FreshRSS

πŸ”’
❌ About FreshRSS
There are new available articles, click to refresh the page.
Before yesterdayDark Reading:

Long Con Impersonates Financial Advisers to Target Victims

By Robert Lemos, Contributing Writer, Dark Reading
Cybercriminals are co-opting the identities of legitimate US financial advisers to use them as fodder for relationship scams (aka "pig butchering"), which end with the theft of investments.

  • January 30th 2023 at 16:45

Spotlight on 2023 DevSecOps Trends

By Pavel Livshiz, General Partner, Hetz Ventures
Solutions that provide more actionable results β€” remediation that frees up engineers, processes which integrate security into software development from its design, along with automation, IAC, and tool consolidation β€” are among the DevSecOps strategies that will prevail this year.

  • January 30th 2023 at 15:00

Enterprises Don't Know What to Buy for Responsible AI

By Dark Reading Staff, Dark Reading
Organizations are struggling to procure appropriate technical tools to address responsible AI, such as consistent bias detection in AI applications.

  • January 27th 2023 at 22:30

Enterprises Need to Do More to Assure Consumers About Privacy

By Edge Editors, Dark Reading
Organizations care about data privacy, but their priorities appear to be different from what their customers think are important.

  • January 27th 2023 at 22:00

Why Most Companies Still Don’t Know What’s on Their Network

By Terry Sweeney, Contributing Editor
Chris Kirsch, CEO of runZero, sits down with Dark Reading’sTerry Sweeney for a Fast Chat on the importance of asset discovery.

  • January 27th 2023 at 21:00

On Data Privacy Day, Organizations Fail Data Privacy Expectations

By Maxine Holt, Research Director, Omdia
Data Privacy Day rolls around year after year, and data privacy breaches likewise. Two-thirds of data breaches result in data exposure.

  • January 27th 2023 at 20:00

Critical RCE Lexmark Printer Bug Has Public Exploit

By Dark Reading Staff, Dark Reading
A nasty SSRF bug in Web Services plagues a laundry list of enterprise printers.

  • January 27th 2023 at 18:02

Google: Influence Operator Dragonbridge Floods Social Media in Sprawling Cyber Campaign

By Nathan Eddy, Contributing Writer, Dark Reading
Google has mounted a massive takedown, but Dragonbridge's extensive capabilities for generating and distributing vast amounts of largely spammy content calls into question the motivation behind the group.

  • January 27th 2023 at 16:11

How Noob Website Hackers Can Become Persistent Threats

By Jai Vijayan, Contributing Writer, Dark Reading
An academic analysis of website defacement behavior by 241 new hackers shows there are four clear trajectories they can take in the future, researchers say.

  • January 27th 2023 at 15:49

3 Ways ChatGPT Will Change Infosec in 2023

By Matt Georgy, Chief Technology Officer, Redacted
OpenAI's chatbot has the promise to revolutionize how security practitioners work.

  • January 27th 2023 at 15:00

Riot Games Latest Video-Game Maker to Suffer Breach

By Robert Lemos, Contributing Writer, Dark Reading
Highlighting continued attacks on game developers, attackers stole source code from and issued a ransom demand to the maker of League of Legends.

  • January 26th 2023 at 22:25

A Child's Garden of Cybersecurity

By Karen Spiegelman, Features Editor
Whether you dream of your child becoming a CISO or just want them to improve their security hygiene, consider this roundup of literary geekery.

  • January 26th 2023 at 22:02

Federal Agencies Infested by Cyberattackers via Legit Remote Management Systems

By Nate Nelson, Contributing Writer, Dark Reading
Hackers don't need a key to get past your defenses if they can essentially teleport using RMMs, warns CISA and the NSA.

  • January 26th 2023 at 20:13

SaaS Rootkit Exploits Hidden Rules in Microsoft 365

A vulnerability within Microsoft's OAuth application registration allows an attacker to create hidden forwarding rules that act as a malicious SaaS rootkit.

  • January 26th 2023 at 20:00

Dutchman Detained for Dealing Details of Tens of Millions of People

By Dark Reading Staff, Dark Reading
The accused sold an enormous data set stolen from the Austrian radio and television licensing authority β€” to an undercover cop.

  • January 26th 2023 at 20:00

Hive Ransomware Gang Loses Its Honeycomb, Thanks to DoJ

By Tara Seals, Managing Editor, News, Dark Reading
The US Department of Justice hacked into Hive's infrastructure, made off with hundreds of decryptors, and seized the gang's operations.

