FreshRSS

πŸ”’
☐ β˜† βœ‡ Dark Reading:

Microsoft Addresses Zero-Days, but Exchange Server Exploit Chain Remains Unpatched

By Tara Seals, Managing Editor, News, Dark Reading β€” October 11th 2022 at 20:32
The computing giant didn't fix ProxyNotLogon in October's Patch Tuesday, but it disclosed a rare 10-out-of-10 bug and patched two other zero-days, including one being exploited.

☐ β˜† βœ‡ Dark Reading:

AI and Residual Finger Heat Could Be a Password Cracker's Latest Tools

By Ericka Chickowski, Contributing Writer, Dark Reading β€” October 11th 2022 at 19:01
New research demonstrates the use of thermal camera images of keyboards and screens in concert with AI to correctly guess computer passwords faster and more accurately.

☐ β˜† βœ‡ Dark Reading:

Critical Open Source vm2 Sandbox Escape Bug Affects Millions

By Elizabeth Montalbano, Contributor, Dark Reading β€” October 11th 2022 at 18:23
Attackers could exploit the "Sandbreak" security bug, which has earned a 10 out of 10 on the CVSS scale, to execute a sandbox escape, achieve RCE, and run shell commands on a hosting machine.

☐ β˜† βœ‡ Dark Reading:

OT Cybersecurity Leader Paul Brager Passes Away

By Dark Reading Staff, Dark Reading β€” October 11th 2022 at 17:53
The IT security executive led ICS/OT, IT/OT integration, and other security programs, as well as diversity and inclusion efforts in the industry.

☐ β˜† βœ‡ Dark Reading:

Intel Processor UEFI Source Code Leaked

By Dark Reading Staff, Dark Reading β€” October 11th 2022 at 17:49
Exposed code included private key for Intel Boot Guard, meaning it can no longer be trusted, according to a researcher.

☐ β˜† βœ‡ Dark Reading:

It's Time to Make Security an Innovation Enabler

By Ulfar Erlingsson, Chief Architect, Lacework β€” October 11th 2022 at 17:00
How data-driven security can best safeguard your unique cloud operations.

☐ β˜† βœ‡ Dark Reading:

Skybox Security Unveils Industry's First SaaS Solution For Security Policy and Vulnerability Management Across Hybrid Environments

October 11th 2022 at 15:21
Skybox Security Cloud Edition ushers in a new era of proactive cybersecurity .
☐ β˜† βœ‡ Dark Reading:

Dependency Management Aims to Make Security Easier

By Robert Lemos, Contributing Writer, Dark Reading β€” October 11th 2022 at 15:17
Existing software security firms and new startups tackle the tasks of exposing dependencies and helping developers manage their use of open-source components.

☐ β˜† βœ‡ Dark Reading:

DigiCert Root CA Approved for Matter Device Attestation by Connectivity Standards Alliance

October 11th 2022 at 15:15
DigiCert ready to help smart home device manufacturers achieve Matter compliance rapidly and at scale.
☐ β˜† βœ‡ Dark Reading:

Stairwell Announces $45M Series B Funding Round

October 11th 2022 at 14:57
Investment led by Section 32 will be used to scale the product and team.
☐ β˜† βœ‡ Dark Reading:

Outpost24 Announces Expansion of Penetration Testing Offerings to North America

October 11th 2022 at 14:13
Pen testing solutions to empower businesses to proactively address application security vulnerabilities amid surging threats.
☐ β˜† βœ‡ Dark Reading:

High-Value Targets: String of Aussie Telco Breaches Continues

By Becky Bracken, Editor, Dark Reading β€” October 11th 2022 at 14:01
Australian IT services provider Dialog has announced a breach, making it the third telecom company in the area compromised in less than a month.

☐ β˜† βœ‡ Dark Reading:

Proposed SEC Disclosure Rules Could Transform Cyber-Incident Response

By Jason Hicks, Field CISO, Coalfire β€” October 11th 2022 at 14:00
It's not too early for firms to start preparing for change.

☐ β˜† βœ‡ Dark Reading:

5 Attack Elements Every Organizations Should Be Monitoring

By Microsoft Security, Microsoft β€” October 4th 2022 at 19:00
Security teams have to protect an increasingly complex enterprise environment. Here are five elements of attack surface management they should consider.

☐ β˜† βœ‡ Dark Reading:

US Airports in Cyberattack Crosshairs for Pro-Russian Group Killnet

By Jai Vijayan, Contributing Writer, Dark Reading β€” October 10th 2022 at 20:45
Killnet calls on other groups to launch similar attacks against US civilian infrastructure, including marine terminals and logistics facilities, weather monitoring centers, and healthcare systems.

