FreshRSS

πŸ”’
☐ β˜† βœ‡ Dark Reading:

Unpatched DNS-Poisoning Bug Affects Millions of Devices, Stumps Researchers

By Dark Reading Staff, Dark Reading β€” May 3rd 2022 at 20:10
The security vulnerability puts wide swaths of industrial networks and IoT devices at risk of compromise, researchers warn.

☐ β˜† βœ‡ Dark Reading:

REvil Revival: Are Ransomware Gangs Ever Really Gone?

By Robert Lemos, Contributing Writer β€” May 3rd 2022 at 19:46
The infamous ransomware group appears to be back from the dead β€” maybe β€” and using the old brand, but experts question whether a reconstituted gang will have much success.

☐ β˜† βœ‡ Dark Reading:

Syxsense Launches Unified Endpoint Security and Management Platform

May 3rd 2022 at 17:50
Syxsense Enterprise delivers real-time vulnerability monitoring and remediation for all endpoints across an organization’s entire network.
☐ β˜† βœ‡ Dark Reading:

Third-Party App Access Is the New Executable File

By Maor Bin, Co-Founder and CEO, Adaptive Shield β€” May 3rd 2022 at 17:00
By providing these apps and other add-ons for SaaS platforms and associated permissions, businesses present bad actors with more opportunities to gain access to company data.

☐ β˜† βœ‡ Dark Reading:

How to Create a Cybersecurity Mentorship Program

By Steve Zurier, Contributing Writer β€” May 3rd 2022 at 16:00
As the talent shortage rages on, companies have found mentorship programs to be one of the best ways to obtain the security skills they need to develop their existing teams.

☐ β˜† βœ‡ Dark Reading:

Radware Launches SkyHawk Security, a Spinoff of Its Cloud Native Protector Business

May 3rd 2022 at 14:25
Tiger Global Management invests $35 million in SkyHawk Security to accelerate growth.
☐ β˜† βœ‡ Dark Reading:

Teleport Raises $110 Million Series C at $1.1 Billion Valuation Led by Bessemer Venture Partners

May 3rd 2022 at 14:15
Funding follows dramatic revenue growth as identity-based access requirements skyrocket.
☐ β˜† βœ‡ Dark Reading:

OccamSec Unveils New Cybersecurity Platform

May 3rd 2022 at 14:10
Providing continuous penetration testing with context, and a host of other features, the Incenter platform is built to give organizations what they need to effectively secure their environment.
☐ β˜† βœ‡ Dark Reading:

Developing Software? Get Accountability Right First

By Guillermo Perez, CEO and Co-Founder, Octobot β€” May 3rd 2022 at 14:00
Software accountability offers a fresh perspective for creating and managing digital products, mainly by making processes more reliable and transparent for every stakeholder.

☐ β˜† βœ‡ Dark Reading:

TLS Flaws Leave Avaya, Aruba Switches Open to Complete Takeover

By Robert Lemos, Contributing Writer β€” May 3rd 2022 at 10:00
In the latest incarnation of the TLStorm vulnerability, switches from Avaya and Aruba β€” and perhaps others β€” are susceptible to compromise from an internal attacker.

☐ β˜† βœ‡ Dark Reading:

DoD Scammed Out of $23M in Phishing Attack on Jet-Fuel Vendors

By Dark Reading Staff, Dark Reading β€” May 2nd 2022 at 17:11
A California man faces prison time and steep fines stemming from cybertheft of US military funds intended to pay jet-fuel suppliers.

☐ β˜† βœ‡ Dark Reading:

Google Offers $1.5M Bug Bounty for Android 13 Beta

By Tara Seals, Managing Editor, News β€” May 2nd 2022 at 20:43
The security vulnerability payout set bug hunters rejoicing, but claiming the reward is much, much easier said than done.

☐ β˜† βœ‡ Dark Reading:

New Regulations in India Require Orgs to Report Cyber Incidents Within 6 Hours

By Dark Reading Staff, Dark Reading β€” May 2nd 2022 at 17:46
CERT-In updates cybersecurity rules to include mandatory reporting, record-keeping, and more.

☐ β˜† βœ‡ Dark Reading:

6 Best Practices to Ensure Kubernetes Security Meets Compliance Regulations

By Glen Kosaka, Head of Product Security, SUSE β€” May 2nd 2022 at 16:48
Security must be precise enough to meet compliance requirements without impeding DevOps and developer productivity. Here's how to strike that balance.

☐ β˜† βœ‡ Dark Reading:

Name That Edge Toon: Flower Power

By John Klossner, Cartoonist β€” May 2nd 2022 at 16:19
Come up with a clever caption, and our panel of experts will reward the winner with a $25 Amazon gift card.