  • January 26th 2023 at 19:40

German Government, Airports, Banks Hit With Killnet DDoS Attacks

By Dark Reading Staff, Dark Reading
After Berlin pledged tanks for Ukraine, some German websites were knocked offline temporarily by Killnet DDoS attacks.

  • January 26th 2023 at 19:26

7 Insights From a Ransomware Negotiator

By Ericka Chickowski, Contributing Writer, Dark Reading
The rapid maturation and rebranding of ransomware groups calls for relentless preparation and flexibility in response, according to one view from the trenches.

  • January 26th 2023 at 18:18

Companies Struggle With Zero Trust as Attackers Adapt to Get Around It

By Robert Lemos, Contributing Writer, Dark Reading
Only one in 10 enterprises will create a robust zero-trust foundation in the next three years, while more than half of attacks won't even be prevented by it, according to Gartner.

  • January 26th 2023 at 17:36

Center for Cyber Safety and Education Opens 2023 Cybersecurity Scholarship Applications

Program provides financial assistance to aspiring information security professionals, enabling students toward long-term career success.
  • January 26th 2023 at 16:12

Cybellum Releases Enhanced SBOM Management and Compliance Oversight for Manufacturers with New Release of its Product Security Platform

Advanced workflow, approval process, and management dashboard enhance control, distribution, and supervision, while reducing errors and streamlining the entire SBOM management process.
  • January 26th 2023 at 15:58

NIST Risk Management Framework Aims to Improve Trustworthiness of Artificial Intelligence

New guidance seeks to cultivate trust in AI technologies and promote AI innovation while mitigating risk
  • January 26th 2023 at 15:43

Organizations Must Brace for Privacy Impacts This Year

By J. Trevor Hughes, President & CEO, IAPP
Expect more regulatory and enforcement action in the US and around the world.

  • January 26th 2023 at 15:00

Snyk Gets Nod of Approval With ServiceNow Strategic Investment

By Jeffrey Schwartz, Contributing Writer, Dark Reading
One of the most closely watched security startups continues to build bank because its platform appeals to both developers and security pros.

  • January 26th 2023 at 00:34

KORE Delivers IoT SAFE Solution for Massive IoT Use Cases with AWS

Delivering secure, global IoT device connectivity, deployment, and management at scale.
  • January 25th 2023 at 22:39

Microsoft Azure-Based Kerberos Attacks Crack Open Cloud Accounts

By Robert Lemos, Contributing Writer, Dark Reading
Two common attacks against on-premises Kerberos authentication servers β€” known as Pass the Ticket and Silver Ticket β€” can be used against Microsoft's Azure AD Kerberos, a security firms says.

  • January 25th 2023 at 22:17

Zacks Investment Research Hack Exposes Data for 820K Customers

By Dark Reading Staff, Dark Reading
Zacks Elite sign-ups for the period 1999–2005 were accessed, including name, address, email address, phone number, and the password associated with Zacks.com.

  • January 25th 2023 at 21:43

Google Pushes Privacy to the Limit in Updated Terms of Service

By Stephen Lawton, Contributing Writer
In the Play Store's ToS, a paragraph says Google may remove "harmful" applications from users' devices. Is that a step too far?

  • January 25th 2023 at 21:42

Despite Slowing Economy, Demand for Cybersecurity Workers Remains Strong

New Cyberseekβ„’ data shows US is short nearly 530,000 skilled cybersecurity staff.
  • January 25th 2023 at 21:25

Researchers Pioneer PoC Exploit for NSA-Reported Bug in Windows CryptoAPI

By Jai Vijayan, Contributing Writer, Dark Reading
The security vulnerability allows attackers to spoof a target certificate and masquerade as any website, among other things.

  • January 25th 2023 at 20:30

GoTo Encrypted Backups Stolen in LastPass Breach

By Dark Reading Staff, Dark Reading
Encrypted backups for several GoTo remote work tools were exfiltrated from LastPass, along with encryption keys.

  • January 25th 2023 at 19:35

Log4j Vulnerabilities Are Here to Stay β€” Are You Prepared?

By Zur Ulianitzky, Head of Security Research, XM Cyber
Don't make perfect the enemy of good in vulnerability management. Context is key β€” prioritize vulnerabilities that are actually exploitable. Act quickly if the vulnerability is on a potential attack path to a critical asset.

