FreshRSS

πŸ”’
☐ β˜† βœ‡ Dark Reading:

VMware, Airline Targeted as Ransomware Chaos Reigns

By Nathan Eddy, Contributing Writer, Dark Reading β€” May 26th 2022 at 16:58
Global ransomware incidents target everything from enterprise servers to grounding an airline, with one India-based group even taking a Robin Hood approach to extortion with the "GoodWill" strain.

☐ β˜† βœ‡ Dark Reading:

Big Cyber Hits on GM, Chicago Public Schools, & Zola Showcase the Password Problem

By Tara Seals, Managing Editor, News, Dark Reading β€” May 26th 2022 at 14:20
Credential-stuffing attacks against online accounts are still popular, and they work thanks to continuing password reuse.

☐ β˜† βœ‡ Dark Reading:

Act Now: Leveraging PCI Compliance to Improve Security

By Tim Erlin, VP of Strategy, Tripwire β€” May 26th 2022 at 14:00
Let the threat landscape guide your company's timeline for complying with new data security standards for credit cards. Use the phase-in time to improve security overall β€” security as a process β€” not just comply with new standards.

☐ β˜† βœ‡ Dark Reading:

Quanta Servers Caught With 'Pantsdown' BMC Vulnerability

By Ericka Chickowski, Contributing Writer, Dark Reading β€” May 26th 2022 at 13:00
Researchers discover 3-year-old critical firmware vulnerability, running in popular cloud servers used to power hyperscalers and cloud providers alike.

☐ β˜† βœ‡ Dark Reading:

Most Common Threats in DBIR

By Edge Editors, Dark Reading β€” May 25th 2022 at 22:11
Supply chain and ransomware attacks increased dramatically in 2021, which explains why so many data breaches in Verizon's "2022 Data Breach Investigations Report" were grouped as system intrusion.

☐ β˜† βœ‡ Dark Reading:

Forescout Launches Forescout Frontline to Help Organizations Tackle Ransomware and Real Time Threats

May 25th 2022 at 20:30
New threat hunting and risk identification service provides organizations with an enterprise-wide baseline of their threat landscape and risk exposure.
☐ β˜† βœ‡ Dark Reading:

Is Your Data Security Living on the Edge?

May 25th 2022 at 20:14
Gartner's security service edge fundamentally changes how companies should be delivering data protection in a cloud and mobile first world.
☐ β˜† βœ‡ Dark Reading:

Interpol's Massive 'Operation Delilah' Nabs BEC Bigwig

By Jai Vijayan, Contributing Writer, Dark Reading β€” May 25th 2022 at 20:09
A sprawling, multiyear operation nabs a suspected SilverTerrier BEC group ringleader, exposing a massive attack infrastructure and sapping the group of a bit of its strength.

☐ β˜† βœ‡ Dark Reading:

JFrog Launches Project Pyrsia to Help Prevent Software Supply Chain Attacks

May 25th 2022 at 19:47
Open source software community initiative utilizes blockchain technology.
☐ β˜† βœ‡ Dark Reading:

Mastercard Launches Cybersecurity β€œExperience Centre”

May 25th 2022 at 19:44
Experience Centre features emerging Mastercard products and solutions for securing digital payments on a global scale, including those developed locally in Vancouver.
☐ β˜† βœ‡ Dark Reading:

Qualys to Unveil VMDR 2.0 at Qualys Security Conference in San Francisco

May 25th 2022 at 19:39
Company will detail enhancements to Vulnerability Management, Detection and Response solution next month.
☐ β˜† βœ‡ Dark Reading:

Corelight Announces New SaaS Platform for Threat Hunting

May 25th 2022 at 19:34
Corelight Investigator aids threat hunting and investigation through intelligent alert aggregation, built-in queries and scalable search
☐ β˜† βœ‡ Dark Reading:

Cybersecurity-Focused SYN Ventures Closes $300 Million Fund II

May 25th 2022 at 19:28
Cylance co-founder Ryan Permeh has joined full time as an operating partner.
☐ β˜† βœ‡ Dark Reading:

Vishing Attacks Reach All Time High, According to Latest Agari and PhishLabs Report

May 25th 2022 at 19:25
According to the findings, vishing attacks have overtaken business email compromise as the second most reported response-based email threat since Q3 2021.
☐ β˜† βœ‡ Dark Reading:

Zero-Click Zoom Bug Allows Code Execution Just by Sending a Message

By Tara Seals, Managing Editor, News, Dark Reading β€” May 25th 2022 at 19:21
Google has disclosed a nasty set of six bugs affecting Zoom chat that can be chained together for MitM and RCE attacks, no user interaction required.

