FreshRSS

๐Ÿ”’
โŒ About FreshRSS
There are new available articles, click to refresh the page.
Before yesterdayDark Reading:

White House Scales Back Response to SolarWinds & Exchange Server Attacks

By Jai Vijayan Contributing Writer
Lessons learned from the Unified Coordination Groups will be used to inform future response efforts, a government official says.

  • April 19th 2021 at 22:10

Attackers Test Weak Passwords in Purple Fox Malware Attacks

By Dark Reading Staff
Researchers share a list of passwords that Purple Fox attackers commonly brute force when targeting the SMB protocol.

  • April 19th 2021 at 21:45

Lazarus Group Uses New Tactic to Evade Detection

By Dark Reading Staff
Attackers conceal malicious code within a BMP file to slip past security tools designed to detect embedded objects within images.

  • April 19th 2021 at 20:30

SolarWinds: A Catalyst for Change & a Cry for Collaboration

By Kurt John Chief Cybersecurity Officer, Siemens USA
Cybersecurity is more than technology or safeguards like zero trust; mostly, it's about collaboration.

  • April 19th 2021 at 14:00

Pandemic Drives Greater Need for Endpoint Security

By Dark Reading Staff
Endpoint security has changed. Can your security plan keep up?

  • April 16th 2021 at 21:10

High-Level Admin of FIN7 Cybercrime Group Sentenced to 10 Years in Prison

By Dark Reading Staff
Fedir Hladyr pleaded guilty in 2019 to conspiracy to commit wire fraud and conspiracy to commit computer hacking.

  • April 16th 2021 at 20:25

Security Gaps in IoT Access Control Threaten Devices and Users

By Kelly Sheridan Staff Editor, Dark Reading
Researchers spot problems in how IoT vendors delegate device access across multiple clouds and users.

  • April 16th 2021 at 20:00

How the Biden Administration Can Make Digital Identity a Reality

By Hal Granoff Head of US Market Development at Callsign
A digital identity framework is the answer to the US government's cybersecurity dilemma.

  • April 16th 2021 at 14:00

Software Developer Arrested in Computer Sabotage Case

By Dark Reading Staff
Officials say Davis Lu placed malicious code on servers in a denial-of-service attack on his employer.

  • April 15th 2021 at 23:30

Google Brings 37 Security Fixes to Chrome 90

By Dark Reading Staff
The latest version of Google Chrome also introduces HTTPS as the browser's default protocol.

  • April 15th 2021 at 21:25

US Formally Attributes SolarWinds Attack to Russian Intelligence Agency

By Jai Vijayan Contributing Writer
Treasury Department slaps sanctions on IT security firms that it says supported Russia's Foreign Intelligence Service carry out the attacks.

  • April 15th 2021 at 20:25

Pandemic Pushes Bot Operators to Redirect Efforts

By Robert Lemos Contributing Writer
As demand for travel, lodging, and concerts plummeted in 2020, bot traffic moved to more popular activities, such as e-commerce, healthcare, and government sites.

  • April 15th 2021 at 20:20

6 Tips for Managing Operational Risk in a Downturn

By Steve Durbin CEO of the Information Security Forum
Many organizations adjust their risk appetite in an economic downturn, as risk is expanded to include supplier and customer insolvency, not to mention cash-flow changes.

  • April 15th 2021 at 17:00

How to Create an Incident Response Plan From the Ground Up

By Eric Ahlm Senior Research Director, Gartner
Security 101: In the wake of an incident, it's important to cover all your bases -- and treat your IR plan as a constantly evolving work in progress.

  • April 15th 2021 at 16:35

Nation-State Attacks Force a New Paradigm: Patching as Incident Response

By Fred Langston Executive Vice President of Professional Services and Co-Founder, CI Security
IT no longer has the luxury of thoroughly testing critical vulnerability patches before rolling them out.