☐ β˜† βœ‡ Dark Reading:

Security Stuff Happens: What Do You Do When It Hits the Fan?

By Tyler Farrar, CISO, Exabeam β€” May 2nd 2022 at 14:00
Breaches can happen to anyone, but a well-oiled machine can internally manage and externally remediate in a way that won't lead to extensive damage to a company's bottom line. (Part 1 of a series.)

☐ β˜† βœ‡ Dark Reading:

2022 Security Priorities: Staffing and Remote Work

By Edge Editors, Dark Reading β€” April 30th 2022 at 02:00
A comprehensive security strategy balances technology, processes, and people β€” and hiring and retaining security personnel and securing the remote workforce are firmly people priorities.

☐ β˜† βœ‡ Dark Reading:

Good News! IAM Is Near-Universal With SaaS

By Dark Reading Staff, Dark Reading β€” April 29th 2022 at 22:49
The less-good news: IAM only works for applications your IT department knows about, so watch for "shadow IT" programs installed or written by users that leave a security gap.

☐ β˜† βœ‡ Dark Reading:

Critical Vulnerabilities Leave Some Network-Attached Storage Devices Open to Attack

By Jai Vijayan, Contributing Writer β€” April 29th 2022 at 21:48
QNAP and Synology say flaws in the Netatalk fileserver allow remote code execution and information disclosure.

☐ β˜† βœ‡ Dark Reading:

Cloudflare Flags Largest HTTPS DDoS Attack It's Ever Recorded

By Dark Reading Staff, Dark Reading β€” April 29th 2022 at 19:36
This scale of this month's encrypted DDoS attack over HTTPS suggests a well-resourced operation, analysts say.

☐ β˜† βœ‡ Dark Reading:

Take a Diversified Approach to Encryption

By Dr. Vincent Berk, Chief Strategy Officer, Quantum Xchange β€” April 29th 2022 at 14:00
Encryption will break, so it's important to mix and layer different encryption methods.

☐ β˜† βœ‡ Dark Reading:

Ambient.ai Expands Computer Vision Capabilities for Better Building Security

By Fahmida Y. Rashid, Managing Editor, Features, Dark Reading β€” April 29th 2022 at 00:47
The AI startup releases new threat signatures to expand the computer vision platform’s ability to identify potential physical security incidents from camera feeds.

☐ β˜† βœ‡ Dark Reading:

Microsoft Patches Pair of Dangerous Vulnerabilities in Azure PostgreSQL

By Jai Vijayan, Contributing Writer β€” April 28th 2022 at 22:23
Flaws gave attackers a way to access other cloud accounts and databases, security vendor says.

☐ β˜† βœ‡ Dark Reading:

IT Teams Worry Staff Lack Cloud-Specific Skills

By Edge Editors, Dark Reading β€” April 28th 2022 at 21:42
Security, cost, and reliability top the list of concerns IT teams have about their cloud operations, according to a recent report.

☐ β˜† βœ‡ Dark Reading:

The Ransomware Crisis Deepens, While Data Recovery Stalls

By Robert Lemos, Contributing Writer β€” April 28th 2022 at 19:55
Higher probabilities of attack, soaring ransoms, and less chance of getting data back β€” the ransomware plague gets worse, and cyber insurance fails to be a panacea.

☐ β˜† βœ‡ Dark Reading:

Capital One Ventures, Snowflake Ventures, Verizon Ventures, and Wipro Ventures Join Securonix $1B+ Growth Investment as Strategic Investors

April 28th 2022 at 19:55
Blue-chip companies deepen commitment based on success of long-standing customer and partner relationships and conviction of Securonix’s vision and hypergrowth potential.
☐ β˜† βœ‡ Dark Reading:

Bumblebee Malware Buzzes Into Cyberattack Fray

By Tara Seals, Managing Editor, News β€” April 28th 2022 at 19:41
The sophisticated Bumblebee downloader is being used in ongoing email-borne attacks that could lead to ransomware infections.

☐ β˜† βœ‡ Dark Reading:

Microsoft: Russia Using Cyberattacks in Coordination With Military Invasion of Ukraine

By Dark Reading Staff, Dark Reading β€” April 28th 2022 at 18:45
Six Russian state-backed threat actors have lunched 237 cyberattacks on Ukraine's infrastructure, new research from MIcrosoft shows.

☐ β˜† βœ‡ Dark Reading:

Explainable AI for Fraud Prevention

By David Utassy, Data Scientist, SEON β€” April 28th 2022 at 14:00
As the use of AI- and ML-driven decision-making draws transparency concerns, the need increases for explainability, especially when machine learning models appear in high-risk environments.

