darkreading
Zero-Days Win the Prize for Most Exploited Vulns
1 year 3 months ago
Among the top exploited zero-day vulnerabilities were bugs found in systems from Citrix and Cisco.
Dark Reading Staff
CISA Releases Its First Ever International Strategic Plan
1 year 3 months ago
Trustwave-Cybereason Merger Boosts MDR Portfolio
1 year 3 months ago
The consolidation folds Cybereason's endpoint detection and response (EDR) platform into Trustwave's managed security services offerings, such as managed detection and response (MDR).
Dark Reading Staff
20% of Industrial Manufacturers Are Using Network Security as a First Line of Defense
1 year 3 months ago
5 Ways to Save Your Organization From Cloud Security Threats
1 year 3 months ago
The shift to cloud means securing your organization's digital assets requires a proactive, multilayered approach.
Manikandan Thangaraj
Iranian Cybercriminals Target Aerospace Workers via LinkedIn
1 year 3 months ago
The group seeks out aerospace professionals by impersonating job recruiters — a demographic it has targeted in the past as well — then deploys the SlugResin backdoor malware.
Dark Reading Staff
Google AI Platform Bugs Leak Proprietary Enterprise LLMs
1 year 3 months ago
The tech giant fixed privilege-escalation and model-exfiltration vulnerabilities in Vertex AI that could have allowed attackers to steal or poison custom-built AI models.
Elizabeth Montalbano, Contributing Writer
How CISOs Can Lead the Responsible AI Charge
1 year 3 months ago
CISOs understand the risk scenarios that can help create safeguards so everyone can use AI safely and focus on the technology's promises and opportunities.
Lucas Moody
Middle East Cybersecurity Efforts Catch Up After Late Start
1 year 3 months ago
Despite having only a scant focus on cybersecurity regulations a decade ago, countries in the Middle East — led by Saudi Arabia and other Gulf nations — have adopted mature frameworks and regulations amid escalating volumes of attacks.
Robert Lemos, Contributing Writer
2 Zero-Day Bugs in Microsoft's Nov. Update Under Active Exploit
1 year 3 months ago
The November 2024 Patch Tuesday update contains a substantially high percentage of remote code execution (RCE) vulnerabilities (including a critical issue in Windows Kerberos), and two other zero-day bugs that have been previously disclosed and could soon come under attack.
Jai Vijayan, Contributing Writer
Amazon Employee Data Compromised in MOVEit Breach
1 year 3 months ago
The data leak was not actually due to a breach in Amazon's systems but rather that of a third-party vendor; the supply chain incident affected several other clients as well.
Dark Reading Staff
New Essay Competition Explores AI's Role in Cybersecurity
1 year 3 months ago
The essays are to focus on the impact that artificial intelligence will have on European policy.
Edge Editors
CrowdStrike Spends to Boost Identity Threat Detection
1 year 3 months ago
Adaptive Shield is the third security posture management provider the company has acquired in the past 14 months as identity-based attacks continue to rise.
Jeffrey Schwartz, Contributing Writer
'GoIssue' Cybercrime Tool Targets GitHub Developers En Masse
1 year 3 months ago
Marketed on a cybercriminal forum, the $700 tool harvests email addresses from public GitHub profiles, priming cyberattackers for further credential theft, malware delivery, OAuth subversion, supply chain attacks, and other corporate breaches.
Elizabeth Montalbano, Contributing Writer
Citrix Patches Zero-Day Recording Manager Bugs
1 year 3 months ago
There is some disagreement over whether the remote code execution (RCE) security flaws allow for unauthenticated exploitation or not. Citrix says no, but researchers say the company is downplaying a "good old unauthenticated RCE."
Jai Vijayan, Contributing Writer
Citrix 'Recording Manager' Zero-Day Bug Allows Unauthenticated RCE
1 year 3 months ago
The security vulnerability is due to an exposed Microsoft Message Queuing (MSMQ) instance and the use of the insecure BinaryFormatter.
Tara Seals, Managing Editor, News, Dark Reading
The Power of the Purse: How to Ensure Security by Design
1 year 3 months ago
CISA should make its recommended goals mandatory and perform audits to ensure compliance.
Gary Barlet
Incident Response, Anomaly Detection Rank High on Planned ICS Security Spending
1 year 3 months ago
The "SANS 2024 State of ICS/OT Cybersecurity" report suggests organizations are going to shift spending from security technologies protecting industrial control systems and operational technology environments to nontechnical activities, such as training and incident response.
Jennifer Lawinski, Contributing Writer
Halliburton Optimistic Amid $35M Data Breach Loss
1 year 3 months ago
Though its third-quarter earnings report confirms that the company remains on track, it's unclear how that will be affected if the threat actors commit further damage.
Dark Reading Staff
Checked
11 hours 5 minutes ago
Public RSS feed
darkreading feed