darkreading
GitHub: How Code Provenance Can Prevent Supply Chain Attacks
1 year ago
Through artifact attestation and the SLSA framework, GitHub's Jennifer Schelkopf argues that at least some supply chain attacks can be stopped in their tracks.
Alexander Culafi, Senior News Writer, Dark Reading
United Natural Food's Operations Limp Through Cybersecurity Incident
1 year ago
It's unclear what kind of cyberattack occurred, but UNFI proactively took certain systems offline, which has disrupted the company's operations.
Kristina Beek, Associate Editor, Dark Reading
Poisoned npm Packages Disguised as Utilities Aim for System Wipeout
1 year ago
Backdoors lurking in legitimate-looking code contain file-deletion commands that can destroy production systems and cause massive disruptions to software supply chains.
Elizabeth Montalbano, Contributing Writer
SSH Keys: The Most Powerful Credential You're Probably Ignoring
1 year ago
SSH keys enable critical system access but often lack proper management. This security blind spot creates significant risk through untracked, unrotated credentials that persist across your infrastructure.
Durgaprasad Balakrishnan
New Trump Cybersecurity Order Reverses Biden, Obama Priorities
1 year ago
The White House put limits on cyber sanctions, killed the digital ID program, and refocused the government's cyber activities to enabling AI, rolling out post-quantum cryptography, and promoting secure software design.
Becky Bracken
OpenAI Bans ChatGPT Accounts Linked to Nation-State Threat Actors
1 year ago
The AI company's investigative team found that many accounts were using the program to engage in malicious activity around the world, such as employment schemes, social engineering, and cyber espionage.
Kristina Beek, Associate Editor, Dark Reading
'Librarian Ghouls' Cyberattackers Strike at Night
1 year ago
Since at least December, the advanced persistent threat (APT) group has been using legit tools to steal data, dodge detection, and drop cryptominers on systems belonging to organizations in Russia.
Jai Vijayan, Contributing Writer
Gartner: How Security Teams Can Turn Hype Into Opportunity
1 year ago
During the opening keynote at Gartner Security & Risk Management Summit 2025, analysts weighed in on how CISOs and security teams can use security fervor around AI and other tech to the betterment of their security posture.
Alexander Culafi, Senior News Writer, Dark Reading
SIEMs Missing the Mark on MITRE ATT&CK Techniques
1 year ago
CardinalOps' report shows that organizations are struggling to keep up with the evolution of the latest threats while a significant number of detection rules remain non-functional.
Kristina Beek, Associate Editor, Dark Reading
Next-Gen Developers Are a Cybersecurity Powder Keg
1 year ago
AI coding tools promise productivity but deliver security problems, too. As developers embrace "vibe coding," enterprises face mounting risks from insecure code generation that security teams can't keep pace with.
Pieter Danhieux
China-Backed Hackers Target SentinelOne in 'PurpleHaze' Attack Spree
1 year ago
Known threat groups APT15 and UNC5174 unleashed attacks against SentinelOne and more than 70 other high-value targets, as part of ongoing cyber-espionage and other malicious activity involving ShadowPad malware.
Elizabeth Montalbano, Contributing Writer
Cutting-Edge ClickFix Tactics Snowball, Pushing Phishing Forward
1 year ago
Several widespread ClickFix campaigns are underway, bent on delivering malware to business targets, and they represent a new level of phishing sophistication that defenders need to be prepared for, researchers warn.
Tara Seals
F5 Acquires Agentic AI Security Startup Fletch
1 year ago
Agentic AI technology will be integrated into the recently launched F5 Application Delivery and Security Platform.
Jeffrey Schwartz
BADBOX 2.0 Targets Home Networks in Botnet Campaign, FBI Warns
1 year ago
Though the operation was partially disrupted earlier this year, the botnet remains active and continues to target connected Android devices.
Kristina Beek, Associate Editor, Dark Reading
Docuseries Explores Mental, Physical Hardships of CISOs
1 year ago
During "CISO: The Worst Job I Ever Wanted," several chief information security officers reveal how difficult it is to be in a role that, despite being around for decades, remains undefined.
Arielle Waldman
Synthetic Data Is Here to Stay, but How Secure Is It?
1 year ago
Synthetic data offers organizations a way to develop AI while maintaining privacy compliance but requires careful management to prevent re-identification risks and ensure model accuracy.
Hadi Chami
MSFT-CrowdStrike 'Rosetta Stone' for Naming APTs: Meh?
1 year ago
Microsoft and CrowdStrike announced an effort to deconflict the overlapping names of threat groups and reduce confusion for companies, but we've been here before.
Robert Lemos, Contributing Writer
Prep for Layoffs Before They Compromise Security
1 year ago
Mass layoffs create cybersecurity vulnerabilities through dormant accounts and disgruntled employees.
Mercedes Cardona
SecOps Teams Need to Tackle AI Hallucinations to Improve Accuracy
1 year ago
The risks associated with AI embedded into threat detection and response tools can't be completely eradicated, but SecOps teams can take steps to at least limit the effects.
Arielle Waldman
Checked
9 hours 44 minutes ago
Public RSS feed
darkreading feed