  • April 15th 2021 at 14:00

Malicious PowerShell Use, Attacks on Office 365 Accounts Surged in Q4

By Jai Vijayan Contributing Writer
There was also a sharp increase in overall malware volumes in the fourth quarter of 2020, COVID-19 related attack activity, and mobile malware, new data shows.

  • April 15th 2021 at 13:00

Test-DEU-169665

By Kelly Sheridan Staff Editor, Dark Reading
President Biden has nominated Jen Easterly as the new director of CISA and is expected to nominate Chris Inglis as the first national cyber director.

  • April 15th 2021 at 08:30

Thycotic & Centrify Merge to Form Cloud Identity Security Firm

By Dark Reading Staff
The combined entity will expand on both companies' privileged access management tools and expects to debut a new brand this year.

  • April 14th 2021 at 21:00

CISA Urges Caution for Security Researchers Targeted in Attack Campaign

By Dark Reading Staff
The agency urges researchers to take precautions amid an ongoing targeted threat campaign.

  • April 14th 2021 at 20:30

FBI Operation Remotely Removes Web Shells From Exchange Servers

By Kelly Sheridan Staff Editor, Dark Reading
A court order authorized the FBI to remove malicious Web shells from hundreds of vulnerable machines running on-premises Exchange Server.

  • April 14th 2021 at 19:25

The CISO Life Is Half as Good

By Sara Peters Senior Editor at Dark Reading
Lora Vaughn was at a crossroads -- and that was before mandated pandemic lockdowns came into play. Here's her story of how life got sweeter after she stepped away from the CISO job.

  • April 14th 2021 at 15:30

Bolstering Our Nation's Defenses Against Cybersecurity Attacks

By Shawn Henry CrowdStrike president of services and CSO
Shawn Henry, former Executive Assistant Director of the FBI and current CrowdStrike president of services and CSO, shares the top three cybersecurity priorities that the Biden administration needs to address.

  • April 14th 2021 at 14:00

Dependency Problems Increase for Open Source Components

By Robert Lemos Contributing Writer
The number of components in the average application rose 77% over two years. No wonder, then, that 84% of codebases have at least one vulnerability.

  • April 14th 2021 at 13:20

DNS Vulnerabilities Expose Millions of Internet-Connected Devices to Attack

By Jai Vijayan Contributing Writer
Researchers uncover a fresh set of nine vulnerabilities in four TCP/IP stacks that are widely used in everything from powerful servers and firewalls to consumer IoT products.

  • April 13th 2021 at 22:15

NSA Alerted Microsoft to New Exchange Server Vulnerabilities

By Kelly Sheridan Staff Editor, Dark Reading
Microsoft today patched 114 CVEs to address the Exchange Server flaws, more than 50 remote code execution vulnerabilities, and one zero-day.

  • April 13th 2021 at 21:39

Compromised Microsoft Exchange Server Used to Host Cryptominer

By Dark Reading Staff
Researchers say an unknown attacker is targeting vulnerable Exchange Servers with a payload hosted on a compromised Exchange Server.

  • April 13th 2021 at 21:35

Global Dwell Time Drops as Ransomware Attacks Accelerate

By Kelly Sheridan Staff Editor, Dark Reading
The length of time attackers remain undiscovered in a target network has fallen to 24 days, researchers report, but ransomware plays a role.

  • April 13th 2021 at 20:50

Dark Reading to Upgrade Site Design, Performance

By Tim Wilson, Editor in Chief, Dark Reading
Improvements will make site content easier to navigate, faster, and more functional.

  • April 13th 2021 at 20:00

5 Objectives for Establishing an API-First Security Strategy

By Ryan Nolette Technical Security Lead at Postman
With APIs predicted to be the most common attack vector by 2022, an API-first security strategy is critical now more than ever.

  • April 13th 2021 at 17:00

Clear & Present Danger: Data Hoarding Undermines Better Security

By Elissa M. Redmiles Researcher, Max Planck Institute for Software Systems
Facebook and Google can identify patterns of attack within their own data, but smaller businesses rarely see enough traffic to successfully identify an attack or warn users.

