Talk With an Expert

NewsBites Cyber Security News

SANS NewsBites is a semiweekly executive summary of the most important cyber security news articles published recently. Each news item is annotated with important context provided by respected subject matter experts within the SANS community.

Filter by:

Microsoft Limits Some MAPP Sharing; MITRE Updates Most Important Hardware Weaknesses; CISA Solicits Comment on "Minimum Elements for a SBOM"

NewsletterNewsbites
  • 26 Aug 2025
  • Volume #XXVII
  • Issue #62

Apple Releases Emergency Updates for Actively Exploited ImageIO Flaw; FBI Warns of FSB Actively Exploiting of Cisco Smart Install; Scattered Spider Member Sentenced

NewsletterNewsbites
  • 22 Aug 2025
  • Volume #XXVII
  • Issue #61

MS Nuance Settles MOVEit Breach Suit for $8.5M; End of Support for Windows 10 in October 2025; NIST Updates Digital Identity Guidelines

NewsletterNewsbites
  • 19 Aug 2025
  • Volume #XXVII
  • Issue #60

OT Systems: Erlang/OTP RCE Exploitation, CISA Security Guidance, and Dragos Financial Risk Report; Patch Tuesday: Microsoft, Adobe, SAP, Intel, and Google

NewsletterNewsbites
  • 15 Aug 2025
  • Volume #XXVII
  • Issue #59

DEF CON Franklin Assists US Water Utilities at No Cost; CISA Pledges Ongoing CVE Funding; DARPA AI Cyber Challenge Winners Announced

NewsletterNewsbites
  • 12 Aug 2025
  • Volume #XXVII
  • Issue #58

Patch Now: Privilege Escalation in MS Exchange Hybrid Deployments; RCE in ControlVault Firmware on Dell Laptops; Zero-Day RCE in Adobe Experience Manager on Java Enterprise Edition

NewsletterNewsbites
  • 08 Aug 2025
  • Volume #XXVII
  • Issue #57

NVIDIA Patches Flaws in Triton Inference Server; SonicWall Investigates Reports of Attacks on Firewalls; Cursor IDE Had Multiple RCE Flaws

NewsletterNewsbites
  • 05 Aug 2025
  • Volume #XXVII
  • Issue #56

Google Project Zero Shortens Upstream Patch Gap; Saint Paul, MN Cyberattack Requires National Guard Assistance; Apple Updates and Microsoft Analysis of macOS Sploitlight

NewsletterNewsbites
  • 01 Aug 2025
  • Volume #XXVII
  • Issue #55

US Senator Requests Mandiant's Salt Typhoon Telco Reports; EU Firms Struggle to Comply With DORA; Google Offers Defensive Measures Against Scattered Spider VMWare Attacks

NewsletterNewsbites
  • 29 Jul 2025
  • Volume #XXVII
  • Issue #54

SharePoint – Assume Compromise and Implement Mitigations

NewsletterNewsbites
  • 25 Jul 2025
  • Volume #XXVII
  • Issue #53

Little-Known Microsoft "Escorts" Handle Sensitive DOD Data; Salt Typhoon Compromised US Army National Guard Network; Stuxnet Anniversary Congressional Hearing on Cyber Threats to Critical Infrastructure

NewsletterNewsbites
  • 18 Jul 2025
  • Volume #XXVII
  • Issue #52

Actively Exploited Flaws to Patch Now: CitrixBleed 2 Memory Safety, Wing FTP Server RCE; Former Employee Steals & Shares Semiconductor IP, Lands 3-Year Prison Sentence

NewsletterNewsbites
  • 15 Jul 2025
  • Volume #XXVII
  • Issue #51