FreshRSS

πŸ”’
❌ About FreshRSS
There are new available articles, click to refresh the page.
Before yesterdayDark Reading:

Ransomware Attempts Flag as Payments Also Decline

By Robert Lemos, Contributing Writer, Dark Reading
Telecom and business services see the highest level of attacks, but the two most common ransomware families, which continue to be LockBit and Conti, are seen less often.

  • July 18th 2022 at 16:00

Watch Out for User Impersonation in Low-Code/No-Code Apps

By Michael Bargury, CTO & Co-Founder, Zenity
How a well-meaning employee could unwittingly share their identity with other users, causing a whole range of problems across IT, security, and the business.

  • July 18th 2022 at 14:00

Building Guardrails for Autonomic Security

By Sounil Yu, CISO and Head of Research, JupiterOne
AI's potential for automating security has promise, but there are miles to go in establishing decision-making boundaries.

  • July 18th 2022 at 14:00

Netwrix Auditor Bug Could Lead to Active Directory Domain Compromise

By Dark Reading Staff, Dark Reading
IT asset tracker and auditor software has a critical issue with insecure object deserialization that could allow threat actors to execute code, researchers say.

  • July 15th 2022 at 18:30

What Are the Risks of Employees Going on a 'Hybrid Holiday'?

By John Ayers, Vice President of Product, Advanced Detection & Response, Optiv
As more employees plan on taking longer holidays and working remotely from the destination for part of that time, organizations have to consider the risks. Like Wi-Fi networks.

  • July 15th 2022 at 18:13

How Attackers Could Dupe Developers into Downloading Malicious Code From GitHub

By Jai Vijayan, Contributing Writer, Dark Reading
Developers need to be cautious about whom they trust on GitHub because it's easy to establish fake credibility on the platform, security vendor warns.

  • July 15th 2022 at 17:27

Ex-CIA Programmer Found Guilty of Stealing Vault 7 Data, Giving It to Wikileaks

By Dark Reading Staff, Dark Reading
Joshua Schulte has been convicted for his role in the Vault 7 Wikileaks data dump that exposed invasive US cyber intelligence tactics.

  • July 15th 2022 at 16:43

Sandworm APT Trolls Researchers on Its Trail as It Targets Ukraine

By Kelly Jackson Higgins, Editor-in-Chief, Dark Reading
Researchers who helped thwart the Russian nation-state group's recent attack on Ukraine's power supply will disclose at Black Hat USA what they found while reverse-engineering the powerful Industroyer2 malware used by the powerful hacking team.

  • July 15th 2022 at 15:16

How Hackers Create Fake Personas for Social Engineering

By John Hammond, Senior Security Researcher, Huntress
And some ways to up your game for identifying fabricated online profiles of people who don't exist.

  • July 15th 2022 at 14:00

Bishop Fox Secures $75 Million in Growth Funding From Carrick Capital Partners

Offensive security leader continues to defy market and economic trends with record growth and recognized innovation.
  • July 14th 2022 at 22:17

DHS Review Board Deems Log4j an 'Endemic' Cyber Threat

By Jai Vijayan, Contributing Writer, Dark Reading
Vulnerability will remain a "significant" threat for years to come and highlighted the need for more public and private sector support for open source software ecosystem, Cyber Safety Review Board says.

  • July 14th 2022 at 20:43

New Phishing Kit Hijacks WordPress Sites for PayPal Scam

By Dark Reading Staff, Dark Reading
Attackers use scam security checks to steal victims' government documents, photos, banking information, and email passwords, researchers warn.

  • July 14th 2022 at 20:22

Scribe Security Releases Code Integrity Validator Alongside Github Security Open Source Project

Developers can now rest assured that the code they are using, as well as their GitHub accounts, are safe.
  • July 14th 2022 at 19:35

AEI HorizonX Ventures Joins Shift5 Series B Funding Round

Investment bolsters Shift5’s traction within commercial aerospace and defense industries.
  • July 14th 2022 at 19:30

Data of Nearly 2M Patients Exposed in Ransomware Attack on Healthcare Debt Collection Firm

By Dark Reading Staff, Dark Reading
Professional Finance Company (PFC) was hit in February 2022 by a ransomware attack.

  • July 14th 2022 at 18:06

Is Cryptocurrency's Crash Causing Headaches for Ransomware Gangs?

By Robert Lemos, Contributing Writer, Dark Reading
Bitcoin is down more than 70% from its highs late last year, causing disruptions for cybercriminals and the underground exchanges that fuel the dark markets.

  • July 14th 2022 at 14:50

Virtual CISOs Are the Best Defense Against Accelerating Cyber-Risks

By Jim Tiller, Global CISO, Nash Squared and Harvey Nash USA
A poor, permanent hire can be a very expensive error, whereas a mis-hire on a virtual CISO can be rapidly corrected.

  • July 14th 2022 at 14:00

The Next Generation of Threat Detection Will Require Both Human and Machine Expertise

By Kumar Saurabh, CEO and Co-Founder, LogicHub
To be truly effective, threat detection and response need to combine the strengths of people and technology.