  • April 13th 2021 at 14:00

Biden Nominates Former NSA Officials for Top Cybersecurity Roles

By Kelly Sheridan Staff Editor, Dark Reading
President Biden has nominated Jen Easterly as the new director of CISA and is expected to nominate Chris Inglis as the first national cyber director.

  • April 12th 2021 at 21:55

Microsoft Warns of Malware Delivery via Google URLs

By Dark Reading Staff
A new campaign abuses legitimate website contact forms to send URLs that ultimately deliver the IcedID banking Trojan.

  • April 12th 2021 at 20:10

Federal Reserve Chairman Says Cyber-Risk a Top Threat to National Economy

By Dark Reading Staff
Jerome Powell tells 60 Minutes that cyberattacks have the potential to do major damage to US financial system.

  • April 12th 2021 at 19:35

Microsoft Uses Machine Learning to Predict Attackers' Next Steps

By Robert Lemos Contributing Writer
Researchers build a model to attribute attacks to specific groups based on tactics, techniques, and procedures, and then figure out their next move.

  • April 12th 2021 at 15:55

New Malware Downloader Spotted in Targeted Campaigns

By Jai Vijayan Contributing Writer
Saint Bot is being used to drop stealers on compromised systems but could be used to deliver any malware.

  • April 12th 2021 at 14:30

Wake Up and Smell the JavaScript

By Deepika Gajaria VP of Products, Tala Security
The SolarWinds attack showed the true meaning of a supply chain breach. And it's the canary in the coal mine for sensitive data on the Web.

  • April 12th 2021 at 14:00

Omdia Research Spotlight: XDR

By Eric Parizo Senior Analyst, Omdia
Few emerging cybersecurity market segments are garnering more attention than XDR. Here, Omdia highlights its recent research on XDR.

  • April 12th 2021 at 13:00

CISA Launches New Threat Detection Dashboard

By Dark Reading Staff
Aviary is a new dashboard that works with CISA's Sparrow threat detection tool.

  • April 9th 2021 at 21:15

Battle for the Endpoint

How to build a new cyber strategy for 2021 and beyond.
  • April 9th 2021 at 21:15

Unofficial Android App Store APKPure Infected With Malware

By Dark Reading Staff
The APKPure app store was infected with malware that can download Trojans to other Android devices, researchers report.

  • April 9th 2021 at 21:15

8 Security & Privacy Apps to Share With Family and Friends

By Kelly Sheridan Staff Editor, Dark Reading
Mobile apps to recommend to the people in your life who want to improve their online security and privacy.

  • April 9th 2021 at 20:30

Women Are Facing an Economic Crisis & the Cybersecurity Industry Can Help

By Sabrina Castiglione Chief Financial Officer & Acting Head of Talent
Investing in women's cybersecurity careers can bring enormous benefits and help undo some of the significant economic damage wrought by the pandemic.

  • April 9th 2021 at 14:00

Zoom Joins Microsoft Teams on List of Enterprise Tools Hacked at Pwn2Own

By Jai Vijayan Contributing Writer
White-hat hacking event shows yet again why there's no such thing as foolproof security against modern attacks.

  • April 8th 2021 at 22:15

Fraudsters Use HTML Legos to Evade Detection in Phishing Attack

By Dark Reading Staff
Criminals stitch pieces of HTML together and hide them in JavaScript files, researchers report.

  • April 8th 2021 at 21:45

600K Payment Card Records Leaked After Swarmshop Breach

By Dark Reading Staff
A leaked database also contains the nicknames, hashed passwords, contact details, and activity history of Swarmshop admins, sellers, and buyers.

  • April 8th 2021 at 21:30

Handcuffs Over AI: Solving Security Challenges With Law Enforcement

By Charles Herring CTO and Co-Founder, WitFoo
We've tried everything else ... now it's time to make the prospect of getting caught -- and punished -- a real deterrent to cybercrime.

