FreshRSS

πŸ”’
❌ About FreshRSS
There are new available articles, click to refresh the page.
Before yesterdayDark Reading:

How Can Disrupting DNS Communications Thwart a Malware Attack?

By Dave Mitchell, CTO, HYAS
Malware eventually has to exfiltrate the data it accessed. By watching DNS traffic for suspicious activity, organizations can halt the damage.

  • February 1st 2023 at 02:05

Firmware Flaws Could Spell 'Lights Out' for Servers

By Robert Lemos, Contributing Writer, Dark Reading
Five vulnerabilities in the baseboard management controller (BMC) software used by 15 major vendors could allow remote code execution if attackers gain network access.

  • January 31st 2023 at 22:35

Critical VMware RCE Vulnerabilities Targeted by Public Exploit Code

By Tara Seals, Managing Editor, News, Dark Reading
Security vulnerabilities in VMware's vRealize Log Insight platform can be chained together to offer a cybercriminals a gaping hole to access corporate crown jewels.

  • January 31st 2023 at 21:30

Phishers Trick Microsoft Into Granting Them 'Verified' Cloud Partner Status

By Nate Nelson, Contributing Writer, Dark Reading
Everyone on Twitter wants a blue check mark. But Microsoft Azure's blue badges are even more valuable to a threat actor stealing your data via malicious OAuth apps.

  • January 31st 2023 at 20:00

Poser Hackers Impersonate LockBit in SMB Cyberattacks

By Dark Reading Staff, Dark Reading
Recent cyberattacks against SMBs across Europe have been traced back to copycat groups using leaked LockBit locker malware.

  • January 31st 2023 at 19:44

Will Cybersecurity Remain Recession-Proof in 2023?

By Jamal Elmellas , Chief Operating Officer, Focus on Security
Demand for skilled professionals will remain high, but cyber budgets will be eaten away.

  • January 31st 2023 at 18:00

NanoLock Addresses Global Industrial & OT Cyber Demand with Expansions into Europe and North America

To meet a pressing demand for industrial and OT security, zero-trust, device-level cybersecurity provider expands with strategic hires in new and established markets.
  • January 31st 2023 at 16:15

New Survey Reveals 40% of Companies Experienced a Data Leak in the Past Year

SysKit report highlighting effects of digital transformation on IT admins and governance landscape released.
  • January 31st 2023 at 16:09

Aura and Nonprofit Cyversity Partner to Support a More Inclusive Cyber Workforce

Mentoring, scholarships, and professional development opportunities will be offered to those underrepresented in the industry through the collaboration.
  • January 31st 2023 at 15:58

Sentra Raises $30 Million Series A Financing to Meet Growing Demand for Data Security in the Cloud

Standard Investments leads round with participation from Munich Re Ventures, Moore Strategic Ventures, Bessemer Venture Partners, and Zeev Ventures.
  • January 31st 2023 at 15:45

Are Your Employees Thinking Critically About Their Online Behaviors?

By Jonathan Watson, Chief Technology Officer, Clio
Three mindset shifts will help employees build a habit of vigilance and make better security decisions. Move past security theater to reframe thinking so employees understand data's value, act with intention, and follow data best practices.

  • January 31st 2023 at 15:00

Russia's Sandworm APT Launches Swarm of Wiper Attacks in Ukraine

By Jai Vijayan, Contributing Writer, Dark Reading
The incidents are the latest indication of the growing popularity of dangerous disk wipers, created to disrupt and degrade critical infrastructure and other organizations.

  • January 30th 2023 at 22:32

Cybercrime Ecosystem Spawns Lucrative Underground Gig Economy

By Robert Lemos, Contributing Writer, Dark Reading
The complex nature of cyberattacks has increased demand for software developers, reverse engineers, and offensive specialists β€” attracting workers facing financial insecurity.

  • January 30th 2023 at 21:52

10M JD Sports Customers' Info Exposed in Data Breach

By Becky Bracken, Editor, Dark Reading
UK sportswear retailer asks exposed customers to stay "vigilant" against phishing attempts following cyberattack.

  • January 30th 2023 at 21:17

IT and Security Professionals Spend an Average of 4,300 Hours Annually Achieving or Maintaining Compliance

New research from Drata shows compliance remains a business challenge for many organizations.
  • January 30th 2023 at 20:33

Make Developers the Driver of Software Security Excellence

By Matias Madou, Co-Founder and CTO, Secure Code Warrior
Those who are wrangling code every day could fuel a genuinely transformational approach to security β€” if they are adequately upskilled.

  • January 30th 2023 at 20:17

Facebook Bug Allows 2FA Bypass Via Instagram

By Dark Reading Staff, Dark Reading
The Instagram rate-limiting bug, found by a rookie hunter, could be exploited to bypass Facebook 2FA in vulnerable apps, researcher reports.

