FreshRSS

πŸ”’
☐ β˜† βœ‡ Dark Reading:

Cerberus Sentinel Completes Acquisition of Creatrix, Inc.

June 2nd 2022 at 21:03
U.S. cybersecurity services firm expands security and identity management services with woman-owned business.
☐ β˜† βœ‡ Dark Reading:

Research Reveals 75% of CISOs Are Worried Too Many Application Vulnerabilities Leak Into Production, Despite a Multi-Layered Security Approach

June 2nd 2022 at 20:54
79% of CISOs say continuous runtime vulnerability management is an essential capability to keep up with the expanding complexity of modern multi-cloud environments.
☐ β˜† βœ‡ Dark Reading:

Intel Chipset Firmware Actively Targeted by Conti Group

By Dark Reading Staff, Dark Reading β€” June 2nd 2022 at 20:50
Conti threat actors are betting chipset firmware is updated less frequently than other software β€” and winning big, analysts say.

☐ β˜† βœ‡ Dark Reading:

Gurucul Launches Cloud-Native SOC Platform Pushing the Boundaries of Next-Gen SIEM and XDR with Identity Threat Detection and Response

June 2nd 2022 at 20:44
Gurucul automating threat detection, investigation and response (TDIR) with advanced analytics, comprehensive threat content, and a flexible enterprise risk engine for hybrid and multi-cloud environments.
☐ β˜† βœ‡ Dark Reading:

Phishers Having a Field Day on WhatsApp, Telegraph

By Dark Reading Staff, Dark Reading β€” June 2nd 2022 at 19:54
A pair of phishing campaigns against users of WhatsApp and Telegram's Telegraph expose them to extortion, credential harvesting, and even account takeover.

☐ β˜† βœ‡ Dark Reading:

New Cloud Pricing and Products Proof of RSA’s Transformation

June 2nd 2022 at 19:52
RSA pivots to exclusive focus. Identity is once again the β€˜beating heart’ of RSA.
☐ β˜† βœ‡ Dark Reading:

Microsoft Philanthropies Collaborates With WiCyS to Help Close the Cybersecurity Skills Gap

June 2nd 2022 at 19:47
Microsoft Philanthropies is expanding its cybersecurity skills for jobs campaign to 23 countries and partnering with Women in CyberSecurity (WiCyS) to build a cybersecurity workforce that is not just larger but also more diverse.
☐ β˜† βœ‡ Dark Reading:

US Sanctions Force Evil Corp to Change Tactics

By Jai Vijayan, Contributing Writer, Dark Reading β€” June 2nd 2022 at 19:45
The threat actor behind the notorious Dridex campaign has switched from using its exclusive credential-harvesting malware to a ransomware-as-a-service model, to make attribution harder.

☐ β˜† βœ‡ Dark Reading:

Neosec Introduces Expert Managed Threat Hunting Service for Detecting and Investigating API Abuse and Vulnerabilities

June 2nd 2022 at 19:36
Neosec threat hunters from the 'ShadowHunt' team jumpstart the API Security process quickly and help build the knowledge in today's overstretched security teams.
☐ β˜† βœ‡ Dark Reading:

Turbulent Cyber Insurance Market Sees Rising Prices and Sinking Coverage

By Stephen Lawton, Contributing Writer β€” June 2nd 2022 at 18:25
As insurers and brokers reckon with unexpected losses, they're charging more for policies and setting higher requirements.

☐ β˜† βœ‡ Dark Reading:

Building America's Cybersecurity Infrastructure

By Mike McNerney, Senior VP of Security, Resilience β€” June 2nd 2022 at 17:00
The government is putting the right skills and expertise in place to fight the rising cyber threat.

☐ β˜† βœ‡ Dark Reading:

'Clipminer' Malware Actors Steal $1.7 Million Using Clipboard Hijacking

By Nathan Eddy, Contributing Writer, Dark Reading β€” June 2nd 2022 at 15:00
The malware targets Windows users via Trojanized downloads of cracked or pirated software and then starts in on cryptocurrency mining and clipboard hijacking.

☐ β˜† βœ‡ Dark Reading:

Fighting Follina: Application Vulnerabilities and Detection Possibilities

By Joe Slowik, Senior Manager, Gigamon β€” June 2nd 2022 at 14:00
Although organizations should perform proper risk analysis and patch as soon as practical after there's a fix for this vulnerability, defenders still have options before that's released.

☐ β˜† βœ‡ Dark Reading:

Neutralizing Novel Trickbot Attacks With AI

By Tony Jarvis, Director of Enterprise Security, Asia Pacific and Japan, Darktrace β€” June 2nd 2022 at 13:00
Artificial intelligence technology can detect the latest wave of Trickbot ransomware and block the attack before it causes damage.