  • January 25th 2023 at 18:00

North Korea's Top APT Swindled $1B From Crypto Investors in 2022

By Nate Nelson, Contributing Writer, Dark Reading
The DPRK has turned crypto scams into big business to replenish its depleted state coffers.

  • January 25th 2023 at 17:45

Multicloud Security Challenges Will Persist in 2023

By Rich Campagna, Senior Vice President and General Manager, CNAPP, Zscaler
Some predictions about impending security challenges, with a few tips for proactively addressing them.

  • January 25th 2023 at 17:00

Cybersecurity Budgets Increase for Retail & Hospitality Industry

Despite economic headwinds and layoffs in other areas, most retail and hospitality CISOs expect to add staff in 2023, according to a new report.
  • January 25th 2023 at 16:10

Can't Fill Open Positions? Rewrite Your Minimum Requirements

By Robin Hicks, Manager, Assurance and Advisory, Technology, Cox Enterprises
If you or your company can't find good infosec candidates, consider changing up the qualifications to find more nontraditional talent.

  • January 25th 2023 at 15:00

Skyhawk Security Launches Multicloud Runtime Threat Detection and Response Platform

By Dark Reading Staff, Dark Reading
Skyhawk Synthesis extends cloud security misconfiguration detection across multiple clouds, the company says β€” throwing cloud security posture management in for free.

  • January 25th 2023 at 00:34

View from Davos: The Changing Economics of Cybercrime

By Vishaal "V8" Hariprasad, CEO and co-founder, Resilience
Participants in a working session on ransomware at the World Economic Forum discussed how planning ahead can reduce cyber risk.

  • January 24th 2023 at 23:13

Ticketmaster Blames Bots in Taylor Swift 'Eras' Tour Debacle

By Becky Bracken, Editor, Dark Reading
Ticketmaster testified in the Senate that a cyberattack was to blame for the high-profile Taylor Swift concert sales collapse, but some senators aren't so sure.

  • January 24th 2023 at 22:02

Forescout Appoints Technology Veteran Barry Mainz as CEO

Mainz brings 25 years of industry experience to execute on Forescout’s strategy and drive its next phase of growth.
  • January 24th 2023 at 20:05

Fenix24 Releases White Paper Proposing New Cyber Incident Response Paradigm

Restoration teams must be part of a collaborative, initial response team to address costly downtime.
  • January 24th 2023 at 19:56

Armis State of Cyberwarfare and Trends Report: 2022-2023 Highlights Global IT and Security Professionals' Sentiment on Cyberwarfare

Respondents indicate organizations are unprepared to handle cyberwarfare, there's no one-size-fits-all response to ransomware, and cybersecurity spending is on the rise.
  • January 24th 2023 at 18:27

Chat Cybersecurity: AI Promises a Lot, but Can It Deliver?

By Dane Sherrets, Senior Solutions Architect, HackerOne
Machine learning offers great opportunities, but it still can't replace human experts.

  • January 24th 2023 at 18:00

'DragonSpark' Malware: East Asian Cyberattackers Create an OSS Frankenstein

By Nate Nelson, Contributing Writer, Dark Reading
Hackers cleverly cobbled together a suite of open source software β€” including a novel RAT β€” and hijacked servers owned by ordinary businesses.

  • January 24th 2023 at 17:22

Microsoft to Block Excel Add-ins to Stop Office Exploits

By Robert Lemos, Contributing Writer, Dark Reading
The company will block the configuration files, which interact with Web applications β€” since threat actors increasingly use the capability to install malicious code.

  • January 24th 2023 at 15:59

Security and the Electric Vehicle Charging Infrastructure

By Shachar Inbar, VP, Head of Business Operations and Information Security, Driivz
When EVs and smart chargers plug in to critical infrastructure, what can go wrong? Plenty.

  • January 24th 2023 at 15:00

Wallarm Aims to Reduce the Harm From Compromised APIs

By Dark Reading Staff, Dark Reading
API Leak Management software discovers exposed API keys and other secrets, blocks their use, and monitors for abuse, the company says.

  • January 23rd 2023 at 23:29

Pair of Galaxy App Store Bugs Offer Cyberattackers Mobile Device Access

By Dark Reading Staff, Dark Reading
Devices running Android 12 and below are at risk of attackers downloading apps that direct users to a malicious domain.

  • January 23rd 2023 at 22:00
❌