  • January 30th 2023 at 19:00

Fake Texts From the Boss, Bogus Job Postings and Frankenstein Shoppers β€” Oh My!

Experian’s annual Future of Fraud Forecast highlights five fraud threats facing businesses and consumers in 2023.
  • January 30th 2023 at 17:40

Convincing, Malicious Google Ads Look to Lift Password Manager Logins

By Jai Vijayan, Contributing Writer, Dark Reading
Users searching for Bitwarden and 1Password's Web vaults on Google have recently reported seeing paid ads with links to cleverly spoofed sites for stealing credentials to their password vaults.

  • January 30th 2023 at 17:15

Long Con Impersonates Financial Advisers to Target Victims

By Robert Lemos, Contributing Writer, Dark Reading
Cybercriminals are co-opting the identities of legitimate US financial advisers to use them as fodder for relationship scams (aka "pig butchering"), which end with the theft of investments.

  • January 30th 2023 at 16:45

Spotlight on 2023 DevSecOps Trends

By Pavel Livshiz, General Partner, Hetz Ventures
Solutions that provide more actionable results β€” remediation that frees up engineers, processes which integrate security into software development from its design, along with automation, IAC, and tool consolidation β€” are among the DevSecOps strategies that will prevail this year.

  • January 30th 2023 at 15:00

Enterprises Don't Know What to Buy for Responsible AI

By Dark Reading Staff, Dark Reading
Organizations are struggling to procure appropriate technical tools to address responsible AI, such as consistent bias detection in AI applications.

  • January 27th 2023 at 22:30

Enterprises Need to Do More to Assure Consumers About Privacy

By Edge Editors, Dark Reading
Organizations care about data privacy, but their priorities appear to be different from what their customers think are important.

  • January 27th 2023 at 22:00

Why Most Companies Still Don’t Know What’s on Their Network

By Terry Sweeney, Contributing Editor
Chris Kirsch, CEO of runZero, sits down with Dark Reading’sTerry Sweeney for a Fast Chat on the importance of asset discovery.

  • January 27th 2023 at 21:00

On Data Privacy Day, Organizations Fail Data Privacy Expectations

By Maxine Holt, Research Director, Omdia
Data Privacy Day rolls around year after year, and data privacy breaches likewise. Two-thirds of data breaches result in data exposure.

  • January 27th 2023 at 20:00

Critical RCE Lexmark Printer Bug Has Public Exploit

By Dark Reading Staff, Dark Reading
A nasty SSRF bug in Web Services plagues a laundry list of enterprise printers.

  • January 27th 2023 at 18:02

Google: Influence Operator Dragonbridge Floods Social Media in Sprawling Cyber Campaign

By Nathan Eddy, Contributing Writer, Dark Reading
Google has mounted a massive takedown, but Dragonbridge's extensive capabilities for generating and distributing vast amounts of largely spammy content calls into question the motivation behind the group.

  • January 27th 2023 at 16:11

How Noob Website Hackers Can Become Persistent Threats

By Jai Vijayan, Contributing Writer, Dark Reading
An academic analysis of website defacement behavior by 241 new hackers shows there are four clear trajectories they can take in the future, researchers say.

  • January 27th 2023 at 15:49

3 Ways ChatGPT Will Change Infosec in 2023

By Matt Georgy, Chief Technology Officer, Redacted
OpenAI's chatbot has the promise to revolutionize how security practitioners work.

  • January 27th 2023 at 15:00

Riot Games Latest Video-Game Maker to Suffer Breach

By Robert Lemos, Contributing Writer, Dark Reading
Highlighting continued attacks on game developers, attackers stole source code from and issued a ransom demand to the maker of League of Legends.

  • January 26th 2023 at 22:25

A Child's Garden of Cybersecurity

By Karen Spiegelman, Features Editor
Whether you dream of your child becoming a CISO or just want them to improve their security hygiene, consider this roundup of literary geekery.

  • January 26th 2023 at 22:02

Federal Agencies Infested by Cyberattackers via Legit Remote Management Systems

By Nate Nelson, Contributing Writer, Dark Reading
Hackers don't need a key to get past your defenses if they can essentially teleport using RMMs, warns CISA and the NSA.

  • January 26th 2023 at 20:13

SaaS Rootkit Exploits Hidden Rules in Microsoft 365

A vulnerability within Microsoft's OAuth application registration allows an attacker to create hidden forwarding rules that act as a malicious SaaS rootkit.

  • January 26th 2023 at 20:00

Dutchman Detained for Dealing Details of Tens of Millions of People

By Dark Reading Staff, Dark Reading
The accused sold an enormous data set stolen from the Austrian radio and television licensing authority β€” to an undercover cop.