☐ β˜† βœ‡ Dark Reading:

Meet the 10 Finalists in the RSA Conference Innovation Sandbox

By Karen Spiegelman, Features Editor β€” May 25th 2022 at 19:17
This year's finalists tackle such vital security concerns as permissions management, software supply chain vulnerability, and data governance. Winners will be announced June 6.

☐ β˜† βœ‡ Dark Reading:

Brexit Leak Site Linked to Russian Hackers

By Dark Reading Staff, Dark Reading β€” May 25th 2022 at 19:07
Purporting to publish leaked emails of pro-Brexit leadership in the UK, a new site's operations have been traced to Russian cyber-threat actors, Google says.

☐ β˜† βœ‡ Dark Reading:

Spring Cleaning Checklist for Keeping Your Devices Safe at Work

By Alex Lisle, Chief Technology Officer, Kryptowire β€” May 25th 2022 at 17:00
Implement zero-trust policies for greater control, use BYOD management tools, and take proactive steps such as keeping apps current and training staff to keep sensitive company data safe and employees' devices secure.

☐ β˜† βœ‡ Dark Reading:

CLOP Ransomware Activity Spiked in April

By Dark Reading Staff, Dark Reading β€” May 25th 2022 at 16:52
In just one month, the ransomware group's activity rose by 2,100%, a new report finds.

☐ β˜† βœ‡ Dark Reading:

Industry 4.0 Points Up Need for Improved Security for Manufacturers

By Jordan Kendall, President, Security Compass Advisory β€” May 25th 2022 at 14:00
With manufacturing ranking as the fourth most targeted sector, manufacturers that understand their exposure will be able to build the necessary security maturity.

☐ β˜† βœ‡ Dark Reading:

DDoS Extortion Attack Flagged as Possible REvil Resurgence

By Nathan Eddy, Contributing Writer, Dark Reading β€” May 25th 2022 at 13:41
A DDoS campaign observed by Akamai from actors claiming to be REvil would represent a major pivot in tactics for the gang.

☐ β˜† βœ‡ Dark Reading:

DBIR Makes a Case for Passwordless

By Dark Reading Staff, Dark Reading β€” May 24th 2022 at 23:21
Verizon's "2022 Data Breach Investigations Report" repeatedly makes the point that criminals are stealing credentials to carry out their attacks.

☐ β˜† βœ‡ Dark Reading:

'There's No Ceiling': Ransomware's Alarming Growth Signals a New Era, Verizon DBIR Finds

By Tara Seals, Managing Editor, News, Dark Reading β€” May 24th 2022 at 22:44
Ransomware has become so efficient, and the underground economy so professional, that traditional monetization of stolen data may be on its way out.

☐ β˜† βœ‡ Dark Reading:

Microsoft Elevation-of-Privilege Vulnerabilities Spiked Again in 2021

By Jai Vijayan, Contributing Writer, Dark Reading β€” May 24th 2022 at 21:43
But there was a substantial drop in the overall number of critical vulnerabilities that the company disclosed last year, new analysis shows.

☐ β˜† βœ‡ Dark Reading:

New Attack Shows Weaponized PDF Files Remain a Threat

By Dark Reading Staff, Dark Reading β€” May 24th 2022 at 21:13
Notable new infection chain uses PDF to embed malicious files, load remote exploits, shellcode encryption, and more, new research shows.

☐ β˜† βœ‡ Dark Reading:

DeFi Is Getting Pummeled by Cybercriminals

By Becky Bracken, Editor, Dark Reading β€” May 24th 2022 at 20:15
Decentralized finance lost $1.8 billion to cyberattacks last year β€” and 80% of those events were the result of vulnerable code, analysts say.

☐ β˜† βœ‡ Dark Reading:

New Connecticut Privacy Law Makes Path to Compliance More Complex

By Stephen Lawton, Contributing Writer β€” May 24th 2022 at 19:33
As states address privacy with ad-hoc laws, corporate compliance teams try to balance yet another set of similar but diverging requirements.

☐ β˜† βœ‡ Dark Reading:

XM Cyber Adds New Security Capability for Microsoft Active Directory

May 24th 2022 at 17:56
Company to debut its AD capabilities at the 2022 RSA Conference.
☐ β˜† βœ‡ Dark Reading:

Strong Password Policy Isn't Enough, Study Shows

By Dark Reading Staff, Dark Reading β€” May 24th 2022 at 17:40
New analysis reveals basic regulatory password requirements fall far short of providing protection from compromise.

☐ β˜† βœ‡ Dark Reading:

Netskope Expands Data Protection Capabilities to Endpoint Devices and Private Apps

May 24th 2022 at 16:01
New features include context-aware, zero-trust data protection on local peripherals and devices.
☐ β˜† βœ‡ Dark Reading:

Nisos Announces $15 Million in Series B Funding Round

May 24th 2022 at 15:56
New funding led by global cyber investor Paladin Capital Group, alongside existing investors Columbia Capital and Skylab Capital.
☐ β˜† βœ‡ Dark Reading:

Crypto Hacks Aren't a Niche Concern; They Impact Wider Society

By Steve Forbes, Government Cyber Security Expert, Nominet β€” May 24th 2022 at 14:00
Million-dollar crypto heists are becoming more common as the currency starts to go mainstream; prevention and enforcement haven't kept pace.