☐ β˜† βœ‡ Dark Reading:

Emotet Rises Again With More Sophistication, Evasion

By Robert Lemos, Contributing Writer, Dark Reading β€” October 10th 2022 at 20:35
An analysis of the malware and its infection strategies finds nearly 21,000 minor and 139 major variations on the malware β€” complexity that helps it dodge analysis.

☐ β˜† βœ‡ Dark Reading:

Zimbra RCE Bug Under Active Attack

By Dark Reading Staff, Dark Reading β€” October 10th 2022 at 18:17
A flaw in unpatched Zimbra email servers could allow attackers to obtain remote code execution by pushing malicious files past filters.

☐ β˜† βœ‡ Dark Reading:

6 Things Every CISO Should Do the First 90 Days on the Job

By James Turgal, VP of Cyber Risk, Strategy & Board Relations, Optiv β€” October 10th 2022 at 14:00
A CISO's responsibilities have evolved immensely in recent years, so their first three months on the job should look a different today than they might have several years ago.

☐ β˜† βœ‡ Dark Reading:

Email Defenses Under Siege: Phishing Attacks Dramatically Improve

By Robert Lemos, Contributing Writer, Dark Reading β€” October 8th 2022 at 13:00
About 1 in 5 phishing email messages reach workers' inboxes, as attackers get better at dodging Microsoft's platform defenses and defenders run into processing limitations.

☐ β˜† βœ‡ Dark Reading:

Credential Harvesting Is Retail Industry's Top Threat

By Edge Editors, Dark Reading β€” October 7th 2022 at 22:52
Why bother with new tactics and exploits when the old tricks are still effective?

☐ β˜† βœ‡ Dark Reading:

Cybersecurity Will Account for Nearly One-Quarter of AI Software Market Through 2025

By Dark Reading Staff, Dark Reading β€” October 7th 2022 at 19:59
A boom in artificial intelligence-powered detection and remediation tools pushes security spending to the top of the AI market, according to Forrester.

☐ β˜† βœ‡ Dark Reading:

State Bar of Georgia Notifies Members and Employees of Cybersecurity Incident

October 7th 2022 at 16:50
Current and former employees and members are being offered complimentary credit monitoring and identity protection services as some personal information may have been accessed.
☐ β˜† βœ‡ Dark Reading:

Patch Now: Fortinet FortiGate & FortiProxy Contain Critical Vuln

By Dark Reading Staff, Dark Reading β€” October 7th 2022 at 16:45
The bug is under active exploitation; Fortinet issued a customer advisory urging customers to apply its update immediately.

☐ β˜† βœ‡ Dark Reading:

LofyGang Uses 100s of Malicious NPM Packages to Poison Open Source Software

By Nathan Eddy, Contributing Writer, Dark Reading β€” October 7th 2022 at 15:12
The group has been operating for over a year, promoting their tools in hacking forums, stealing credit card information, and using typosquatting techniques to target open source software flaws.

☐ β˜† βœ‡ Dark Reading:

Meta Flags Malicious Android, iOS Apps Affecting 1M Facebook Users

By Jai Vijayan, Contributing Writer, Dark Reading β€” October 7th 2022 at 14:00
Some 400 mobile apps have posed as legitimate software on Google Play and the Apple App Store over the past year, and were designed to steal Facebook user credentials.

☐ β˜† βœ‡ Dark Reading:

We Can Save Security Teams From Crushing Workloads. Will We?

By Steve Ryan, Founder & CEO, Trinity Cyber β€” October 7th 2022 at 14:00
Today, the processing of mountain-high stacks of alarms is considered "security." That system is failing customers and the cybersecurity workforce.

☐ β˜† βœ‡ Dark Reading:

CyberRatings.org Invites Industry Participation in Forthcoming Enterprise Firewall and Data Center Firewall Tests

October 7th 2022 at 13:15
Test methodologies published today, and their scope includes security effectiveness, performance, stability and reliability, and total cost of ownership.
☐ β˜† βœ‡ Dark Reading:

Sharing Knowledge at 44CON

By Jonathan Care, Contributing Writer, Dark Reading β€” October 7th 2022 at 00:11
The infosec conference named after the UK's calling code returned this year with a focus on building a healthy community.

☐ β˜† βœ‡ Dark Reading:

macOS Archive Utility Bug Lets Malicious Apps Bypass Security Checks

By Dark Reading Staff, Dark Reading β€” October 6th 2022 at 20:45
Exploit allows unsigned and unnotarized macOS applications to bypass Gatekeeper and other security, without notifying the user.

