darkreading
Name That Toon Contest
3 weeks hence
[Virtual Event] Anatomy of a Data Breach: What to Do if it Happens to You
1 week 6 days hence
Pakistan Spies on Afghan Finance Ministry With Xeno RAT
11 hours 1 minute ago
Despite broadly connected digital infrastructure, standard fare TTPs are enough to cause trouble for Afghanistan's porous cybersecurity.
Nate Nelson
Attackers Use AI to Automate EDR Evasion Testing
17 hours 28 minutes ago
Python scripts were used to test malware against endpoint detection and response agents from Sophos, CrowdStrike, and Windows Defender.
Alexander Culafi
Tropical Blend: Cyber & Politics Ramp Up Across Latin America
19 hours 9 minutes ago
China-linked espionage groups have attacked at least a dozen nations in the region, gathering information on maritime shipping, oil production, and other geopolitical interests.
Robert Lemos
Cyber Insurance Rates Are Dropping, but Exclusions Widen
19 hours 51 minutes ago
Cyber insurance coverage is slowly changing, and some policies may not provide coverage for social engineering attacks like ClickFix.
Rob Wright
Coding Gaffe Exposes Microsoft 365 Accounts to Widespread Takeover
20 hours 1 minute ago
A disabled security setting meant to protect authentication across Android versions of key apps like Word, PowerPoint, and Excel paved the way for attackers to steal logins and data.
Elizabeth Montalbano
Malicious Notifications Could Trick Google Gemini Users
1 day 3 hours ago
A prompt injection flaw in Google Gemini's voice assistant let attackers hide malicious commands in notifications, enabling social engineering and more.
Alexander Culafi
Global Stock Exchange Hit by Monthslong Email Campaign
1 day 5 hours ago
A threat actor got a near-continuous view into an influential finance executive's email inbox, thanks to clever use of legitimate, native Windows tools.
Nate Nelson
Zoom CISO: AI as a Security Enabler, Not Role-Replacer
1 day 17 hours ago
Zoom CISO Sandra McLeod discusses the challenges of securing a global communication platform, the promise of AI-driven security workflows, and her advice for aspiring cybersecurity leaders.
Kristina Beek
FBI-Flagged Phishing Kit Kali365 Expands Its Reach
1 day 17 hours ago
Once targeting just Microsoft 365, the phishing-as-a-service platform now aims at AWS, Okta, and Russian platforms, while relying on device code phishing.
Jai Vijayan
DriveSurge Hijacks Thousands of Sites for ClickFix, FakeUpdate Attacks
1 day 18 hours ago
A sneaky, wide-scale IAB operation uses a malicious traffic distribution system (TDS) to redirect visitors of trusted websites to ones that deliver malware.
Elizabeth Montalbano
China Uses Dual-Method Cyberattack on Czech Orgs
1 day 19 hours ago
China is stealing data from high-value targets via a sneaky, double-layer spear-phishing campaign that includes the Azureveil malware.
Alexander Culafi
Securing AI Agents Before They Go Rogue Is Next to Impossible
1 day 19 hours ago
High-autonomy agents with broad permissions and unfettered access are a recipe for disaster, and enterprises need to act now before they become the next horror story.
Rob Wright
[An RX Global Event] Infosecurity Europe
2 days 1 hour ago
Beyond Assume-Breach: How AI-Native Security Will Reshape Enterprise Defense
2 days 3 hours ago
Twenty years after Dark Reading launched, we're looking ahead at what's next for enterprise security. Spoiler: It's hyper-segmented, AI-orchestrated, and way more sophisticated than your dad's firewall.
Fahmida Y. Rashid, Tara Seals
Anthropic to Open Mythos AI to EU's ENISA
2 days 17 hours ago
The European security agency's entry to Project Glasswing is the result of "strong bilateral cooperation" between the European Commission and Anthropic.
Jai Vijayan
Microsoft's Zero-Day Legal Threats Spark Backlash
2 days 20 hours ago
After a disgruntled security researcher published several zero-day exploits in recent weeks, Microsoft seemingly indicated criminal charges were in order.
Rob Wright
Patch Now: Another Palo Alto Auth Bypass Bug Under Active Exploit
3 days ago
Exploiting the PAN-OS GlobalProtect VPN vulnerability requires certain conditions, but adversaries have done so in two attack waves that started in mid-May.
Elizabeth Montalbano
Checked
1 hour 2 minutes ago
Public RSS feed
darkreading feed