☐ β˜† βœ‡ Dark Reading:

Darktrace's Brianna Leddy on How Ransomware Groups Adapt to New Defenses

By Dark Reading Staff, Dark Reading β€” June 1st 2022 at 22:40
In this Tech Talk, Darktrace's Brianna Leddy and Dark Reading's Terry Sweeney discuss ways ransomware groups adapt their activities as enterprise security teams evolve their defenses and controls.

☐ β˜† βœ‡ Dark Reading:

Managing Extended Software Supply Chain Risks

June 1st 2022 at 22:30
Supply chain woes have dominated headlines, but there's another type of supply chain that's also increasingly at risk: the cloud supply chain.
☐ β˜† βœ‡ Dark Reading:

Hunting for Threats Using Network Traffic Flows

By Fahmida Y. Rashid, Managing Editor, Features, Dark Reading β€” June 1st 2022 at 21:30
SeclarityIO's NetworkSage platform analyzes network traffic data to identify attacks before they become real problems.

☐ β˜† βœ‡ Dark Reading:

FluBot Android Malware Operation Disrupted, Infrastructure Seized

By Jai Vijayan, Contributing Writer, Dark Reading β€” June 1st 2022 at 21:08
Security researchers have described the malware as among the fastest-spreading mobile threats in recent years.

☐ β˜† βœ‡ Dark Reading:

NetSPI's New Breach and Attack Simulation Enhancements Help Organizations Achieve Behavior-Based Threat Detection

June 1st 2022 at 20:49
Organizations leverage the platform-driven, human-delivered service to measure and continuously improve the efficacy of detective controls and MSSP coverage.
☐ β˜† βœ‡ Dark Reading:

Netenrich Debuts Resolution Intelligence Secure Digital Operations Platform at RSA 2022

June 1st 2022 at 20:46
New operational analytics and AI/ML platform drives contextual intelligence and prioritized actions to anticipate risky behaviors, disrupt threats and insure business resilience.
☐ β˜† βœ‡ Dark Reading:

12K Misconfigured Elasticsearch Buckets Ravaged by Extortionists

By Tara Seals, Managing Editor, News, Dark Reading β€” June 1st 2022 at 20:45
The cloud instances were left open to the public Internet with no authentication, allowing attackers to wipe the data.

☐ β˜† βœ‡ Dark Reading:

Darktrace's David Masson on What Attacks on Critical Infrastructure Look Like

By Dark Reading Staff, Dark Reading β€” June 1st 2022 at 20:30
In this Tech Talk, Darktrace's David Masson and Dark Reading's Terry Sweeney discuss the rise of destructive attacks against critical infrastructure.

☐ β˜† βœ‡ Dark Reading:

Feds Seize Domains Dealing Stolen Personal Data

By Dark Reading Staff, Dark Reading β€” June 1st 2022 at 20:28
WeLeakInfo.to and two related domains let users search data stolen in more than 10,000 different breaches.

☐ β˜† βœ‡ Dark Reading:

Netskope Acquires WootCloud, Extending Zero Trust Capabilities to Enterprise IoT

June 1st 2022 at 20:13
Contextual Intelligence derived with machine learning helps customers identify, assess and remediate threats from IoT devices on their networks, achieving full visibility and control.
☐ β˜† βœ‡ Dark Reading:

ReliaQuest to Acquire Digital Shadows

June 1st 2022 at 20:09
Combined company creates world-class security operations platform to offer customers unmatched visibility and detection to defend against threats.
☐ β˜† βœ‡ Dark Reading:

Lookout Acquires SaferPass To Address The Rising Threat Of Identity Theft

June 1st 2022 at 20:03
Password management solution delivers proactive, seamless approach to protecting privacy and login credentials for consumers and businesses; Password Management market expected to reach $3 billion by 2026.
☐ β˜† βœ‡ Dark Reading:

EnemyBot Puts Enterprises in the Crosshairs With Raft of '1-Day' Bugs

By Tara Seals, Managing Editor, News, Dark Reading β€” June 1st 2022 at 19:20
EnemyBot DDoS botnet is rapidly weaponizing security bugs disclosed in CMS systems like WordPress plug-ins, Android devices, commercial Web servers, and other enterprise applications.

☐ β˜† βœ‡ Dark Reading:

Security at the Edge: Why It's Complicated

By Paul Kurtz, Chief Cybersecurity Adviser, Splunk Public Sector β€” June 1st 2022 at 17:00
Edge technology widens the attack surface by bringing data analysis closer to where it's collected. Now is the time for public and private sector groups to establish guidelines and identify security best-practices frameworks.