☐ β˜† βœ‡ Dark Reading:

Russian Hackers Shut Down US State Government Websites

By Dark Reading Staff, Dark Reading β€” October 6th 2022 at 19:56
Russian-speaking cyberattackers boast they are behind disruption of Colorado, Kentucky, and Mississippi government websites.

☐ β˜† βœ‡ Dark Reading:

US Consumers Are Finally Becoming More Security & Privacy Conscious

By Jai Vijayan, Contributing Writer, Dark Reading β€” October 6th 2022 at 18:30
The trend, spotted by Consumer Reports, could mean good news for organizations struggling to contain remote work challenges.

☐ β˜† βœ‡ Dark Reading:

Hackers Have It Out for Microsoft Email Defenses

By Tara Seals, Managing Editor, News, Dark Reading β€” October 6th 2022 at 15:35
Cybercriminals are focusing more and more on crafting special email attacks that evade Microsoft Defender and Office security.

☐ β˜† βœ‡ Dark Reading:

Russia-Linked Cybercrime Group Hawks Combo of Malicious Services With LilithBot

By Elizabeth Montalbano, Contributor, Dark Reading β€” October 6th 2022 at 15:15
The malware-as-a-service group Eternity is selling a one-stop shop for various malware modules it's been distributing individually via a subscription model on Telegram.

☐ β˜† βœ‡ Dark Reading:

School Is in Session: 5 Lessons for Future Cybersecurity Pros

By Chris Jacob, VP, Threat Intelligence Engineering at ThreatQuotient β€” October 6th 2022 at 14:00
Opportunities in the field continue to grow β€” and show no signs of slowing down.

☐ β˜† βœ‡ Dark Reading:

7 IoT Devices That Make Security Pros Cringe

By Ericka Chickowski, Contributing Writer, Dark Reading β€” October 6th 2022 at 13:15
A look at everything from truly dumb smart devices to cool-looking IoT tech with huge cybersecurity and privacy implications.

☐ β˜† βœ‡ Dark Reading:

New SonicWall Survey Data Reveals 91% of Organizations Fear Ransomware Attacks in 2022

October 6th 2022 at 13:13
Amid an economic downturn, cybersecurity staffing shortages, and endless cyberattacks, financially motivated attacks are the top concern among IT professionals.
☐ β˜† βœ‡ Dark Reading:

Contrast Security Launches Expanded Security Testing Tools for JavaScript and Popular Angular, React, and jQuery Frameworks

October 6th 2022 at 13:04
New language and framework support empowers developers to analyze front-end code for vulnerabilities throughout the development lifecycle.
☐ β˜† βœ‡ Dark Reading:

Relentless Russian Cyberattacks on Ukraine Raise Important Policy Questions

By Tara Seals, Managing Editor, News, Dark Reading β€” October 5th 2022 at 21:44
Microsoft cybersecurity executive John Hewie explained cyberwar developments and what they mean for Western democratic policy going forward.

☐ β˜† βœ‡ Dark Reading:

Ikea Smart Light System Flaw Lets Attackers Turn Bulbs on Full Blast

By Dark Reading Staff, Dark Reading β€” October 5th 2022 at 20:00
With just one malformed Zigbee frame, attackers could take over certain Ikea smart lightbulbs, leaving users unable to turn the lights down.

☐ β˜† βœ‡ Dark Reading:

CISA: Multiple APT Groups Infiltrate Defense Organization

By Robert Lemos, Contributing Writer, Dark Reading β€” October 5th 2022 at 19:25
Advanced attackers gained access to Microsoft Exchange services, conducted searches of email, and used an open source toolkit to collect data from the network for nearly a year.

☐ β˜† βœ‡ Dark Reading:

Secure Your Application Layer, Secure Your Business

October 5th 2022 at 18:00
Users and malicious actors interact with your business through the application layer. Build trust in your software by securing this first line of defense.
☐ β˜† βœ‡ Dark Reading:

NullMixer Dropper Delivers a Multimalware Code Bomb

By Dark Reading Staff, Dark Reading β€” October 5th 2022 at 17:45
In one shot, Trojan dropper NullMixer installs a suite of downloaders, banking Trojans, stealers, and spyware on victims' systems.