☐ β˜† βœ‡ Dark Reading:

A Peek into Visa's AI Tools Against Fraud

By Fahmida Y. Rashid, Managing Editor, Features, Dark Reading β€” April 28th 2022 at 00:06
Visa has invested heavily in data analytics and artificial intelligence over the past five years to secure the movement of money and keep fraud rates low.

☐ β˜† βœ‡ Dark Reading:

Doppler Takes on Secrets Management

By Fahmida Y. Rashid, Managing Editor, Features, Dark Reading β€” April 27th 2022 at 22:48
The startup is the latest company to try to solve the problem of organizing and sharing secrets.

☐ β˜† βœ‡ Dark Reading:

Chinese APT Bronze President Mounts Spy Campaign on Russian Military

By Jai Vijayan, Contributing Writer β€” April 27th 2022 at 22:19
The war in Ukraine appears to have triggered a change in mission for the APT known as Bronze President (aka Mustang Panda).

☐ β˜† βœ‡ Dark Reading:

Synopsys to Acquire WhiteHat Security from NTT

April 27th 2022 at 20:54
Acquisition expands security software-as-a-service capabilities.
☐ β˜† βœ‡ Dark Reading:

CISA: Log4Shell Was the Most-Exploited Vulnerability in 2021

By Dark Reading Staff, Dark Reading β€” April 27th 2022 at 20:02
Internet-facing zero-day vulnerabilities were the most commonly used types of bugs in 2021 attacks, according to the international Joint Cybersecurity Advisory (JCSA).

☐ β˜† βœ‡ Dark Reading:

Tenable's Bit Discovery Buy Underscores Demand for Deeper Visibility of IT Assets

By Robert Lemos, Contributing Writer β€” April 27th 2022 at 19:36
The four-year-old firm, started by two industry veterans, focuses on gaining visibility into Internet-facing services as more companies seek insight into what attackers see.

☐ β˜† βœ‡ Dark Reading:

Coca-Cola Investigates Data-Theft Claims After Ransomware Attack

By Becky Bracken, Editor, Dark Reading β€” April 27th 2022 at 18:14
The Stormous ransomware group is offering purportedly stolen Coca-Cola data for sale on its leak site, but the soda giant hasn't confirmed that the heist happened.

☐ β˜† βœ‡ Dark Reading:

5-Year Vulnerability Trends Are Both Surprising and Sadly Predictable

April 27th 2022 at 14:00
What 5,800+ pentests show us: Companies have been struggling with the same known and preventable security bugs year over year. Bandwidth stands at the heart of the problem.
☐ β˜† βœ‡ Dark Reading:

How Industry Leaders Should Approach Open Source Security

By Stephen Nolan, Head of Product, Anaconda β€” April 27th 2022 at 14:00
Here's how to reduce security risk and gain the benefits of open source software.

☐ β˜† βœ‡ Dark Reading:

Log4j Attack Surface Remains Massive

By Jai Vijayan, Contributing Writer β€” April 26th 2022 at 23:52
Four months after the Log4Shell vulnerability was disclosed, most affected open source components remain unpatched, and companies continue to use vulnerable versions of the logging tool.

☐ β˜† βœ‡ Dark Reading:

How Do I Report My Security Program's ROI?

By John Ayers, Vice President of Product, Advanced Detection & Response, Optiv β€” April 26th 2022 at 22:57
If security leaders focus on visibility and metrics, they can demonstrate their programs' value to company leadership and boards.

☐ β˜† βœ‡ Dark Reading:

Tenable Acquires External Attack Surface Management Vendor for $44.5M

By Dark Reading Staff, Dark Reading β€” April 26th 2022 at 22:11
Acquisition will add Internet-facing attack surface mapping and monitoring to Tenable's internal asset management products.

☐ β˜† βœ‡ Dark Reading:

The Ins and Outs of Secure Infrastructure as Code

By Rory McCune, Cloud Native Security Advocate, Aqua Security β€” April 26th 2022 at 20:00
The move to IaC has its challenges but done right can fundamentally improve an organization's overall security posture.

☐ β˜† βœ‡ Dark Reading:

CISA Taps Veteran CISO Bob Lord for Technical Adviser Role

By Dark Reading Staff, Dark Reading β€” April 26th 2022 at 17:50
Lord previously spearheaded security for the Democratic National Committee and held leadership roles at companies including Yahoo, Rapid7, and Twitter.

☐ β˜† βœ‡ Dark Reading:

The XDR Revolution: Threat Detection and Response for All!

By Eric Parizo, Principal Analyst, Omdia β€” April 13th 2022 at 20:51
In this webinar replay, Omdia outlines the ways in which XDR facilitates faster and easier threat detection and response, and key points organizations should consider when evaluating XDR technology.