☐ β˜† βœ‡ Dark Reading:

Multiple Governments Buying Android Zero-Days for Spying: Google

By Dark Reading Staff, Dark Reading β€” May 23rd 2022 at 21:22
An analysis from Google TAG shows that Android zero-day exploits were packaged and sold for state-backed surveillance.

☐ β˜† βœ‡ Dark Reading:

QuSecure Carves Out Space in Quantum Cryptography With Its Vision of a Post-RSA World

By Jeffrey Schwartz, Contributing Writer β€” May 23rd 2022 at 21:13
NIST may be on the brink of revealing which post-quantum computing encryption algorithms it is endorsing, solidifying commercial developments like QuProtect.

☐ β˜† βœ‡ Dark Reading:

Malicious Python Repository Package Drops Cobalt Strike on Windows, macOS & Linux Systems

By Jai Vijayan, Contributing Writer, Dark Reading β€” May 23rd 2022 at 21:03
The PyPI "pymafka" package is the latest example of growing attacker interest in abusing widely used open source software repositories.

☐ β˜† βœ‡ Dark Reading:

Linux Trojan XorDdos Attacks Surge, Targeting Cloud, IoT

By Dark Reading Staff, Dark Reading β€” May 23rd 2022 at 18:18
Analysts have seen a massive spike in malicious activity by the XorDdos Trojan in the last six months, against Linux cloud and IoT infrastructures .

☐ β˜† βœ‡ Dark Reading:

Why the Employee Experience Is Cyber Resilience

By Daniel Riedel, SVP, Strategic Services, Copado β€” May 23rd 2022 at 17:38
A culture of trust, combined with tools designed around employee experience, can work in tandem to help organizations become more resilient and secure.

☐ β˜† βœ‡ Dark Reading:

Valeo Networks Acquires Next I.T.

May 23rd 2022 at 14:31
Next I.T. is the sixth and largest acquisition to date for Valeo Networks.
☐ β˜† βœ‡ Dark Reading:

Kingston Digital Releases Touch-Screen Hardware-Encrypted External SSD for Data Protection

May 23rd 2022 at 14:28
IronKey Vault Privacy 80 External SSD safeguards against brute-force attacks and BadUSB with digitally-signed firmware.
☐ β˜† βœ‡ Dark Reading:

After the Okta Breach, Diversify Your Sources of Truth

By Gal Diskin, CTO and Co-Founder, Authomize β€” May 23rd 2022 at 14:00
What subsequent protections do you have in place when your first line of defense goes down?

☐ β˜† βœ‡ Dark Reading:

Chatbot Army Deployed in Latest DHL Shipping Phish

By Dark Reading Staff, Dark Reading β€” May 20th 2022 at 19:54
In a new phishing tactic, faux chatbots establish a conversation with victims to guide them to malicious links, researchers say.

☐ β˜† βœ‡ Dark Reading:

Partial Patching Still Provides Strong Protection Against APTs

By Jai Vijayan, Contributing Writer, Dark Reading β€” May 20th 2022 at 19:14
Organizations that deploy updates only after a vulnerability is disclosed apply far fewer updates and do so at a lower cost than those that stay up to date on all of their software, university researchers say.

☐ β˜† βœ‡ Dark Reading:

Quantum Key Distribution for a Post-Quantum World

By Lee Sattler, Distinguished Engineer in Product Strategy and Operations, Verizon β€” May 20th 2022 at 18:01
New versions of QKD use separate wavelengths on the same fiber, improving cost and efficiency, but distance is still a challenge.

☐ β˜† βœ‡ Dark Reading:

Microsoft Rushes a Fix After May Patch Tuesday Breaks Authentication

By Dark Reading Staff, Dark Reading β€” May 20th 2022 at 16:37
Two of Microsoft's Patch Tuesday updates need a do-over after causing certificate-based authentication errors.

☐ β˜† βœ‡ Dark Reading:

Authentication Is Static, Yet Attackers Are Dynamic: Filling the Critical Gap

By Gunnar Peterson, CISO, Forter β€” May 20th 2022 at 14:00
To succeed against dynamic cybercriminals, organizations must go multiple steps further and build a learning system that evolves over time to keep up with attacker tactics.

☐ β˜† βœ‡ Dark Reading:

New Open Source Project Brings Consistent Identity Access to Multicloud

By Fahmida Y. Rashid, Managing Editor, Features, Dark Reading β€” May 20th 2022 at 12:23
Hexa and IDQL allow organizations using cloud platforms such as Microsoft Azure, Amazon Web Services, and Google Cloud Platform to apply consistent access policy across all applications, regardless of environment.

