darkreading
Name That Toon Contest
1 day 16 hours hence
Apple's MacOS Gap Lets Users Disable Security Tools
6 hours 11 minutes ago
Attackers can exploit the issue to disable security and integrated browser tools without needing administrator privileges or kernel exploits.
Jai Vijayan
Scope of Salesforce Attacks Expands as Icarus Leaks Data
21 hours 26 minutes ago
More victims have emerged after attackers breached application vendor Klue and used its OAuth tokens to steal customers' Salesforce data.
Rob Wright
'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows
22 hours 54 minutes ago
The CI/CD workflow weakness affects Microsoft's Azure Sentinel, Google's AI Agent Development Kit, Apache's Doris analytics database, Cloudflare's Workers SDK, and Python Software Foundation's Black.
Alexander Culafi
SocGholish Takedown Highlights Malicious TDS Threats
1 day 4 hours ago
SocGholish uses traffic distribution systems (TDSs) to provide initial access into victims' networks for cybercrime groups such as the notorious Evil Corp.
Rob Wright
FortiBleed Attackers Turn Firewalls Into Credential Stealers as Heists Persist
1 day 5 hours ago
The threat actors engineered a Golang-based sniffer to target 430,000 FortiGate firewalls and identify 110 million credentials in the ongoing global campaign.
Elizabeth Montalbano
DifyTap Bugs Let Attackers 'Wiretap' AI Chat Histories
1 day 20 hours ago
Four vulnerabilities allow attackers to exploit Dify, a platform for AI application building and management, to silently access and exfiltrate sensitive data.
Alexander Culafi
Crypto Heist Fueled by Elaborate Fake Reputation-Boosting Campaign
2 days 2 hours ago
Attackers are using multiple online channels — including GitHub, YouTube, and VirusTotal — to build an illusion of trust to spread a cross-platform clipboard hijacker.
Elizabeth Montalbano
He Thought He Was Secure; His Phone Number Got Stolen Anyway
2 days 3 hours ago
Threat actors can easily steal one-time passwords sent by text when they conduct a SIM swap attack. This can lead to account takeovers, so users must layer up their security measures.
Arielle Waldman
Stressors, AI Forcing Changes to Cybersecurity Teams
5 days 5 hours ago
As threats proliferate and AI complicates cybersecurity, CISOs say the job is getting harder, but more companies still want cybersecurity expertise, if even on a part-time basis.
Robert Lemos
Novo Nordisk Breach Highlights Software Development Pipeline Risk
5 days 22 hours ago
A leaked GitHub token underscores what most organizations get wrong: Treating secrets management as a tooling problem rather than an identity problem.
Jai Vijayan
Operation Escaneo Signals Shift in LatAm Threat Landscape
5 days 23 hours ago
The threat group's curious business model may combine opportunistic monetization alongside intel collection, without much coordination between the two.
Alexander Culafi
FIFA Bug Exposes World Cup Streams to Remote Takeover
5 days 23 hours ago
A hacker could have "Rickrolled" the World Cup — or worse — thanks to FIFA's unenforced Entra access controls.
Nate Nelson
Salesforce Data Thefts Continue via Klue App Compromise
6 days 1 hour ago
Klue's Battlecards is now the third integrated application that has been compromised to steal customers' Salesforce data, and victims include Huntress, the cybersecurity vendor.
Rob Wright
[Virtual Event] Anatomy of a Data Breach: What to Do if it Happens to You
6 days 3 hours ago
Get Out of Security Debt by Tackling the Exposure Problem
6 days 5 hours ago
Teams digging out of security debt need to answer only two simple questions: Which vulnerabilities in our systems are exposed, and how long should they stay that way?
Chris Wysopal
EU Gets a Head Start in Developing 6G Network Security
6 days 11 hours ago
"Shield-6G" will combine AI threat detection, digital twins, honeypots, and more, to help carriers protect 6G networks against the threats of tomorrow.
Nate Nelson
INC Ransomware Thrives by Mastering the Basics
6 days 22 hours ago
And one of those basics is focusing on sectors where a ransomware disruption creates immediate pressure to pay up, like with healthcare.
Alexander Culafi
Sweeping Credential-Harvesting Heist Compromises 30K+ Fortinet Devices
1 week ago
Attackers are actively targeting various sectors across nearly 200 countries and already have compiled a list of working credentials for tens of thousands of compromised devices.
Elizabeth Montalbano
Checked
5 hours 11 minutes ago
Public RSS feed
darkreading feed