Contact Sales
Contact Sales

NewsBites Cyber Security News

SANS NewsBites is a semiweekly executive summary of the most important cyber security news articles published recently. Each news item is annotated with important context provided by respected subject matter experts within the SANS community.

Filter by:

CVE Program Regains Threatened Funding; CISA Urges Caution After Oracle Breach; UK ICO Fines Law Firm for 2022 Data Theft

NewsletterNewsbites
  • 18 Apr 2025
  • Volume #XXVII
  • Issue #30

CA/Browser Forum Cuts SLS/TLS Cert Lifespan to 47 Days; Threat Actors Maintained Persistence on Patched Fortinet Devices; Windows inetpub Folder is Part of a Security Fix

NewsletterNewsbites
  • 15 Apr 2025
  • Volume #XXVII
  • Issue #29

Oracle Says Data Was Stolen From "Obsolete" Servers; US OCC Experienced Major Cybersecurity Incident; CIS Will Provide Gap Funding for MS-ISAC

NewsletterNewsbites
  • 11 Apr 2025
  • Volume #XXVII
  • Issue #28

UK Tribunal Opens "Bare Details" of Apple E2EE Backdoor Order; Update Apache Parquet to Fix CVSS 10.0 RCE; UMD Medical Center Sued Over Employee's Keylogging

NewsletterNewsbites
  • 08 Apr 2025
  • Volume #XXVII
  • Issue #27

Cisco CSLU Critical Flaw Added to KEV; Oracle Faces Class Action Suit; Ivanti Buffer Overflow Exploited for RCE

NewsletterNewsbites
  • 04 Apr 2025
  • Volume #XXVII
  • Issue #26

HTTPS Certificates Get New Security Requirements; Oracle Health Data Breach; 23andMe Future Buyer Must Follow Privacy Policy

NewsletterNewsbites
  • 01 Apr 2025
  • Volume #XXVII
  • Issue #25

23andMe Files Bankruptcy, Consider Deleting Data; FOSS Needs Protection from AI Crawlers

NewsletterNewsbites
  • 28 Mar 2025
  • Volume #XXVII
  • Issue #24

Update Chrome to fix Critical Use-After-Free Flaw; WP Ghost Wordpress Plugin Vulnerable to RCE; "IngressNightmare" Flaws in Ingress NGINZ Controller

NewsletterNewsbites
  • 25 Mar 2025
  • Volume #XXVII
  • Issue #23

Counterfeit CAPTCHA ClickFix Lures; Windows Shortcuts Exploited Since 2017; GitHub Actions Compromise May Be Cascading Supply Chain Attack

NewsletterNewsbites
  • 22 Mar 2025
  • Volume #XXVII
  • Issue #22

E2EE RCS Between iOS and Android; Alexa Verbal Commands Will be Sent to Cloud; UK Holds Closed-Door IPT Hearing Despite Outcry

NewsletterNewsbites
  • 18 Mar 2025
  • Volume #XXVII
  • Issue #21

Apple Webkit Zero-Day Exploited; Patch Tuesday: Microsoft, Adobe, Apple; Ivanti and VeraCore Flaws Added to KEV

NewsletterNewsbites
  • 14 Mar 2025
  • Volume #XXVII
  • Issue #20

Known PHP Flaw Actively Exploited for RCE; Fortra: Malicious Use of Cobalt Strike Down 80 Percent

NewsletterNewsbites
  • 11 Mar 2025
  • Volume #XXVII
  • Issue #19