darkreading
Iran MOIS Phishes 50+ Embassies, Ministries, Int'l Orgs
8 hours 5 minutes ago
The Homeland Justice APT tried spying on countries and organizations from six continents, using more than 100 hijacked email accounts.
Nate Nelson, Contributing Writer
Japan, South Korea Take Aim at North Korean IT Worker Scam
13 hours 5 minutes ago
With the continued success of North Korea's IT worker scams, Asia-Pacific nations are working with private firms to blunt the scheme's effectiveness.
Robert Lemos, Contributing Writer
Russia's APT28 Targets Microsoft Outlook With 'NotDoor' Malware
17 hours 16 minutes ago
The notorious Russian state-sponsored hacking unit, also known as Fancy Bear, is abusing Microsoft Outlook for covert data exfiltration.
Rob Wright
Cloudflare Holds Back the Tide on 11.5Tbps DDoS Attack
17 hours 30 minutes ago
It's the equivalent of watching more than 9,350 full-length HD movies or streaming 7,480 hours of high-def video nonstop in less than a minute.
Kristina Beek
Hacked Routers Linger on the Internet for Years, Data Shows
21 hours 9 minutes ago
While trawling Internet scan data for signs of compromised infrastructure, researchers found that asset owners may not know for years their devices had been hacked.
Fahmida Y. Rashid
WhatsApp Bug Anchors Targeted Zero-Click iPhone Attacks
1 day ago
A "sophisticated" attack that also exploits an Apple zero-day flaw is targeting a specific group of iPhone users, potentially with spyware.
Elizabeth Montalbano, Contributing Writer
Varonis Acquires Email Security Provider SlashNext to Enhance BEC Defenses
1 day 2 hours ago
Varonis plans to integrate SlashNext's advanced phishing, BEC, and social engineering attack protection capabilities into its data security platform.
Jeffrey Schwartz
UAE to Implement Cyber Education Initiative
1 day 8 hours ago
The initiative will be tailored to students and their growth in cybersecurity preparedness.
Kristina Beek
Amazon Stymies APT29 Credential Theft Campaign
1 day 17 hours ago
A group linked to Russian intelligence services redirected victims to fake Cloudflare verification pages and exploited Microsoft's device code authentication flow.
Jai Vijayan, Contributing Writer
WordPress Woes Continue Amid ClickFix Attacks, TDS Threats
1 day 19 hours ago
Vulnerable and malicious plug-ins are giving threat actors the ability to compromise WordPress sites and use them as a springboard to a variety of cyber threats and scams.
Rob Wright
Zscaler, Palo Alto Networks Breached via Salesloft Drift
1 day 20 hours ago
Two major security firms suffered downstream compromises as part of a large-scale supply chain attack involving Salesloft Drift, a marketing SaaS application.
Alexander Culafi
Jaguar Land Rover Shuts Down in Scramble to Secure 'Cyber Incident'
1 day 21 hours ago
The luxury automaker said its retail and production activities have been "severely disrupted."
Kristina Beek
Hackers Are Sophisticated & Impatient — That Can Be Good
2 days ago
You can't negotiate with hackers from a place of fear — but you can turn their urgency against them with the right playbook, people, and preparation.
Ensar Seker
NIST Enhances Security Controls for Improved Patching
2 days 1 hour ago
The US National Institute of Standards and Technology released Security and Privacy Control version 5.2.0 to help organizations be more proactive regarding patching.
Arielle Waldman
JSON Config File Leaks Azure ActiveDirectory Credentials
2 days 2 hours ago
In this type of misconfiguration, cyberattackers could use exposed secrets to authenticate directly via Microsoft’s OAuth 2.0 endpoints and infiltrate Azure cloud environments.
Elizabeth Montalbano, Contributing Writer
An Audit Isn't a Speed Bump — It's Your Cloud Co-Pilot
6 days ago
Auditing must be seen for what it truly can be: a multiplier of trust, not a bottleneck of progress.
Ravi Sharma
Proof-of-Concept in 15 Minutes? AI Turbocharges Exploitation
6 days 1 hour ago
Generating exploits with AI and large language models shrinks the time to target software flaws, giving security teams scant time to patch. Can enterprises adapt?
Robert Lemos, Contributing Writer
CISA, FBI, NSA Warn of Chinese 'Global Espionage System'
6 days 17 hours ago
Three federal agencies were parties to a global security advisory this week warning about the extensive threat posed by Chinese nation-state actors targeting network devices.
Alexander Culafi
Hackers Steal 4M+ TransUnion Customers' Data
6 days 18 hours ago
The credit reporting agency said the breach was "limited to specific data elements" and didn't include credit reports or core credit information.
Kristina Beek
Checked
5 hours 5 minutes ago
Public RSS feed
darkreading feed