☐ β˜† βœ‡ Dark Reading:

Giving Away the Keys to Your Backups? Here’s How to Keep Out Hackers

By John Anthony Smith, Chief Listening Officer, CEO, & Founder, Conversant Group/Fenix 24 β€” October 5th 2022 at 17:00
As threat actors' sophistication has grown dramatically in the last few years, organizations haven't kept up with implementing the necessary countermeasure controls.

☐ β˜† βœ‡ Dark Reading:

NetSPI Raises $410 Million in Growth Funding from KKR

October 5th 2022 at 15:12
New investment to fuel the offensive security leader's record-breaking growth and innovation pipeline.
☐ β˜† βœ‡ Dark Reading:

7 Practical Considerations for Effective Threat Intelligence

By Steve Durbin, CEO, Information Security Forum β€” October 5th 2022 at 14:00
If your security team is considering, planning, building, or operating a threat intelligence capability, this advice can help.

☐ β˜† βœ‡ Dark Reading:

Why Don't CISOs Trust Their Employees?

By Alex Romero, Co-Founder and COO, Constella Intelligence β€” October 5th 2022 at 14:00
Executives fear "malicious insiders" as top cyber threat to companies, research shows. Reasonable steps to secure and monitor systems may prevent reputational damage but are not enough.

☐ β˜† βœ‡ Dark Reading:

RatMilad Spyware Scurries onto Enterprise Android Phones

By Elizabeth Montalbano, Contributor, Dark Reading β€” October 5th 2022 at 13:01
A novel mobile malware found lurking behind a phone-spoofing app is being distributed via Telegram and a dedicated website, in a broad operation to monitor corporate victims.

☐ β˜† βœ‡ Dark Reading:

The Insecurities of Cybersecurity Success

By Edge Editors, Dark Reading β€” October 4th 2022 at 22:35
Becoming a big wheel doesn't have to cost your happiness, but grind culture makes that likely.

☐ β˜† βœ‡ Dark Reading:

Exposure Management? Understanding the Attacker Takes Center Stage

By Robert Lemos, Contributing Writer, Dark Reading β€” October 4th 2022 at 21:48
Announcing its exposure management platform, Tenable joins other companies in offering ways β€” such as attack surface management β€” to look at business networks through the eyes of attackers.

☐ β˜† βœ‡ Dark Reading:

Microsoft Updates Mitigation for Exchange Server Zero-Days

By Jai Vijayan, Contributing Writer, Dark Reading β€” October 4th 2022 at 20:27
Researchers had discovered that Microsoft's original mitigation steps for the so-called "ProxyNotShell" flaws was easily bypassed.

☐ β˜† βœ‡ Dark Reading:

Aussie Telco Telstra Breached, Reportedly Exposing 30,000 Employees' Data

By Dark Reading Staff, Dark Reading β€” October 4th 2022 at 17:55
The Telstra cyber incident comes just weeks after its main rival Optus suffered a major compromise of its customer database.

☐ β˜† βœ‡ Dark Reading:

Former NSA Employee Faces Death Penalty for Selling Secrets

By Dark Reading Staff, Dark Reading β€” October 4th 2022 at 17:10
Suspect allegedly thought he was swapping secrets with a foreign government for crypto β€” but the contact turned out to be an FBI agent.

☐ β˜† βœ‡ Dark Reading:

Workforce Data Privacy in the Modern Work Era

By Ramon Chen, Chief Product Officer, ActivTrak β€” October 4th 2022 at 17:00
It takes culture as well as individual and corporate responsibilities to ensure workforce data privacy and compliance.

☐ β˜† βœ‡ Dark Reading:

Steam Gaming Phish Showcases Browser-in-Browser Threat

By Elizabeth Montalbano, Contributor, Dark Reading β€” October 4th 2022 at 14:37
Attackers are using the recently emerged browser-in-the-browser phishing technique to steal accounts from Valve's popular gaming platform, but it's a warning shot to businesses.

☐ β˜† βœ‡ Dark Reading:

More Than 30% of All Malicious Attacks Target Shadow APIs

October 4th 2022 at 14:30
New research spotlights how attackers are capitalizing on API-driven innovation.
☐ β˜† βœ‡ Dark Reading:

Eclypsium Raises Series B to Protect Digital Supply Chain As Attacks Grow

October 4th 2022 at 14:26
The new round highlights market demand to protect global businesses from soaring breaches through supply chains of critical hardware, devices, firmware, and software.
☐ β˜† βœ‡ Dark Reading:

Aryaka Delivers Zero-Trust WAN Based on Unified SASE Architecture

October 4th 2022 at 14:11
The new offering integrates firewall-as-a-service and secure web gateway into cloud-managed networking and security services.
❌