darkreading
Name That Toon Contest
2 weeks 6 days hence
[Virtual Event] Anatomy of a Data Breach: What to Do if it Happens to You
1 week 5 days hence
Rust-Written IronWorm Hits NPM Supply Chain
20 hours 46 minutes ago
Like Shai-Hulud, the campaign targets developers to steal credentials and reuses them to propagate across the software supply channel.
Jai Vijayan
China's TA4922 Expands Cybercrime Attacks Globally
21 hours 9 minutes ago
One of the world's most diverse, least-focused cybercrime groups is enlarging its footprint beyond East Asia.
Nate Nelson
4 Critical Threats Where Attackers Have the Advantage
21 hours 25 minutes ago
Gartner analysts issued a call to action to bolster defenses against several emerging critical threats, such as deepfakes and prompt injections.
Rob Wright
Bugcrowd Launches EU Data Residency Option For Evolving Data Sovereignty Needs
1 day 4 hours ago
Organizations are growing serious about what nation’s rules apply to their data. Experts point to geopolitical tensions as a main contributing factor.
Arielle Waldman
Pakistan Spies on Afghan Finance Ministry With Xeno RAT
1 day 14 hours ago
Despite broadly connected digital infrastructure, standard fare TTPs are enough to cause trouble for Afghanistan's porous cybersecurity.
Nate Nelson
Attackers Use AI to Automate EDR Evasion Testing
1 day 20 hours ago
Python scripts were used to test malware against endpoint detection and response agents from Sophos, CrowdStrike, and Windows Defender.
Alexander Culafi
Tropical Blend: Cyber & Politics Ramp Up Across Latin America
1 day 22 hours ago
China-linked espionage groups have attacked at least a dozen nations in the region, gathering information on maritime shipping, oil production, and other geopolitical interests.
Robert Lemos
Cyber Insurance Rates Are Dropping, but Exclusions Widen
1 day 23 hours ago
Cyber insurance coverage is slowly changing, and some policies may not provide coverage for social engineering attacks like ClickFix.
Rob Wright
Coding Gaffe Exposes Microsoft 365 Accounts to Widespread Takeover
1 day 23 hours ago
A disabled security setting meant to protect authentication across Android versions of key apps like Word, PowerPoint, and Excel paved the way for attackers to steal logins and data.
Elizabeth Montalbano
Malicious Notifications Could Trick Google Gemini Users
2 days 6 hours ago
A prompt injection flaw in Google Gemini's voice assistant let attackers hide malicious commands in notifications, enabling social engineering and more.
Alexander Culafi
Global Stock Exchange Hit by Monthslong Email Campaign
2 days 8 hours ago
A threat actor got a near-continuous view into an influential finance executive's email inbox, thanks to clever use of legitimate, native Windows tools.
Nate Nelson
Zoom CISO: AI as a Security Enabler, Not Role-Replacer
2 days 20 hours ago
Zoom CISO Sandra McLeod discusses the challenges of securing a global communication platform, the promise of AI-driven security workflows, and her advice for aspiring cybersecurity leaders.
Kristina Beek
FBI-Flagged Phishing Kit Kali365 Expands Its Reach
2 days 21 hours ago
Once targeting just Microsoft 365, the phishing-as-a-service platform now aims at AWS, Okta, and Russian platforms, while relying on device code phishing.
Jai Vijayan
DriveSurge Hijacks Thousands of Sites for ClickFix, FakeUpdate Attacks
2 days 22 hours ago
A sneaky, wide-scale IAB operation uses a malicious traffic distribution system (TDS) to redirect visitors of trusted websites to ones that deliver malware.
Elizabeth Montalbano
China Uses Dual-Method Cyberattack on Czech Orgs
2 days 22 hours ago
China is stealing data from high-value targets via a sneaky, double-layer spear-phishing campaign that includes the Azureveil malware.
Alexander Culafi
Securing AI Agents Before They Go Rogue Is Next to Impossible
2 days 23 hours ago
High-autonomy agents with broad permissions and unfettered access are a recipe for disaster, and enterprises need to act now before they become the next horror story.
Rob Wright
[An RX Global Event] Infosecurity Europe
3 days 5 hours ago
Checked
9 hours 33 minutes ago
Public RSS feed
darkreading feed