  • January 26th 2023 at 20:00

Hive Ransomware Gang Loses Its Honeycomb, Thanks to DoJ

By Tara Seals, Managing Editor, News, Dark Reading
The US Department of Justice hacked into Hive's infrastructure, made off with hundreds of decryptors, and seized the gang's operations.

  • January 26th 2023 at 19:40

German Government, Airports, Banks Hit With Killnet DDoS Attacks

By Dark Reading Staff, Dark Reading
After Berlin pledged tanks for Ukraine, some German websites were knocked offline temporarily by Killnet DDoS attacks.

  • January 26th 2023 at 19:26

7 Insights From a Ransomware Negotiator

By Ericka Chickowski, Contributing Writer, Dark Reading
The rapid maturation and rebranding of ransomware groups calls for relentless preparation and flexibility in response, according to one view from the trenches.

  • January 26th 2023 at 18:18

Companies Struggle With Zero Trust as Attackers Adapt to Get Around It

By Robert Lemos, Contributing Writer, Dark Reading
Only one in 10 enterprises will create a robust zero-trust foundation in the next three years, while more than half of attacks won't even be prevented by it, according to Gartner.

  • January 26th 2023 at 17:36

Center for Cyber Safety and Education Opens 2023 Cybersecurity Scholarship Applications

Program provides financial assistance to aspiring information security professionals, enabling students toward long-term career success.
  • January 26th 2023 at 16:12

Cybellum Releases Enhanced SBOM Management and Compliance Oversight for Manufacturers with New Release of its Product Security Platform

Advanced workflow, approval process, and management dashboard enhance control, distribution, and supervision, while reducing errors and streamlining the entire SBOM management process.
  • January 26th 2023 at 15:58

NIST Risk Management Framework Aims to Improve Trustworthiness of Artificial Intelligence

New guidance seeks to cultivate trust in AI technologies and promote AI innovation while mitigating risk
  • January 26th 2023 at 15:43

Organizations Must Brace for Privacy Impacts This Year

By J. Trevor Hughes, President & CEO, IAPP
Expect more regulatory and enforcement action in the US and around the world.

  • January 26th 2023 at 15:00

Snyk Gets Nod of Approval With ServiceNow Strategic Investment

By Jeffrey Schwartz, Contributing Writer, Dark Reading
One of the most closely watched security startups continues to build bank because its platform appeals to both developers and security pros.

  • January 26th 2023 at 00:34

KORE Delivers IoT SAFE Solution for Massive IoT Use Cases with AWS

Delivering secure, global IoT device connectivity, deployment, and management at scale.
  • January 25th 2023 at 22:39

Microsoft Azure-Based Kerberos Attacks Crack Open Cloud Accounts

By Robert Lemos, Contributing Writer, Dark Reading
Two common attacks against on-premises Kerberos authentication servers β€” known as Pass the Ticket and Silver Ticket β€” can be used against Microsoft's Azure AD Kerberos, a security firms says.

  • January 25th 2023 at 22:17

Zacks Investment Research Hack Exposes Data for 820K Customers

By Dark Reading Staff, Dark Reading
Zacks Elite sign-ups for the period 1999–2005 were accessed, including name, address, email address, phone number, and the password associated with Zacks.com.

  • January 25th 2023 at 21:43

Google Pushes Privacy to the Limit in Updated Terms of Service

By Stephen Lawton, Contributing Writer
In the Play Store's ToS, a paragraph says Google may remove "harmful" applications from users' devices. Is that a step too far?

  • January 25th 2023 at 21:42

Despite Slowing Economy, Demand for Cybersecurity Workers Remains Strong

New Cyberseekβ„’ data shows US is short nearly 530,000 skilled cybersecurity staff.
  • January 25th 2023 at 21:25

Researchers Pioneer PoC Exploit for NSA-Reported Bug in Windows CryptoAPI

By Jai Vijayan, Contributing Writer, Dark Reading
The security vulnerability allows attackers to spoof a target certificate and masquerade as any website, among other things.

  • January 25th 2023 at 20:30

GoTo Encrypted Backups Stolen in LastPass Breach

By Dark Reading Staff, Dark Reading
Encrypted backups for several GoTo remote work tools were exfiltrated from LastPass, along with encryption keys.

  • January 25th 2023 at 19:35

Log4j Vulnerabilities Are Here to Stay β€” Are You Prepared?

By Zur Ulianitzky, Head of Security Research, XM Cyber
Don't make perfect the enemy of good in vulnerability management. Context is key β€” prioritize vulnerabilities that are actually exploitable. Act quickly if the vulnerability is on a potential attack path to a critical asset.

  • January 25th 2023 at 18:00

North Korea's Top APT Swindled $1B From Crypto Investors in 2022

By Nate Nelson, Contributing Writer, Dark Reading
The DPRK has turned crypto scams into big business to replenish its depleted state coffers.

  • January 25th 2023 at 17:45
❌