supply Chain Attack Exploits Software Backdoor to Bypass Authentication A highly sophisticated cyber-attack targets the SolarWinds Orion platform through a compromised supply chain, allowing threat actors to bypass authentication and execute unauthenticated commands.
solarwinds SolarWinds Supply Chain Attack Creates Unprecedented Cybersecurity Fallout The SolarWinds supply chain compromise catches the security industry off guard and threatens critical infrastructure with potential physical consequences. A detailed timeline reveals how the massive intrusion unfolds through compromised software updates.
trump President Trump Fires Cybersecurity Chief Chris Krebs Over Election Claims President Trump terminates top cybersecurity official Christopher Krebs following Krebs' statements affirming the security of the 2020 election. Krebs maintains that his agency handled the election protection efforts correctly.
solarwinds SolarWinds Supply Chain Attack Explained: Widespread Impact and Ongoing Fallout The SolarWinds hack involves malicious code injected into the Orion software platform, compromising thousands of organizations globally. The breach sparks ongoing legal battles with the SEC and highlights severe vulnerabilities in IT supply chains.
zoom Zoom Reaches FTC Settlement Over Misleading Encryption Promises Video conferencing platform Zoom agrees to implement a stronger security program and undergo regular assessments after the FTC accuses it of falsely claiming to offer end-to-end encryption.
apple CISA Warns Users to Apply Critical Apple Security Updates Apple releases security patches for macOS and Safari to fix severe vulnerabilities that attackers are actively exploiting. CISA urges all users and administrators to update their systems immediately.
enterprise Greylock Investor Asheem Chandna Explores Future of Enterprise and Cybersecurity Startups TechCrunch hosts an Extra Crunch Live session with Greylock's Asheem Chandna to discuss the rapidly evolving enterprise and cybersecurity startup landscapes.
true app Privacy-Focused Social App True Exposes User Data in Server Lapse A social networking app that promises to protect user privacy accidentally leaves a database exposed, leaking private messages, locations, and account tokens.
cybersecurity Cryptocurrency Scammers Briefly Hijack Trump Campaign Website Unknown hackers briefly take over part of President Trump's campaign website to run a Monero cryptocurrency scam. Authorities confirm no sensitive donor data is exposed during the minutes-long incident.