☐ β˜† βœ‡ Dark Reading:

Consumer Reports Launches IoT Cybersecurity 'Nutrition Label'

By Dark Reading Staff, Dark Reading β€” June 1st 2022 at 17:00
Stalwart consumer advocacy group says it intends to educate people about cybersecurity and how to choose the safest products.

☐ β˜† βœ‡ Dark Reading:

10 No-BS Tips for Building a Diverse and Dynamic Security Team

By Ericka Chickowski, Contributing Writer, Dark Reading β€” June 1st 2022 at 16:55
Advice from women and nonbinary security leaders on creating well-rounded security teams, stronger CISO leadership, and a more resilient industry.

☐ β˜† βœ‡ Dark Reading:

Zero Trust Research Reveals Nearly Half of All Security Leaders Do Not Believe They Will Be Breached Despite Increasing Attacks and Adoption of Zero Trust Strategies

June 1st 2022 at 16:41
Industry-first report finds zero trust segmentation eliminates 5 cyber disasters per year and saves $20+ million annually.
☐ β˜† βœ‡ Dark Reading:

Help Organizations to Mitigate Risk in Microsoft 365 with 'Vectra Protect'

June 1st 2022 at 16:37
Vectra offers a free of charge security assessment for your cloud tenant.
☐ β˜† βœ‡ Dark Reading:

Ordr Secures $40 Million in Series C Funding to Answer Increased Demand for Connected Device Security

June 1st 2022 at 16:33
Rising threat of data breaches and ransomware attacks drives need for complete and accurate real-time information about devices and their risks.
☐ β˜† βœ‡ Dark Reading:

StorCentric Launches Nexsan EZ-NAS -Network-Attached Storage for SMBs and Enterprise Edge Deployments

June 1st 2022 at 16:29
EZ-NAS also provides add-on data backup, cloud connector and ransomware anomaly detection.
☐ β˜† βœ‡ Dark Reading:

Distinguishing AI Hype From Reality in SecOps

By Nash Borges, VP of Engineering and Data Science, Secureworks β€” June 1st 2022 at 14:00
AI and ML are important SecOps tools, but human involvement is still required.

☐ β˜† βœ‡ Dark Reading:

3.6M MySQL Servers Found Exposed Online

By Dark Reading Staff, Dark Reading β€” May 31st 2022 at 21:05
Researchers from Shadowserver recommend removing the servers from the Internet to shrink external attack surface.

☐ β˜† βœ‡ Dark Reading:

Surefire Cyber Launches to Help Cyber Insurance Ecosystem from Response to Resilience, with $10 Million in Funding by Forgepoint Capital

May 31st 2022 at 20:54
Industry veterans roll out end-to-end incident response services and innovative tech-enabled platform, following successful incubation.
☐ β˜† βœ‡ Dark Reading:

New Microsoft Zero-Day Attack Underway

By Jai Vijayan, Contributing Writer, Dark Reading β€” May 31st 2022 at 20:37
"Follina" vulnerability in Microsoft Support Diagnostic Tool (MSDT) affects all currently supported Windows versions and can be triggered via specially crafted Office documents.

☐ β˜† βœ‡ Dark Reading:

Biometric Data Offers Added Security β€” But Don't Lose Sight of These Important Risks

By Tatiana Walk-Morris, Contributing Writer β€” May 31st 2022 at 20:20
With rising fraud, businesses are seeking authentication methods that are security- and user-friendly. But with that comes a few complications.

☐ β˜† βœ‡ Dark Reading:

Fewer DDoS Attacks in 2021, Still Above Pre-Pandemic Levels

By Dark Reading Staff, Dark Reading β€” May 31st 2022 at 17:44
New research finds a rise in TCP acknowledgement (ACK) DDoS attacks, which rely on a smaller amount of traffic to disrupt targets.

☐ β˜† βœ‡ Dark Reading:

New CyberCatch Research Discovers Alarming Increase in Cyber Vulnerabilities for Small and Medium Sized Businesses in US and Canada

May 31st 2022 at 17:08
For the first time, CyberCatch's SMBVR detected significant vulnerability to 'session riding' attacks among North American SMBs.
☐ β˜† βœ‡ Dark Reading:

How to Keep Your Enterprise Safe From Digital Supply Chain Attacks

By Ran Nahmias, Co-Founder & Chief Business Officer, Cyberpion β€” May 31st 2022 at 14:00
Digital supply chains are more vulnerable than ever; here's what you need to do to secure them.

☐ β˜† βœ‡ Dark Reading:

6 Steps to Ensure Cyber Resilience

By Grayson Milbourne, Security Intelligence Director, OpenText Security Solutions β€” May 30th 2022 at 14:00
To minimize the impact of cyber incidents, organizations must be pragmatic and develop a strategy of resilience for dealing with break-ins, advanced malware, and data theft.

