FreshRSS

πŸ”’
☐ β˜† βœ‡ Dark Reading:

Ransomware 3.0: The Next Frontier

By James Gimbi, Senior Director of Technical Advisory Services, Moxfive β€” October 4th 2022 at 14:00
Attackers are already circling back to reselling stolen data instead of β€” and in addition to β€” extortion.

☐ β˜† βœ‡ Dark Reading:

Expert Insights: How to Protect Sensitive Machine-Learning Training Data Without Borking It

By Gary McGraw Ph.D., Co-founder Berryville Institute of Machine Learning β€” October 4th 2022 at 13:10
Another element of ML security is the data used to train the machine learning system itself.

☐ β˜† βœ‡ Dark Reading:

Growing Reliance on Cloud Brings New Security Challenges

By Fahmida Y. Rashid, Managing Editor, Features, Dark Reading β€” October 4th 2022 at 02:00
With organizations expanding their cloud operations, cloud security is imperative to protect applications and data.

☐ β˜† βœ‡ Dark Reading:

Bumblebee Malware Loader's Payloads Significantly Vary by Victim System

By Jai Vijayan, Contributing Writer, Dark Reading β€” October 3rd 2022 at 20:56
On some systems the malware drops infostealers and banking Trojans; on others it installs sophisticated post-compromise tools, new analysis shows.

☐ β˜† βœ‡ Dark Reading:

First 72 Hours of Incident Response Critical to Taming Cyberattack Chaos

By Robert Lemos, Contributing Writer, Dark Reading β€” October 3rd 2022 at 20:51
Responding to cyberattacks is extraordinarily stressful, but better planning, frequent practice, and the availability of mental health services can help IR professionals, a survey finds.

☐ β˜† βœ‡ Dark Reading:

Vice Society Publishes LA Public School Student Data, Psych Evals

By Becky Bracken, Editor, Dark Reading β€” October 3rd 2022 at 20:21
After a flat refusal to pay the ransom, Los Angeles Unified School District's stolen data has been dumped on the Dark Web by a ransomware gang.

☐ β˜† βœ‡ Dark Reading:

Name That Edge Toon: Mumbo Dumbo

By John Klossner, Cartoonist β€” October 3rd 2022 at 16:26
Come up with a clever caption, and our panel of experts will reward the winner with a $25 Amazon gift card.

☐ β˜† βœ‡ Dark Reading:

How AWS, Cisco, Netflix & SAP Are Approaching Cybersecurity Awareness Month

By CJ Moses, Chief Information Security Officer, Amazon Web Services β€” October 3rd 2022 at 14:00
This year's theme is "See Yourself in Cyber," and these security folks are using the month to reflect on the personal factor in cybersecurity.

☐ β˜† βœ‡ Dark Reading:

Worried About the Exchange Zero-Day? Here's What to Do

By Dark Reading Staff, Dark Reading β€” September 30th 2022 at 22:14
While organizations wait for an official patch for the two zero-day flaws in Microsoft Exchange, they should scan their networks for signs of exploitation and apply these mitigations.

☐ β˜† βœ‡ Dark Reading:

LA School District Ransomware Attackers Now Threaten to Leak Stolen Data

By Becky Bracken, Editor, Dark Reading β€” September 30th 2022 at 20:31
Weeks after it breached the Los Angeles Unified School District, the Vice Society ransomware group is threatening to leak the stolen data, unless they get paid.

☐ β˜† βœ‡ Dark Reading:

The Top 4 Mistakes in Security Programs to Avoid

By Chris Kirk, Principal Cybersecurity Consultant, Microsoft β€” September 30th 2022 at 20:00
Overlooking even just a single security threat can severely erode a company’s community and consumer confidence, tarnish reputation and brand, negatively impact corporate valuations, provide competitors with an advantage, and create unwanted scrutiny.

