darkreading
Please support the site operations by clicking ads.
Top Travel Sites Have Some First-Class Security Issues to Clean Up
2 years ago
Public-facing vulnerabilities, cloud sprawl, access to back-end servers are just a few of the challenges travel and hospitality companies must address.
Elizabeth Montalbano, Contributing Writer
Exploited: CISA Highlights Apache OFBiz Flaw After PoC Emerges
2 years ago
The vulnerability carries nearly the highest score possible on the CVSS scale, at 9.8, impacting a system used by major companies around the world.
Kristina Beek, Associate Editor, Dark Reading
How Telecom Vulnerabilities Can Be a Threat to Cybersecurity Posture
2 years ago
Telecom-based attacks such as SMS toll fraud and 2FA hijacking have evolved into a mainstream concern for CISOs.
Ayan Halder
Dragos Expands Asset Visibility in Latest Platform Update
2 years ago
The latest release of the Dragos Platform provide industrial and critical infrastructure organizations with complete and enriched view of their OT environment.
Dark Reading Staff
South Korean APT Exploits 1-Click WPS Office Bug, Nabs Chinese Intel
2 years ago
The most popular office software suite in China actually has two critical vulnerabilities, which allowed hackers the opportunity for remote code execution. Time to patch.
Nate Nelson, Contributing Writer
CCTV Zero-Day Exposes Critical Infrastructure to Mirai Botnet
2 years ago
CISA warned about the RCE zero-day vulnerability in AVTECH IP cameras in early August, and now vulnerable systems are being used to spread malware.
Becky Bracken, Senior Editor, Dark Reading
BlackByte Targets ESXi Bug With Ransomware to Access Virtual Assets
2 years ago
The pivot is one of several changes the groups using the malware have used in recent attacks.
Jai Vijayan, Contributing Writer
Attackers Exploit Critical Atlassian Confluence Flaw for Cryptojacking
2 years ago
Novel attack vectors leverage the CVE-2023-22527 RCE flaw discovered in January, which is still under active attack, to turn targeted cloud environments into cryptomining networks.
Elizabeth Montalbano, Contributing Writer
Hitachi Energy Vulnerabilities Plague SCADA Power Systems
2 years ago
The company has assessed four of the five disclosed vulnerabilities as being of high to critical severity.
Jai Vijayan, Contributing Writer
Manufacturing Sector Under Fire From Microsoft Credential Thieves
2 years ago
The emails impersonate well-known companies in the industry, fooling the victim into thinking they are communicating with a legitimate entity.
Dark Reading Staff
Why LLMs Are Just the Tip of the AI Security Iceberg
2 years ago
With the right processes and tools, organizations can implement advanced AI security frameworks that make hidden risks visible, enabling security teams to track and address them before impact.
Diana Kelley
Hundreds of LLM Servers Expose Corporate, Health & Other Online Data
2 years ago
LLM automation tools and vector databases can be rife with sensitive data — and vulnerable to pilfering.
Nate Nelson, Contributing Writer
Zimbabwe Trains Government Officials in Cybersecurity Skills
2 years ago
African nation's proactive approach to cybersecurity comes amid a rise in painful cyberattacks, including the breach of a major bank.
Dark Reading Staff
77% of Educational Institutions Spotted a Cyberattack Within the Last 12 Months
2 years ago
PoC Exploit for Zero-Click Vulnerability Made Available to the Masses
2 years ago
The exploit can be accessed on GitHub and makes it easier for the flaw to be exploited by threat actors.
Dark Reading Staff
Microsoft's Sway Serves as Launchpad for 'Quishing' Campaign
2 years ago
The attack is a mashup of QR codes and phishing that gets users to click on links to malicious webpages.
Dark Reading Staff
China's Volt Typhoon Exploits Zero-Day in Versa's SD-WAN Director Servers
2 years ago
So far, the threat actor has compromised at least five organizations using CVE-2024-39717; CISA has added bug to its Known Exploited Vulnerability database.
Jai Vijayan, Contributing Writer
Why Every Business Should Prioritize Confidential Computing
2 years ago
Confidential computing safeguards data in use, making it a crucial component of cloud security.
Pankaj Mendki
Threat Group 'Bling Libra' Pivots to Extortion for Cloud Attacks
2 years ago
The ShinyHunters attackers are skipping selling stolen data on hacker forums in favor of using deadline-driven ransom notes for financial gain.
Elizabeth Montalbano, Contributing Writer
Checked
10 hours 59 minutes ago
Public RSS feed
darkreading feed