☐ β˜† βœ‡ Dark Reading:

API Attacks Soar Amid the Growing Application Surface Area

By Robert Lemos, Contributing Writer β€” April 26th 2022 at 17:01
With Web application programming interface (API) traffic growing quickly, the average cloud-focused company sees three times more attacks.

☐ β˜† βœ‡ Dark Reading:

Cyber Conflict Overshadowed a Major Government Ransomware Alert

By Hitesh Sheth, CEO, Vectra β€” April 26th 2022 at 14:00
The FBI warns that ransomware targets are no longer predictably the biggest, richest organizations, and that attackers have leveled up to victimize organizations of all sizes.

☐ β˜† βœ‡ Dark Reading:

Introducing Apostro: A Risk Management Platform for Web3 Security

April 26th 2022 at 13:19
Apostro's system will monitor all transactions to identify malicious behavior that can cause damage to DeFi protocols.
☐ β˜† βœ‡ Dark Reading:

SecurityScorecard Launches Cyber Risk Quantification Portfolio

April 26th 2022 at 13:14
SecurityScorecard's Cyber Risk Quantification portfolio helps customers understand the financial impact of a cyber-attack.
☐ β˜† βœ‡ Dark Reading:

What the ECDSA Flaw in Java Means for Enterprises

By Dark Reading Staff, Dark Reading β€” April 25th 2022 at 23:59
This Tech Tip reminds developers and security teams to check what version of Java they are running. Whether they are vulnerable to the ECDSA flaw boils down to the version number.

☐ β˜† βœ‡ Dark Reading:

Iranian Hacking Group Among Those Exploiting Recently Disclosed VMware RCE Flaw

By Jai Vijayan, Contributing Writer β€” April 25th 2022 at 23:36
Threat actor is using the flaw to deliver Core Impact backdoor on vulnerable systems, security vendor says.

☐ β˜† βœ‡ Dark Reading:

North Korean State Actors Deploying Novel Malware to Spy on Journalists

By Dark Reading Staff, Dark Reading β€” April 25th 2022 at 23:10
Spear-phishing campaign loaded with new "Goldbackdoor" malware targeted journalists with NK News, analysts found.

☐ β˜† βœ‡ Dark Reading:

When Security Meets Development: The DevSecOps Conundrum

By Srinivas Mukkamala, Senior Vice President, Security Products, Ivanti β€” April 25th 2022 at 22:09
The DevSecOps journey is well worth undertaking because it can improve communication, speed up development, and ensure quality products.

☐ β˜† βœ‡ Dark Reading:

Mastercard Launches Next-Generation Identity Technology with Microsoft

April 25th 2022 at 19:20
New 'trust' tool improves online experience and helps tackle digital fraud.
☐ β˜† βœ‡ Dark Reading:

Ukraine Invasion Driving DDoS Attacks to All-Time Highs

By Dark Reading Staff, Dark Reading β€” April 25th 2022 at 18:07
Unprecedented numbers of DDoS attacks since February are the result of hacktivists' cyberwar against Russian state interests, researchers say.

☐ β˜† βœ‡ Dark Reading:

Trend Micro Launches New Security Platform

April 25th 2022 at 15:30
An ecosystem of native and third-party integrations provides visibility and control across the entire attack surface.
☐ β˜† βœ‡ Dark Reading:

Overlapping ICS/OT Mandates Distract From Threat Detection and Response

By Mark Carrigan, Senior Vice President, Process Safety and OT Cybersecurity, Hexagon PPM β€” April 25th 2022 at 14:00
It's time for regulators of critical infrastructure β€” including industrial control systems and operational technology β€” to focus more on operational resiliency.

☐ β˜† βœ‡ Dark Reading:

Many Medical Device Makers Skimp on Security Practices

By Dark Reading Staff, Dark Reading β€” April 22nd 2022 at 22:34
Barely over a quarter of medical device companies surveyed maintain a software bill-of-materials, and less than half set security requirements at the design stage.

☐ β˜† βœ‡ Dark Reading:

Sophos Buys Alert-Monitoring Automation Vendor

By Dark Reading Staff, Dark Reading β€” April 22nd 2022 at 20:16
Acquisition of cloud-based alert security company will help Sophos automate tasks bogging down security teams, the company says.

☐ β˜† βœ‡ Dark Reading:

Neustar Security Services’ UltraDNS Integrates Terraform for Streamlined, Automated DNS Management

April 22nd 2022 at 20:00
UltraDNS Terraform Provider enhances productivity, change management.
☐ β˜† βœ‡ Dark Reading:

FBI Warns Ransomware Attacks on Agriculture Co-ops Could Upend Food Supply Chain

By Dark Reading Staff, Dark Reading β€” April 22nd 2022 at 19:32
Ransomware groups are looking to strike large agriculture cooperatives during strategic seasons, when they are most vulnerable, according to law enforcement.

❌