darkreading
Name That Toon Contest
10 hours 51 minutes hence
Europe Evolves Into Ransomware's Favorite Region
14 hours 8 minutes ago
After a global lull, ransomware gangs are setting sights on a rich new arena: attacking EU organizations and their suppliers.
Nate Nelson
Attackers Hit Cisco SD-WAN Flaw 2 Months Before Disclosure
1 day 2 hours ago
Researchers believe rogue peering was used to connect to the victim's SD-WAN devices to gain admin privileges and root-level access.
Jai Vijayan
2026 FIFA World Cup Faces Surge in Cyber Threats
1 day 3 hours ago
Persistent cybercrime, social engineering, and infrastructure threats continue to plague the FIFA 2026 World Cup across the US, Canada, and Mexico.
Alexander Culafi
Do CISOs Need a Code of Ethics?
1 day 4 hours ago
Dark Reading Confidential Episode 19: Kickbacks, no-show jobs, "dirty" VCs, and shelf ware — industry expert Robert "RSnake" Hansen explains why he thinks its time for a CISO code of ethics to ensure cybersecurity bosses aren't engaged in self-dealing that could risk enterprise, and even national, security.
Dark Reading Editorial Team
More Malicious OpenClaw Skills Threaten AI Supply Chain
1 day 7 hours ago
OpenClaw removed five packages from ClawHub, its skills marketplace, that bypassed security checks even though they included infostealers and other threats.
Elizabeth Montalbano
Apple's MacOS Gap Lets Users Disable Security Tools
1 day 12 hours ago
Attackers can exploit the issue to disable security and integrated browser tools without needing administrator privileges or kernel exploits.
Jai Vijayan
Scope of Salesforce Attacks Expands as Icarus Leaks Data
2 days 3 hours ago
More victims have emerged after attackers breached application vendor Klue and used its OAuth tokens to steal customers' Salesforce data.
Rob Wright
'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows
2 days 4 hours ago
The CI/CD workflow weakness affects Microsoft's Azure Sentinel, Google's AI Agent Development Kit, Apache's Doris analytics database, Cloudflare's Workers SDK, and Python Software Foundation's Black.
Alexander Culafi
SocGholish Takedown Highlights Malicious TDS Threats
2 days 10 hours ago
SocGholish uses traffic distribution systems (TDSs) to provide initial access into victims' networks for cybercrime groups such as the notorious Evil Corp.
Rob Wright
FortiBleed Attackers Turn Firewalls Into Credential Stealers as Heists Persist
2 days 11 hours ago
The threat actors engineered a Golang-based sniffer to target 430,000 FortiGate firewalls and identify 110 million credentials in the ongoing global campaign.
Elizabeth Montalbano
DifyTap Bugs Let Attackers 'Wiretap' AI Chat Histories
3 days 2 hours ago
Four vulnerabilities allow attackers to exploit Dify, a platform for AI application building and management, to silently access and exfiltrate sensitive data.
Alexander Culafi
Crypto Heist Fueled by Elaborate Fake Reputation-Boosting Campaign
3 days 7 hours ago
Attackers are using multiple online channels — including GitHub, YouTube, and VirusTotal — to build an illusion of trust to spread a cross-platform clipboard hijacker.
Elizabeth Montalbano
He Thought He Was Secure; His Phone Number Was Stolen Anyway
3 days 9 hours ago
Threat actors can easily steal one-time passwords sent by text when they conduct a SIM swap attack. This can lead to account takeovers, so users must layer up their security measures.
Arielle Waldman
Stressors, AI Forcing Changes to Cybersecurity Teams
6 days 11 hours ago
As threats proliferate and AI complicates cybersecurity, CISOs say the job is getting harder, but more companies still want cybersecurity expertise, if even on a part-time basis.
Robert Lemos
Novo Nordisk Breach Highlights Software Development Pipeline Risk
1 week ago
A leaked GitHub token underscores what most organizations get wrong: Treating secrets management as a tooling problem rather than an identity problem.
Jai Vijayan
Operation Escaneo Signals Shift in LatAm Threat Landscape
1 week ago
The threat group's curious business model may combine opportunistic monetization alongside intel collection, without much coordination between the two.
Alexander Culafi
FIFA Bug Exposes World Cup Streams to Remote Takeover
1 week ago
A hacker could have "Rickrolled" the World Cup — or worse — thanks to FIFA's unenforced Entra access controls.
Nate Nelson
Salesforce Data Thefts Continue via Klue App Compromise
1 week ago
Klue's Battlecards is now the third integrated application that has been compromised to steal customers' Salesforce data, and victims include Huntress, the cybersecurity vendor.
Rob Wright
Checked
11 hours 8 minutes ago
Public RSS feed
darkreading feed