darkreading

Public RSS feed

Cyberattacks tripled over the past year in Israel, making it the most targeted nation in 2023, as cyber operations become a standard part of military conflicts and global protests.
Posted: April 16, 2024, 6:00 am
A third-party telephony service provider for Cisco Duo falls prey to social engineering, and the company advises customer vigilance against subsequent phishing attacks.
Posted: April 15, 2024, 8:21 pm
Roku assures customers that no financial information was stolen and that any purchases made through user accounts have been reimbursed.
Posted: April 15, 2024, 7:43 pm
A sophisticated threat actor is leveraging the bug to deploy a Python backdoor for stealing data and executing other malicious actions.
Posted: April 15, 2024, 7:28 pm
Handala threat group claims to have hacked radar systems in Israel as tensions rise between the two nations.
Posted: April 15, 2024, 4:07 pm
A Russian-language cyberattack campaign impersonates legitimate game operations to spread various cross-platform infostealers.
Posted: April 15, 2024, 2:35 pm
The responsibility to hold Microsoft accountable for abiding by its self-proclaimed principles shouldn't fall to customers and competition authorities.
Posted: April 15, 2024, 2:00 pm
But just how the government differentiates its platform from similar private-sector options remains to be seen.
Posted: April 12, 2024, 8:50 pm
Akamai joins a growing list of security vendors aiming to strengthen companies' DNS defenses.
Posted: April 12, 2024, 8:39 pm
Our collection of the most relevant reporting and industry perspectives for those guiding cybersecurity strategies and focused on SecOps. Also included: facing hard truths in software security, and the latest guidance from the NSA.
Posted: April 12, 2024, 7:20 pm
Though Federal Civilian Executive Branch (FCEB) agencies are the primary targets, CISA encourages all organizations to up their security, given the high risk.
Posted: April 12, 2024, 6:09 pm
Microsoft, Google, and Simbian each offers generative AI systems that allow security operations teams to use natural language to automate cybersecurity tasks.
Posted: April 12, 2024, 3:46 pm
Attacks on critical infrastructure are ramping up — but organizations now have the knowledge and tools needed to defend against them.
Posted: April 12, 2024, 2:00 pm
With stores of mega-corporate business intelligence, a Sisense compromise could potentially mushroom into supply chain cyberattack disaster, experts fear.
Posted: April 11, 2024, 10:17 pm
Project behind the Rust programming language asserted that any calls to a specific API would be made safe, even with unsafe inputs, but researchers found ways to circumvent the protections.
Posted: April 11, 2024, 8:08 pm
North Korean hackers break ground with new exploitation techniques for Windows and macOS.
Posted: April 11, 2024, 8:02 pm
Led by industry veterans Gadi Evron and Sounil Yu, the new company lets organizations adjust how much information LLMs provide based on the user's role and responsibilities.
Posted: April 11, 2024, 7:34 pm
Attackers have compromised an 8-year-old version of the cloud platform to distribute various malware that can take over infected systems.
Posted: April 11, 2024, 6:22 pm
In new threat notification information, Apple singled out Pegasus vendor NSO Group as a culprit in mercenary spyware attacks.
Posted: April 11, 2024, 6:19 pm
A machine learning bill of materials (MLBOM) framework can bring transparency, auditability, control, and forensic insight into AI and ML supply chains.
Posted: April 11, 2024, 2:00 pm
Phony call center company conducted online fraud and other Internet scams.
Posted: April 11, 2024, 12:48 pm
Following the Volt Typhoon attacks on critical infrastructure in the region by China, the US reportedly will share cybersecurity threat information with both countries.
Posted: April 10, 2024, 11:00 pm
Much of the open source code embedded in enterprise software stacks comes from small, under-resourced, volunteer-run projects.
Posted: April 10, 2024, 10:22 pm
Prioritizing security and user experience will help you build a robust and reliable authentication system for your business.
Posted: April 10, 2024, 8:19 pm
Agency encourages broader use of encryption, data-loss prevention, as well as data rights management to safeguard data, networks, and users.
Posted: April 10, 2024, 8:06 pm
It's finally happening: Rather than just for productivity and research, threat actors are using LLMs to write malware. But companies need not worry just yet.
Posted: April 10, 2024, 6:48 pm
Though a municipal agency assures the public that few are affected, hundreds have their data held ransom for $100,000 by the ransomware gang.
Posted: April 10, 2024, 5:42 pm
In a cyberattack more reminiscent of the 2010s, a seemingly lone hacker fleeced a major corporation for millions of open customer records.
Posted: April 10, 2024, 4:01 pm
Various anti-detection features, including the use of the ScrubCrypt antivirus-evasion tool, fuel an attack that aims to take over Microsoft Windows machines.
Posted: April 10, 2024, 2:45 pm
Global organizations and geopolitical entities must adopt new strategies to combat the growing sophistication in attacks that parallel the complexities of our new geopolitical reality.
Posted: April 10, 2024, 2:00 pm
A cheat sheet for all of the most common techniques hackers use, and general principles for stopping them.
Posted: April 10, 2024, 5:00 am
Google has integrated Mandiant's security offerings into its AI platform to detect, stop, and remediate cybersecurity attacks as quickly as possible.
Posted: April 10, 2024, 12:22 am
The device management company introduced a Fleet Hardening Score and Privilege Escalation (the good kind) to its endpoint security platform for Apple devices.
Posted: April 9, 2024, 11:30 pm
Microsoft patched a record number of 147 new CVEs this month, though only three are rated "Critical."
Posted: April 9, 2024, 9:13 pm
Scans showed that 91,000 devices are exposed and at risk for unauthorized access and TV set takeover.
Posted: April 9, 2024, 8:44 pm
As more electric vehicles are sold, the risk to compromised charging stations looms large alongside the potential for major cybersecurity exploits.
Posted: April 9, 2024, 6:31 pm
Distributed denial-of-service attacks still plague the enterprise, but adding preventive measures can reduce their impact.
Posted: April 9, 2024, 5:51 pm
We are potentially encroaching on a water supply crisis if data center operators, utilities, and the government don't implement preventative measures now.
Posted: April 9, 2024, 5:00 pm
The company is asking users to retire several network-attached storage (NAS) models to avoid compromise through a publicly available exploit that results in backdooring.
Posted: April 9, 2024, 4:32 pm
We need more than "do-it-yourself" approaches to threats that clearly rise to the level of national security issues.
Posted: April 9, 2024, 2:00 pm
Novacoast's Apex Program prepares individuals with visual impairments for cybersecurity careers.
Posted: April 9, 2024, 1:50 pm
With a complex attack chain and using Telegram for its command and control, CoralRaider targets victims in Asian countries — and appears to have accidentally infected itself as well.
Posted: April 9, 2024, 4:01 am