☐ β˜† βœ‡ Dark Reading:

Reshaping the Threat Landscape: Deepfake Cyberattacks Are Here

By Jai Vijayan, Contributing Writer, Dark Reading β€” September 30th 2022 at 19:10
It's time to dispel notions of deepfakes as an emergent threat. All the pieces for widespread attacks are in place and readily available to cybercriminals, even unsophisticated ones.

☐ β˜† βœ‡ Dark Reading:

Cybercriminals See Allure in BEC Attacks Over Ransomware

By Robert Lemos, Contributing Writer, Dark Reading β€” September 30th 2022 at 18:44
While ransomware seems stalled, business email compromise (BEC) attacks continue to make profits from the ProxyShell and Log4j vulnerabilities, nearly doubling in the latest quarter.

☐ β˜† βœ‡ Dark Reading:

Trojanized, Signed Comm100 Chat Installer Anchors Supply Chain Attack

By Dark Reading Staff, Dark Reading β€” September 30th 2022 at 17:38
Malicious Comm100 files have been found scattered throughout North America, and across sectors including tech, healthcare, manufacturing, telecom, insurance, and others.

☐ β˜† βœ‡ Dark Reading:

Microsoft Confirms Pair of Blindsiding Exchange Zero-Days, No Patch Yet

By Tara Seals, Managing Editor, News, Dark Reading β€” September 30th 2022 at 16:24
The "ProxyNotShell" security vulnerabilities can be chained for remote code execution and total takeover of corporate email platforms.

☐ β˜† βœ‡ Dark Reading:

SolarMarker Attack Leverages Weak WordPress Sites, Fake Chrome Browser Updates

By Nathan Eddy, Contributing Writer, Dark Reading β€” September 30th 2022 at 14:47
The SolarMarker group is exploiting a vulnerable WordPress-run website to encourage victims to download fake Chrome browser updates, part of a new tactic in its watering-hole attacks.

☐ β˜† βœ‡ Dark Reading:

With the Software Supply Chain, You Can't Secure What You Don't Measure

By Tomislav Pericin, Chief Software Architect & Co-Founder, ReversingLabs β€” September 30th 2022 at 14:00
Reports to the National Vulnerability Database jumped in 2022, but we should pay just as much attention to the flaws that are not being reported to NVD, including those affecting the software supply chain.

☐ β˜† βœ‡ Dark Reading:

Onyxia Raises $5M to Help Companies Proactively Manage Cybersecurity Risks Using AI

September 30th 2022 at 13:22
Onyxia, an AI-powered cybersecurity strategy and performance platform providing a centralized way for security teams to monitor and manage cybersecurity efforts in real time, has raised $5 million in seed fundraising led by World Trade Ventures with participation by Silvertech Ventures and angel investors.
☐ β˜† βœ‡ Dark Reading:

Cyera Survey Finds One in Three Respondents Want to Minimize Cloud Data Risk

September 30th 2022 at 00:28
Multiple providers say 'cloud data sprawl' makes managing cloud data risk a priority initiative within the next 12 months.
☐ β˜† βœ‡ Dark Reading:

Safous Adds Browser Isolation to Its Zero-Trust Network Access Service

September 30th 2022 at 00:24
This new function offers secure access to corporate applications and external SaaS through a virtual browser.
☐ β˜† βœ‡ Dark Reading:

Israel Cybersecurity Enterprise (ICE) Teams with CybeReady to Deliver World-Class Security Training

September 30th 2022 at 00:11
Security service provider selects cybersecurity training platform to safeguard enterprises in LATAM.
☐ β˜† βœ‡ Dark Reading:

Aunalytics Launches Security Patching Platform as a Service

September 29th 2022 at 23:56
Expedited software patching and updating recognized as one of the most important processes to protect against system compromise from cyberattacks.
☐ β˜† βœ‡ Dark Reading:

Veristor Partners with SANS Security Awareness to Deliver Employee Security Awareness Training