☐ β˜† βœ‡ Dark Reading:

Critical OAS Bugs Open Industrial Systems to Takeover

By Jai Vijayan, Contributing Writer, Dark Reading β€” May 28th 2022 at 14:00
The most serious flaw gives attackers a way to remotely execute code on systems that many organizations use to move data in critical ICS environments, security vendor says.

☐ β˜† βœ‡ Dark Reading:

Exposed Kubernetes Clusters, Kubelet Ports Can Be Abused in Cyberattacks

By Nathan Eddy, Contributing Writer, Dark Reading β€” May 27th 2022 at 20:54
Organizations must ensure their kubelets and related APIs aren’t inadvertently exposed or lack proper access control, offering an easy access point for malicious actors.

☐ β˜† βœ‡ Dark Reading:

Space Force Expands Cyber Defense Operations

By Dark Reading Staff, Dark Reading β€” May 27th 2022 at 20:25
Space Force's Delta 6 cyber-defense group adds squadrons, updates legacy Satellite Control Network.

☐ β˜† βœ‡ Dark Reading:

Scammer Behind $568M International Cybercrime Syndicate Gets 4 Years

By Dark Reading Staff, Dark Reading β€” May 27th 2022 at 17:02
The 14th defendant behind The Infraud Organization contraband marketplace has been sentenced, this time for one count of racketeering.

☐ β˜† βœ‡ Dark Reading:

New Chaos Malware Variant Ditches Wiper for Encryption

By Tara Seals, Managing Editor, News, Dark Reading β€” May 27th 2022 at 16:07
The Chaos ransomware-builder was known for creating destructor malware that overwrote files and made them unrecoverable -- but the new Yashma version finally generates binaries that can encrypt files of all sizes.

☐ β˜† βœ‡ Dark Reading:

ChromeLoader Malware Hijacks Browsers With ISO Files

By Nathan Eddy, Contributing Writer, Dark Reading β€” May 27th 2022 at 15:49
The malware's abuse of PowerShell makes it more dangerous, allowing for more advanced attacks such as ransomware, fileless malware, and malicious code memory injections.

☐ β˜† βœ‡ Dark Reading:

Physical Security Teams' Impact Is Far-Reaching

By Tom Kopecky, Chief Strategy Officer and Co-Founder, Ontic β€” May 27th 2022 at 14:00
Here's how physical security teams can integrate with the business to identify better solutions to security problems.

☐ β˜† βœ‡ Dark Reading:

Taking the Danger Out of IT/OT Convergence

By Dave Masson, Director of Enterprise Security, Darktrace β€” May 27th 2022 at 11:23
The Colonial Pipeline attack highlighted the risks of convergence. Unified security provides a safer way to proceed.

☐ β˜† βœ‡ Dark Reading:

Microsoft Unveils Dev Box, a Workstation-as-a-Service

By Dark Reading Staff, Dark Reading β€” May 26th 2022 at 22:54
Microsoft Dev Box will make it easier for developers and hybrid teams to get up and running with workstations already preconfigured with required applications and tools.

☐ β˜† βœ‡ Dark Reading:

Broadcom Snaps Up VMware in $61B Deal

By Dark Reading Staff, Dark Reading β€” May 26th 2022 at 22:27
Massive merger will put Broadcom's Symantec and VMware's Carbon Black under one roof.

☐ β˜† βœ‡ Dark Reading:

Lacework Announces Layoffs, Restructuring

By Dark Reading Staff, Dark Reading β€” May 26th 2022 at 20:46
The cloud-security company blames "seismic" market shifts for shakeup.

☐ β˜† βœ‡ Dark Reading:

Third-Party Scripts on Websites Present a 'Broad & Open' Attack Vector

By Jai Vijayan, Contributing Writer, Dark Reading β€” May 26th 2022 at 20:20
Nearly half of the world's largest websites use externally generated JavaScript that makes them ripe targets for cyberattackers interested in stealing data, skimming credit cards, and executing other malicious actions.

☐ β˜† βœ‡ Dark Reading:

Twitter Fined $150M for Security Data Misuse

By Dark Reading Staff, Dark Reading β€” May 26th 2022 at 18:00
Twitter is charged with using emails and phone numbers ostensibly collected for account security to sell targeted ads.

☐ β˜† βœ‡ Dark Reading:

The FDA's New Cybersecurity Guidance for Medical Devices Reminds Us That Safety & Security Go Hand in Hand

By Roman Kesler, VP of Research, Cybellum β€” May 26th 2022 at 17:00
The new draft guidance on premarket submissions incorporates quality system regulations and doubles down on a life-cycle approach to product security.

❌