☐ β˜† βœ‡ Dark Reading:

More Than 1,000 Cybersecurity Career Pursuers Complete the (ISC)Β² Entry-Level Cybersecurity Certification Pilot Exam

May 19th 2022 at 21:47
New professional certification program establishes a pathway into the workforce for students and career changers by demonstrating their foundational knowledge, skills and abilities to employers.
☐ β˜† βœ‡ Dark Reading:

Deadbolt Ransomware Targeting QNAP NAS Devices

May 19th 2022 at 21:37
QNAP is urging customers of its NAS products to update QTS and avoid exposing the devices to the Internet.

☐ β˜† βœ‡ Dark Reading:

Pro-Russian Information Operations Escalate in Ukraine War

By Jai Vijayan, Contributing Writer, Dark Reading β€” May 19th 2022 at 19:41
In the three months since the war started, Russian operatives and those allied with the nation's interests have unleashed a deluge of disinformation and fake news to try and sow fear and confusion in Ukraine, security vendor says.

☐ β˜† βœ‡ Dark Reading:

DoJ Won't Charge 'Good Faith' Security Researchers

By Dark Reading Staff, Dark Reading β€” May 19th 2022 at 19:29
Revised policy means security analysts won't be charged under the Computer Fraud and Abuse Act.

☐ β˜† βœ‡ Dark Reading:

Majority of Kubernetes API Servers Exposed to the Public Internet

By Ericka Chickowski, Contributing Writer, Dark Reading β€” May 19th 2022 at 18:39
Shadowserver Foundation researchers find 380,000 open Kubernetes API servers.

☐ β˜† βœ‡ Dark Reading:

Dig Exits Stealth With $11M for Cloud Data Detection and Response Solution

May 19th 2022 at 18:32
CrowdStrike and CyberArk invest in Dig's seed round, which was led by Team8, alongside Merlin Ventures and chairs of MongoDB and Exabeam.
☐ β˜† βœ‡ Dark Reading:

6 Scary Tactics Used in Mobile App Attacks

By Storm Swendsboe, Director of Intelligence, SafeGuard Cyber β€” May 19th 2022 at 14:00
Mobile attacks have been going on for many years, but the threat is rapidly evolving as more sophisticated malware families with novel features enter the scene.

☐ β˜† βœ‡ Dark Reading:

Phishing Attacks for Initial Access Surged 54% in Q1

By Jai Vijayan, Contributing Writer, Dark Reading β€” May 19th 2022 at 13:01
For the first time in a year, security incidents involving email compromises surpassed ransomware incidents, a new analysis shows.

☐ β˜† βœ‡ Dark Reading:

MITRE Creates Framework for Supply Chain Security

By Kelly Jackson Higgins, Editor-in-Chief, Dark Reading β€” May 18th 2022 at 21:29
System of Trust includes data-driven metrics for evaluating the integrity of software, services, and suppliers.

☐ β˜† βœ‡ Dark Reading:

CISA to Federal Agencies: Patch VMware Products Now or Take Them Offline

By Dark Reading Staff, Dark Reading β€” May 18th 2022 at 21:05
Last month attackers quickly reverse-engineered VMware patches to launch RCE attacks. CISA warns it's going to happen again.

☐ β˜† βœ‡ Dark Reading:

How Pwn2Own Made Bug Hunting a Real Sport

By Andrada Fiscutean, Contributing Writer, Dark Reading β€” May 18th 2022 at 20:19
From a scrappy contest where hackers tried to win laptops, Pwn2Own has grown into a premier event that has helped normalize bug hunting.

☐ β˜† βœ‡ Dark Reading:

Lacework Integrates Kubernetes Features to Enhance Security Across Multi-Cloud Environments

May 18th 2022 at 19:15
Polygraph Data Platform adds Kubernetes audit log monitoring, integration with Kubernetes admission controller, and Infrastructure as Code (IaC) security to help seamlessly integrate security into developer workflows.
☐ β˜† βœ‡ Dark Reading:

CISA: Unpatched F5 BIG-IP Devices Under Active Attack

By Dark Reading Staff, Dark Reading β€” May 18th 2022 at 17:46
Publicly released proof-of-concept exploits are supercharging attacks against unpatched systems, CISA warns.

☐ β˜† βœ‡ Dark Reading:

The Industry Must Better Secure Open Source Code From Threat Actors

By Andrew Useckas, Chief Technology Officer and Co-Founder, ThreatX β€” May 18th 2022 at 17:00
Build security in up front to secure open source code at the foundational level. Apply security controls, have engineering teams test, do code review, and use attacker-centric behavioral analytics to mitigate threats.

❌