September 29th 2022 at 23:44
Companies collaborate to strengthen organizations' first line of security defense – end users.
☐ β˜† βœ‡ Dark Reading:

YouMail, Inc. and WMC Global Partner to Deliver Voice and SMS Phishing Disruption Services

September 29th 2022 at 23:39
Joint phishing intelligence solution provides 360-degree mobile communication defense.
☐ β˜† βœ‡ Dark Reading:

Organizations Finding the Need for New Approaches on the Cybersecurity Front, CompTIA research reveals

September 29th 2022 at 23:33
Settling for 'satisfactory' level of readiness may underestimate growing levels of risk.
☐ β˜† βœ‡ Dark Reading:

Intel Hardens Confidential Computing With Project Amber Updates

By Agam Shah, Contributing Writer β€” September 29th 2022 at 23:31
The chip giant has developed new features and services to make it tougher for malicious hackers and insiders to access sensitive data from applications in the cloud.

☐ β˜† βœ‡ Dark Reading:

KnowBe4 Simplifies Compliance Requirements for Healthcare Privacy

September 29th 2022 at 23:23
KnowBe4's Compliance Audit Readiness Assessment (CARA) now addresses select requirements from HIPAA Security Rule.
☐ β˜† βœ‡ Dark Reading:

Pathlock Expands SAP Capabilities with Acquisition of Grey Monarch

September 29th 2022 at 23:19
Combination of two companies to help SAP customers streamline audit, compliance and control processes.
☐ β˜† βœ‡ Dark Reading:

Ransomware Attacks Continue Increasing: 20% of All Reported Attacks Occurred in the Last 12 Months - New Survey

September 29th 2022 at 23:10
Survey of over 2,000 IT pros revealed that a quarter either don't know or don't think Microsoft 365 data can be affected by ransomware.
☐ β˜† βœ‡ Dark Reading:

Why the US Should Help Secure Mexican Infrastructure β€” and What It Gets in Return

By Daron Hartvigsen, Managing Director, StoneTurn β€” September 29th 2022 at 21:44
Call it cross-border enlightened self-interest: As one of the US's premier trade partners and closest neighbors, what's bad for Mexico is bad for the US.

☐ β˜† βœ‡ Dark Reading:

The Country Where You Live Impacts Password Choices

By Tara Seals, Managing Editor, News, Dark Reading β€” September 29th 2022 at 20:32
Literacy, levels of personal freedom, and other macro-social factors help determine how strong average passwords are in a given locale, researchers have found.

☐ β˜† βœ‡ Dark Reading:

Dangerous New Attack Technique Compromising VMware ESXi Hypervisors

By Jai Vijayan, Contributing Writer, Dark Reading β€” September 29th 2022 at 19:26
China-based threat actor used poisoned vSphere Installation Bundles to deliver multiple backdoors on systems, security vendor says.

☐ β˜† βœ‡ Dark Reading:

3 Reasons Why BEC Scams Work in Real Estate

By Kolawole Samuel Adebayo, Contributing Writer β€” September 29th 2022 at 18:33
Identity verification could be the key to fighting back and building trust in an industry beset with high-stakes fraud.

☐ β˜† βœ‡ Dark Reading:

(ISC)Β² Recruits More Than 55,000 Cybersecurity Candidates in First 30 Days of New Programs to Address Workforce Gap

September 29th 2022 at 15:01
2,700 cybersecurity career pursuers have already passed the (ISC)2 Certified in Cybersecurityβ„  exam, with more than 53,000 more people registered for a free course and exam.
☐ β˜† βœ‡ Dark Reading:

Capital One Phish Showcases Growing Bank-Brand Targeting Trend

By Becky Bracken, Editor, Dark Reading β€” September 29th 2022 at 14:42
Capital One lures leveraged the bank's new partnership with Authentify, showing that phishers watch the headlines, and take advantage.