  • July 14th 2022 at 13:33

Data Breaches Linked to Ransomware Declined in Q2 2022

By Nathan Eddy, Contributing Writer, Dark Reading
Phishing retained its place as the top root cause of data compromises, according to new data from the Identity Theft Resource Center (ITRC).

  • July 14th 2022 at 13:31

Researchers Devise New Speculative Execution Attacks Against Some Intel, AMD CPUs

By Jai Vijayan, Contributing Writer, Dark Reading
"Retbleed" bypasses a commonly used mechanism for protecting against a certain kind of side-channel attack.

  • July 13th 2022 at 22:55

CyberRatings.org Issues AAA Rating on Forcepoint's Cloud Network Firewall

Forcepoint's test results are second in a series of publications on this new technology.
  • July 13th 2022 at 21:23

Report: Financial Institutions Overly Complacent About Current Authentication Methods

New research report finds most financial organizations have experienced a breach due to an authentication weakness, yet only a third took action
  • July 13th 2022 at 21:09

Mozilla: EU's eIDAS Proposal Attracts Growing Criticism

In the wrong hands, the changes could enable state-sponsored internet surveillance says Mozilla's Chief Security Officer
  • July 13th 2022 at 20:24

MacOS Bug Could Let Malicious Code Break Out of Application Sandbox

By Dark Reading Staff, Dark Reading
Microsoft reveals now-fixed flaw in Apple's App Sandbox controls could allow attackers to escalate device privileges and deploy malware.

  • July 13th 2022 at 19:52

The 3 Critical Elements You Need for Vulnerability Management Today

Most organizations are flying blind when remediating vulnerabilities. We lack the tooling to secure software fast enough. We need a new approach to vulnerability management now.
  • July 13th 2022 at 19:39

Internet Searches Reveal Surprisingly Prevalent Ransomware

By Robert Lemos, Contributing Writer, Dark Reading
Two mostly defunct threats β€” WannaCry and NonPetya β€” top the list of ransomware searches, but does that mean they are still causing problems?

  • July 13th 2022 at 18:44

3 Golden Rules of Modern Third-Party Risk Management

By Yoni Shohet, CEO and Co-Founder, Valence Security
It's time to expand the approach of TPRM solutions so risk management is more effective in the digital world.

  • July 13th 2022 at 17:00

Survey: Small Cybersecurity Teams Face Greater Risk from Attacks than Larger Enterprises

Cynet CISO survey reveals lack of staff, skills, and resources driving smaller teams to outsource security with advanced tools, technologies, and services.
  • July 13th 2022 at 15:08

Microsoft: 10,000 Orgs Targeted in Phishing Attack That Bypasses Multifactor Authentication

By Dark Reading Staff, Dark Reading
The massive phishing campaign does not exploit a vulnerability in MFA. Instead, it spoofs an Office 365 authentication page to steal credentials.

  • July 13th 2022 at 14:54

US Government and QuSecure Orchestrate First-Ever Post-Quantum Encryption Communication over a Government Network

QuSecure’s QuProtect leverages unique post-quantum cryptographic algorithm on government legacy systems to achieve world’s first and only post-quantum resilient channel within a government facility.
  • July 13th 2022 at 14:17

New Research Reveals 93% of Organizations Surveyed Have Had Failed IIoT/OT Security Projects

Barracuda research finds organizations are struggling to protect operational technology and getting breached as a result.
  • July 13th 2022 at 14:01

Keep Humans in the Loop in SOC Operations

By A.N. Ananth, President, Netsurion
Machine learning and automation can help free up security pros for higher-value tasks.

  • July 13th 2022 at 14:00

Exostar Empowers SMBs with Enhanced, Low-Cost, Easy-to-Use Microsoft 365 and CMMC 2.0 Solutions

Upgrades to the Exostar platform promote secure, compliant collaboration and handling of controlled unclassified information.
  • July 13th 2022 at 13:39

QuickBooks Vishing Scam Targets Small Businesses

By Nathan Eddy, Contributing Writer, Dark Reading
Businesses receive an invoice via email with a credit card charge and are asked to call a fake number and hand over personal information to receive a refund.

  • July 13th 2022 at 12:00

Getting Up and Running with Windows Autopatch

By Dark Reading Staff, Dark Reading
This Tech Tip outlines how system administrators can get started with automated continuous patching for their Windows devices and applications.

  • July 13th 2022 at 00:33

PyPI Mandates 2FA, Plans Google Titan Key Giveaway

By Dark Reading Staff, Dark Reading
Python's most popular package manager is intent on securing the supply chain by requiring developers to enable two-factor authentication.

  • July 12th 2022 at 22:42

Microsoft Issues Fixes for 84 Vulnerabilities: Here's What to Patch Now

By Jai Vijayan, Contributing Writer, Dark Reading
July's security update included fixes for one actively exploited flaw, more than 30 bugs in Azure Site Recovery, and four privilege escalation bugs in Windows Print Spooler.

