darkreading

Public RSS feed

Efficiency is the name of the game for the security operations center — and 91% of cybersecurity pros say artificial intelligence and machine learning are winning that game.
Posted: November 20, 2024, 9:27 pm
In US Senate testimony, a CrowdStrike exec explained how this advanced persistent threat penetrated telcos in Asia and Africa, gathering SMS messages, unique identifiers, and other metadata along the way.
Posted: November 20, 2024, 8:35 pm
Cybersecurity investigators found the leaked data to be information from a third party, not Ford itself, that is already accessible to the public and not sensitive in nature.
Posted: November 20, 2024, 6:10 pm
Though information regarding the exploits is limited, the company did report that Intel-based Mac systems have been targeted by cybercriminals looking to exploit CVE-2024-44308 and CVE-2024-44309.
Posted: November 20, 2024, 3:05 pm
If the US wants to maintain its lead in cybersecurity, it needs to make the tough funding decisions that are demanded of it.
Posted: November 20, 2024, 3:00 pm
An elusive, sophisticated cybercriminal group has used known and zero-day vulnerabilities to compromise more than 20,000 SOHO routers and other IoT devices so far, and then puts them up for sale on a residential proxy marketplace for state-sponsored cyber-espionage actors and others to use.
Posted: November 20, 2024, 2:14 pm
Recent backdoor implants and cyber-espionage attacks on their supply chains have African organizations looking to diversify beyond Chinese, American tech vendors.
Posted: November 20, 2024, 8:00 am
DeepTempo's Tempo is a deep learning-based Snowflake native app that allows organizations to detect and respond to evolving threats directly within their Snowflake environments.
Posted: November 20, 2024, 5:52 am
RIIG is a risk intelligence and cybersecurity solutions provider offering open source intelligence solutions designed for zero-trust environments.
Posted: November 20, 2024, 12:50 am
The secure coding curriculum, funded by a $2.5 million grant, is available for students and professionals at all stages of their careers.
Posted: November 20, 2024, 12:33 am
Since surfacing in August, the likely LockBit variant has claimed more than two dozen victims and appears poised to strike many more.
Posted: November 19, 2024, 9:48 pm
In further proof of the professionalization of Russian cybercriminal groups, ransomware gangs have been posting job ads for security positions such as pen testers, looking to boost their ransomware deployment operations.
Posted: November 19, 2024, 6:54 pm
According to the unsealed criminal charges, the operation is believed to have running for nearly four years.
Posted: November 19, 2024, 6:09 pm
The company says no sensitive data was stolen, but federal agencies claim otherwise. CISA and FBI sources said attackers accessed all records of specific customers and the private communications of targeted individuals.
Posted: November 19, 2024, 4:27 pm
Individual companies and entire industries alike must take responsibility for protecting customer data — and doing the right thing when they fail.
Posted: November 19, 2024, 3:00 pm
Freshly released court documents reveal new details on controversial Israeli spyware firm's operations.
Posted: November 18, 2024, 10:16 pm
Experimental counter-offensive system responds to malicious AI probes with their own surreptitious prompt-injection commands.
Posted: November 18, 2024, 10:06 pm
Posted: November 18, 2024, 9:44 pm
Posted: November 18, 2024, 9:14 pm
Other Biden administration appointees at CISA will also submit their resignations on Jan. 20, as the cyber-defense agency prepares for President-elect Trump's new DHS director.
Posted: November 18, 2024, 8:43 pm
A vulnerability found in the Really Simple Security plug-in allows an attacker to remotely gain access to any account on an affected website, including the administrator, when 2FA is enabled.
Posted: November 18, 2024, 8:14 pm
Of the numerous victims, at least three refused to pay the demanded ransom, with the rest seemingly in talks with the cybercriminal group.
Posted: November 18, 2024, 7:49 pm
Feeling creative? Submit your caption and our panel of experts will reward the winner with a $25 gift card.
Posted: November 18, 2024, 6:02 pm
The tangle of user-built tools is formidable to manage, but it can lead to a greater understanding of real-world business needs.
Posted: November 18, 2024, 6:00 pm
The security vendor's Expedition firewall appliance's PAN-OS interface tool has racked up four critical security vulnerabilities under active attack in November, leading it to advise customers to update immediately and take them off the Internet.
Posted: November 18, 2024, 5:11 pm
Companies that recognize current market opportunities — from the need to safely implement revolutionary technology like AI to the vast proliferation of cyber threats — have remarkable growth prospects.
Posted: November 18, 2024, 3:00 pm
The voluntary recommendations from the Department of Homeland Security cover how artificial intelligence should be used in the power grid, water system, air travel network, healthcare, and other pieces of critical infrastructure.
Posted: November 18, 2024, 1:38 pm
Email at many organizations has stopped working; the tech giant has advised users who are facing the issue to uninstall the updates so that it can address flaw.
Posted: November 15, 2024, 10:52 pm
According to Mozilla, users have a lot more power to manipulate ChatGPT than they might realize. OpenAI hopes those manipulations remain within a clearly delineated sandbox.
Posted: November 15, 2024, 10:21 pm
In the future, the cybersecurity landscape likely will depend not only on the ability of federal workforces to protect their agencies but also on their capacity to continuously develop and sharpen those skills.
Posted: November 15, 2024, 3:00 pm
A new report from the Open Software Supply Chain Attack Reference (OSC&R) team provides a framework to reduce how much vulnerable software reaches production.
Posted: November 15, 2024, 2:36 pm
Given increased tensions with China over tariffs, companies could see a shift in attacks, but also fewer regulations and a run at a business-friendly federal privacy law.
Posted: November 15, 2024, 1:00 pm
The proposed rules codify existing temporary directives requiring pipeline and railroad operators to report cyber incidents and create cyber-risk management plans.
Posted: November 15, 2024, 12:38 am
Frenos offers a zero-impact, continuous security assessment platform for operational technology environments.
Posted: November 14, 2024, 11:51 pm
Several versions of PostgreSQL are impacted, and customers will need to upgrade in order to patch.
Posted: November 14, 2024, 9:53 pm
In addition to his prison sentence, he will have to pay more than $1 million in restitution to his victims.
Posted: November 14, 2024, 8:50 pm
As alerts pile up, the complexity can overwhelm security professionals, allowing real threats to be missed. This is where vendors must step up.
Posted: November 14, 2024, 6:00 pm
Cloud service providers are getting better at protecting data, pushing adversaries to develop new cloud ransomware scripts to target PHP applications, a new report says.
Posted: November 14, 2024, 5:30 pm
If the government truly wants to protect the US's most vital assets, it must rethink its cybersecurity policies and prioritize proactive, coordinated, and enforceable measures.
Posted: November 14, 2024, 3:00 pm
Less-experienced users of Microsoft's website building platform may not understand all the implications of the access controls in its low- or no-code environment.
Posted: November 14, 2024, 1:00 pm
APT Wirte is doing double duty, adding all manner of supplemental malware to gain access, eavesdrop, and wipe data, depending on the target.
Posted: November 14, 2024, 7:00 am
Posted: November 13, 2024, 10:46 pm
The China-affiliated group is using the highly modular DeepData framework to target organizations in South Asia.
Posted: November 13, 2024, 10:39 pm
Among the top exploited zero-day vulnerabilities were bugs found in systems from Citrix and Cisco.
Posted: November 13, 2024, 10:34 pm
Posted: November 13, 2024, 10:32 pm
The consolidation folds Cybereason's endpoint detection and response (EDR) platform into Trustwave's managed security services offerings, such as managed detection and response (MDR).
Posted: November 13, 2024, 10:23 pm