☐ β˜† βœ‡ Dark Reading:

Espionage Group Wields Steganographic Backdoor Against Govs, Stock Exchange

By Elizabeth Montalbano, Contributor, Dark Reading β€” September 29th 2022 at 14:33
APT group Witchetty (aka LookingFrog) has exploited the ProxyShell and ProxyLogon vulnerabilities to gain initial access and deploy new custom cyber tools against government agencies and a stock exchange.

☐ β˜† βœ‡ Dark Reading:

XSS Flaw in Prevalent Media Imaging Tool Exposes Trove of Patient Data

By Becky Bracken, Editor, Dark Reading β€” September 29th 2022 at 13:37
Bugs in Canon Medical's Virea View could allow cyberattackers to access several sources of sensitive patient data.

☐ β˜† βœ‡ Dark Reading:

What Lurks in the Shadows of Cloud Security?

By Fernando Montenegro, Senior Principal Analyst, Omdia β€” September 29th 2022 at 13:00
Organizations looking to get ahead in cloud security have gone down the path of deploying CSPM tooling with good results. Still, there’s a clear picture that data security and security operations are next key areas of interest.

☐ β˜† βœ‡ Dark Reading:

Fake Accounts Are Not Your Friends!

By Jonathan Care, Contributing Writer, Dark Reading β€” September 28th 2022 at 22:21
Inflated user bases and fake engagement cause more harm than good, especially when the artificial accounts are based on stolen human identities.

☐ β˜† βœ‡ Dark Reading:

Plug Your Data Leaks: Integrating Data Loss Prevention into Your Security Stack

September 28th 2022 at 21:33
The average cost of a data-exposing cybersecurity incident is $4.35 million. If your business can’t avoid to pay, make sure you’ve got a strong data loss prevention practice in place.
☐ β˜† βœ‡ Dark Reading:

Google Quashes 5 High-Severity Bugs With Chrome 106 Update

By Dark Reading Staff, Dark Reading β€” September 28th 2022 at 21:24
External researchers contributed 16 of the 20 security updates included in the new Chrome 106 Stable Channel rollout, including five high-severity bugs.

☐ β˜† βœ‡ Dark Reading:

Sophisticated Covert Cyberattack Campaign Targets Military Contractors

By Jai Vijayan, Contributing Writer, Dark Reading β€” September 28th 2022 at 20:59
Malware used in the STEEP#MAVERICK campaign features rarely seen obfuscation, anti-analysis, and evasion capabilities.

☐ β˜† βœ‡ Dark Reading:

Fast Company CMS Hack Raises Security Questions

By Tara Seals, Managing Editor, News, Dark Reading β€” September 28th 2022 at 20:12
The company's website remains offline after hackers used its compromised CMS to send out racist messages.

☐ β˜† βœ‡ Dark Reading:

Container Supply Chain Attacks Cash In on Cryptojacking

By Ericka Chickowski, Contributing Writer, Dark Reading β€” September 28th 2022 at 19:57
Cloud-native threats are costing cloud customer victims money as cryptojackers mine their vulnerable cloud instances.

☐ β˜† βœ‡ Dark Reading:

Google Cloud DORA: Securing the Supply Chain Begins With Culture

By Robert Lemos, Contributing Writer, Dark Reading β€” September 28th 2022 at 19:47
The team's annual survey finds that the right development culture is better than technical measures when it comes to shoring up software supply chain security practices. An additional benefit: Less burnout.

☐ β˜† βœ‡ Dark Reading:

Phishing Attacks Crushed Records Last Quarter, Driven by Mobile

By Dark Reading Staff, Dark Reading β€” September 28th 2022 at 19:42
Shocking phishing numbers (more than 1 million in a single quarter) are being driven by vishing, smishing, and other lures that target mobile devices.

☐ β˜† βœ‡ Dark Reading:

The Countdown to DORA

By Ilias Chantzos, Global Privacy Officer and Head of EMEA Government Affairs, Broadcom β€” September 28th 2022 at 17:00
With provisional agreement reached on the Digital Operational Resilience Act, the clock is now ticking for banks and information and communications technology (ICT) services companies with European operations. Here's what you need to know.

