darkreading
Name That Toon Contest
4 days 19 hours hence
Stressors, AI Forcing Changes to Cybersecurity Teams
2 days 2 hours ago
As threats proliferate and AI complicates cybersecurity, CISOs say the job is getting harder, but more companies still want cybersecurity expertise, if even on a part-time basis.
Robert Lemos
Novo Nordisk Breach Exposes Software Development Pipeline Risk
2 days 19 hours ago
A leaked GitHub token underscores what most organizations get wrong: Treating secrets management as a tooling problem rather than an identity problem.
Jai Vijayan
Operation Escaneo Signals Shift in LatAm Threat Landscape
2 days 20 hours ago
The threat group's curious business model may combine opportunistic monetization alongside intel collection, without much coordination between the two.
Alexander Culafi
FIFA Bug Exposes World Cup Streams to Remote Takeover
2 days 21 hours ago
A hacker could have "Rickrolled" the World Cup — or worse — thanks to FIFA's unenforced Entra access controls.
Nate Nelson
Salesforce Data Thefts Continue via Klue App Compromise
2 days 23 hours ago
Klue's Battlecards is now the third integrated application that has been compromised to steal customers' Salesforce data, and victims include Huntress, the cybersecurity vendor.
Rob Wright
[Virtual Event] Anatomy of a Data Breach: What to Do if it Happens to You
3 days ago
Get Out of Security Debt by Tackling the Exposure Problem
3 days 2 hours ago
Teams digging out of security debt need to answer only two simple questions: Which vulnerabilities in our systems are exposed, and how long should they stay that way?
Chris Wysopal
EU Gets a Head Start in Developing 6G Network Security
3 days 8 hours ago
"Shield-6G" will combine AI threat detection, digital twins, honeypots, and more, to help carriers protect 6G networks against the threats of tomorrow.
Nate Nelson
INC Ransomware Thrives by Mastering the Basics
3 days 20 hours ago
And one of those basics is focusing on sectors where a ransomware disruption creates immediate pressure to pay up, like with healthcare.
Alexander Culafi
Sweeping Credential-Harvesting Heist Compromises 30K+ Fortinet Devices
4 days 1 hour ago
Attackers are actively targeting various sectors across nearly 200 countries and already have compiled a list of working credentials for tens of thousands of compromised devices.
Elizabeth Montalbano
UK Social Media Ban for Minors Has Privacy Experts Worried
4 days 7 hours ago
The UK will ban adolescents under 16 years old from user-to-user social media platforms, despite age verification issues and privacy concerns.
Robert Lemos
Fileless Phantom Stealer Targets Browser Credentials
4 days 17 hours ago
In addition to executing entirely in memory, the malware's infection chain incorporates other anti-analysis techniques designed to evade detection.
Jai Vijayan
Security Community Slams US Ban on Exporting Mythos, Fable
4 days 17 hours ago
An open letter signed by dozens of security experts asked the government to reverse export restrictions on Anthropic's Claude Fable 5 and Mythos 5 models.
Alexander Culafi
SprySOCKS Windows Variant Abuses Kernel Drivers to Evade Detection
4 days 19 hours ago
FishMonger, a China-nexus threat group, has deployed an undocumented version of the Linux backdoor against government targets in Honduras, Taiwan, Thailand, and Pakistan.
Rob Wright
Rokarolla Android Trojan Levels Up to Full Device Control, Persistence
4 days 22 hours ago
The emerging malware, spread via fake TikTok and Chrome downloads, has evolved by combining banking fraud with extensive device surveillance and remote control.
Elizabeth Montalbano
'Lorem Ipsum' Malware Pivots to ClickFix Delivery
5 days ago
New analysis shows the campaign, which uses compromised WordPress sites, may be linked to the ransomware and data extortion group Vice Society.
Jai Vijayan
HTTP/2 Bomb Attacks Put Telcos, Healthcare Orgs at Risk
5 days 20 hours ago
The denial-of-service (DoS) exploit takes advantage of two features in HTTP/2 that were designed to save Internet bandwith, not power massive amplification attacks.
Nate Nelson
Copilot 'SearchLeak' Attack Allows 1-Click Data Theft
5 days 20 hours ago
The critical, three-stage attack is now patched, but it's part of a new group of AI prompt-injection issues that use hidden URLs and other variables.
Alexander Culafi
Checked
49 minutes 46 seconds ago
Public RSS feed
darkreading feed