  • July 12th 2022 at 21:52

Understanding the Omdia Threat Detection Data Life Cycle

By Eric Parizo, Principal Analyst, Omdia
Data quality is key in an effective TDIR solution. Omdia's threat detection data life cycle highlights the considerations for effective data-driven threat detection.

  • July 12th 2022 at 20:11

Don't Have a COW: Containers on Windows and Other Container-Escape Research

By Ericka Chickowski, Contributing Writer, Dark Reading
Several pieces of Black Hat USA research will explore container design weaknesses and escalation of privilege attacks that can lead to container escapes.

  • July 12th 2022 at 18:28

One-Third of Users Without Security Awareness Training Click on Phishing URLs

By Dark Reading Staff, Dark Reading
New data from security training provider shows half of untrained users in consulting, energy, and healthcare industries fall for phishing attacks.

  • July 12th 2022 at 17:27

5 Traits That Differentiate CISOs From CIROs

By James Christiansen, VP of Cloud Security Transformation, Netskope
Chief information risk officers must have a keen understanding of β€” and interaction with β€” the business.

  • July 12th 2022 at 17:00

How Confidential Computing Locks Down Data, Regardless of Its State

By Ijlal Loutfi, Product Manager, Ubuntu Security
Whether data's in motion, at rest, or in use, confidential computing makes moving workloads to the public cloud safer, and can enhance data security in other deployments.

  • July 12th 2022 at 14:00

Accessible Cybersecurity Awareness Training Reduces Your Risk of Cyberattack

By Lise Lapointe, CEO and Founder, Terranova Security
If you're not teaching all of your employees proper security hygiene, you are leaving the door open to risk. Close that door by providing accessible training.

  • July 12th 2022 at 13:07

Ransomware Scourge Drives Price Hikes in Cyber Insurance

By Nathan Eddy, Contributing Writer, Dark Reading
Cybersecurity insurance costs are rising, and insurers are likely to demand more direct access to organizational metrics and measures to make more accurate risk assessments.

  • July 12th 2022 at 12:00

Paladin Cloud Launches New Cloud Security and Governance Platform

By Dark Reading Staff, Dark Reading
The new open source security-as-code platform will help developers and security teams automatically detect security policy violations across the organization's cloud infrastructure.

  • July 11th 2022 at 23:47

Fake Google Software Updates Spread New Ransomware

By Jai Vijayan, Contributing Writer, Dark Reading
"HavanaCrypt" is also using a command-and-control server that is hosted on a Microsoft Hosting Service IP address, researchers say.

  • July 11th 2022 at 22:18

'Luna Moth' Group Ransoms Data Without the Ransomware

By Dark Reading Staff, Dark Reading
Unsophisticated campaigns use off-the-shelf RATs and other tools to exfiltrate data and demand a ransom to keep it private.

  • July 11th 2022 at 21:38

Online Payment Fraud Expected to Cost $343B Over Next 5 Years

By Dark Reading Staff, Dark Reading
Fraudster innovation will continue to drive successful phishing, business email compromise, and socially engineered attacks, researchers say.

  • July 11th 2022 at 17:37

Proposed SEC Rules Require More Transparency About Cyber-Risk

By Stephen Lawton, Contributing Writer
The new guidelines would require public companies to file periodic disclosures about their cybersecurity practices and notify the SEC within 96 hours of a material breach.

  • July 11th 2022 at 14:01

Diversity in Cybersecurity: Fostering Gender-Inclusive Teams That Perform Better

By Anupama Akkapeddi, IT Security Evangelist, ManageEngine
Proactive steps in recruiting women to cybersecurity teams, along with policies focused on diversity, equity, and inclusion, help make cybersecurity teams more effective. Addressing specific barriers that female candidates face will make those teams more inclusive and more representative.

  • July 11th 2022 at 14:00

New Phishing Attacks Shame, Scare Victims into Surrendering Twitter, Discord Credentials

By Nathan Eddy, Contributing Writer, Dark Reading
Scams pressure victims to "resolve an issue that could impact their status, business."

  • July 11th 2022 at 13:10

Microsoft Reverses Course on Blocking Office Macros by Default

By Jai Vijayan, Contributing Writer, Dark Reading
Security experts criticize company for reversing course, albeit temporarily, on a decision it made just this February to block macros in files downloaded from the Internet.

  • July 8th 2022 at 21:19

DoJ Charges CEO for Dealing $1B in Fake Cisco Gear

By Dark Reading Staff, Dark Reading
Fraudster allegedly passed off refurbished, modified Cisco equipment as new to hospitals, schools, and even the military.

  • July 8th 2022 at 18:12

Welcome-Back-to-the-Future Shock

By Jonathan Care, Contributing Writer, Dark Reading
This year's RSA Conference saw a strange mix of selling the future and the past β€” for good reason.

  • July 8th 2022 at 15:44
❌