☐ β˜† βœ‡ Dark Reading:

Chaos Malware Resurfaces With All-New DDoS & Cryptomining Modules

By Elizabeth Montalbano, Contributor, Dark Reading β€” September 28th 2022 at 16:12
The previously identified ransomware builder has veered in an entirely new direction, targeting consumers and business of all sizes by exploiting known CVEs through brute-forced and/or stolen SSH keys.

☐ β˜† βœ‡ Dark Reading:

Illumio Introduces New Solution to Stop Endpoint Ransomware from Spreading Across the Hybrid Attack Surface

September 28th 2022 at 14:23
Illumio Endpoint extends zero trust segmentation to see risk and set policy across macOS and Windows devices.
☐ β˜† βœ‡ Dark Reading:

Jamf Announces Intent to Acquire ZecOps, to Provide a Market-Leading Security Solution for Mobile Devices as Targeted Attacks Continue to Grow

September 28th 2022 at 14:21
ZecOps extends Jamf's mobile security capabilities by adding advanced detections and incident response.
☐ β˜† βœ‡ Dark Reading:

Time to Change Our Flawed Approach to Security Awareness

By Arun Vishwanath, Technologist β€” September 28th 2022 at 14:00
Defend against phishing attacks with more than user training. Measure users' suspicion levels along with cognitive and behavioral factors, then build a risk index and use the information to better protect those who are most vulnerable.

☐ β˜† βœ‡ Dark Reading:

When Will Cybersecurity Get Its Bloomberg Terminal?

By Yotam Segev, Co-Founder and CEO, Cyera β€” September 28th 2022 at 14:00
The "single pane of glass" that gathers and correlates all the information security professionals need doesn't exist, so it's up to us to create it.

☐ β˜† βœ‡ Dark Reading:

Malwarebytes Expands OneView Platform for MSPs

September 28th 2022 at 13:39
Malwarebytes achieves 250% year-over-year MSP partner growth, introduces new modules to enhance protection, detection, and resolution of threats for SMBs.
☐ β˜† βœ‡ Dark Reading:

Most Attackers Need Less Than 10 Hours to Find Weaknesses

By Robert Lemos, Contributing Writer, Dark Reading β€” September 28th 2022 at 10:00
Vulnerable configurations, software flaws, and exposed Web services allow hackers to find exploitable weaknesses in companies' perimeters in just hours, not days.

☐ β˜† βœ‡ Dark Reading:

Lazarus Lures Aspiring Crypto Pros With Fake Exchange Job Postings

By Becky Bracken, Editor, Dark Reading β€” September 27th 2022 at 21:40
Previously observed using fake Coinbase jobs, the North Korea-sponsored APT has expanded into using Crypo.com gigs as cover to distribute malware.

☐ β˜† βœ‡ Dark Reading:

Amid Sweeping Change, Cyber Defenders Face Escalating Visibility β€” and Pressure

By Tara Seals, Managing Editor, News, Dark Reading β€” September 27th 2022 at 21:27
Why cyber teams are now front and center for business enablement within organizations, and the significant challenges they face.

☐ β˜† βœ‡ Dark Reading:

FBI Helping Australian Authorities Investigate Massive Optus Data Breach: Reports

By Jai Vijayan, Contributing Writer, Dark Reading β€” September 27th 2022 at 20:27
Initial reports suggest a basic security error allowed the attacker to access the company's live customer database via an unauthenticated API.

☐ β˜† βœ‡ Dark Reading:

Microsoft Rolls Out Passwordless Sign-on for Azure Virtual Desktop

By Dark Reading Staff, Dark Reading β€” September 27th 2022 at 19:04
Azure says cloud-native single sign-on with a passwordless option is most-requested new AVD feature in the product's history.

❌