  • April 8th 2021 at 14:00

SecOps and DevOps: From Cooperation to Automation

By Eric Parizo Senior Analyst, Omdia
Omdia Principal Analyst Eric Parizo discusses the major obstacles SecOps organizations face as they seek to build ties with DevOps teams, and offers a programmatic approach to help create a path toward DevSecOps.

  • April 7th 2021 at 23:00

Did 4 Major Ransomware Groups Truly Form a Cartel?

By Robert Lemos Contributing Writer
An analysis of well-known extortion groups and their cryptocurrency transactions reveals the answer.

  • April 7th 2021 at 22:55

Voice-Changing Software Found on APT Attackers' Server

By Kelly Sheridan Staff Editor, Dark Reading
Security researchers believe the presence of Morph Vox Pro could indicate APT-C-23 has new plans for their phishing campaigns.

  • April 7th 2021 at 21:10

Cring Ransomware Used in Attacks on European Industrial Firms

By Dark Reading Staff
Attackers exploited a vulnerability in Fortigate VPN servers to gain access to target networks, researchers report.

  • April 7th 2021 at 20:07

Fortune 500 Security Shows Progress and Pitfalls

By Kelly Sheridan Staff Editor, Dark Reading
Fortune 500 companies have improved on email security and vulnerability disclosure programs but struggle in asset management and high-risk services.

  • April 7th 2021 at 19:35

Rethinking Cyberattack Response: Prevention & Preparedness

By Hitesh Sheth CEO, Vectra
The SolarWinds incident is the starkest reminder yet that complacency can exact a terrible price.

  • April 7th 2021 at 17:00

5 Ways to Transform Your Phishing Defenses Right Now

By Kevin O'Brien Co-Founder and CEO, GreatHorn
By transforming how you approach phishing, you can break the phishing kill chain and meaningfully reduce your business risk.

  • April 7th 2021 at 14:00

Attackers Actively Seeking, Exploiting Vulnerable SAP Applications

By Jai Vijayan Contributing Writer
Analysis of threat activity in mission-critical environments prompts CISA advisory urging SAP customers to apply necessary security patches and updates.

  • April 7th 2021 at 13:30

Cartoon Caption Winner: Something Seems Afoul

By John Klossner Cartoonist
And the winner of Dark Readings's March cartoon caption contest is ...

  • April 7th 2021 at 12:45

Microsoft Teams, Exchange Server, Windows 10 Hacked in Pwn2Own 2021

By Dark Reading Staff
The 2021 Pwn2Own is among the largest in its history, with 23 separate entries targeting 10 products.

  • April 6th 2021 at 22:20

Security Falls Short in Rapid COVID Cloud Migration

By Dark Reading Staff
The quick pivot to the cloud for remote support also ushered in risks.

  • April 6th 2021 at 21:50

Crime Service Gives Firms Another Reason to Purge Macros

By Robert Lemos Contributing Writer
Recent Trickbot campaigns and at least three common banking Trojans all attempt to infect systems using malicious macros in Microsoft Office documents created using EtterSilent.

  • April 6th 2021 at 21:25

The Edge Pro Tip: Update Your DDoS Defense Plan

By Edge Editors Dark Reading
The idea of monetizing distributed denial-of-service (DDoS) attacks dates back to the 1990s. But the rise of DDoS-for-hire services and cryptocurrencies has radically changed the landscape.

  • April 6th 2021 at 20:50

Ryuk's Rampage Has Lessons for the Enterprise

By Andrew Jaquith Chief Information Security Officer & General Manager, Cyber, COMPLEX
The Ryuk ransomware epidemic is no accident. The cybercriminals responsible for its spread have systematically exploited weaknesses in enterprise defenses that must be addressed.

  • April 6th 2021 at 17:00
โŒ