Dark Reading

Modern Software: What's Really Inside?

02/20/2023
Open source has changed the software game from build or buy to assemble with care.

Despite Breach, LastPass Demonstrates the Power of Password Management

02/20/2023
What's scarier than keeping all of your passwords in one place and having that place raided by hackers? Maybe reusing insecure passwords.

Researchers Create an AI Cyber Defender That Reacts to Attackers

02/20/2023
The system based on deep reinforcement learning can adapt to defenders' tactics and stop 95% of simulated attacks, according to its developers.

Majority of Ransomware Attacks Last Year Exploited Old Bugs

02/20/2023
New research shows that 57 vulnerabilities that threat actors are currently using in ransomware attacks enable everything from initial access to data theft.

Is OWASP at Risk of Irrelevance?

02/17/2023
A growing group of OWASP members and board leaders are calling for the AppSec group to make big changes to stay apace with modern development.

Check Point Boosts AppSec Focus With CNAPP Enhancements

02/17/2023
Established network security players like Check Point are responding to the shift to cloud-native applications, which have exposed more vulnerabilities in open source software supply chains.

Novel Spy Group Targets Telecoms in 'Precision-Targeted' Cyberattacks

02/17/2023
The primary victims so far have been employees of telcos in the Middle East, who were hit with custom backdoors via the cloud, in a likely precursor to a broader attack.

Google Translate Helps BEC Groups Scam Companies in Any Language

02/17/2023
BEC gangs Midnight Hedgehog and Mandarin Capybara show how online marketing and translation tools are making it easy for these threat groups to scale internationally.

Inglis Retires as National Cyber Director Ahead of Biden's Cybersecurity EO

02/17/2023
The long-time NSA and cyber specialist says he's exiting the public sector.

Not Stoked: Burton Snowboards' Online Orders Disrupted After Cyberattack

02/17/2023
The snow sports specialist is investigating to see what caused the operations-disrupting "cyber incident."

Massive GoAnywhere RCE Exploit: Everything You Need to Know

02/17/2023
Weeks after an exploit was first announced in a popular cloud-based file transfer service, could some organizations still be vulnerable? The answer is yes.

AppSec Threats Deserve Their Own Incident Response Plan

02/17/2023
With a rearranging of priorities and good incident response plans, organizations can be ready to face the future of software attacks.

ESXi Ransomware Update Outfoxes CISA Recovery Script

02/16/2023
New ESXiArgs-ransomware attacks include a workaround for CISA's decryptor, researchers find.

Atlassian: Leaked Data Stolen via Third-Party App

02/16/2023
SiegedSec threat group leaked data that Atlassian says was taken from app used to coordinate in-office resources.

MVP Vibe Fest Bridges Gap Between Athletics and Cybersecurity

02/16/2023
Top athletes compete both on and off the track in a mix of track and field events and cyber games.

WatchGuard Launches New Line of Firewall Products to Enhance Unified Security for Remote and Distributed Businesses

02/16/2023
Powered by WatchGuard’s Unified Security Platform® architecture, new Fireboxes deliver enhanced performance and added security capabilities that MSPs and IT admins can easily manage in WatchGuard Cloud.

Cybersecurity Jobs Remain Secure Despite Recession Fears

02/16/2023
Only 10% of corporate executives expect to lay off members of cybersecurity teams in 2023, much lower than other areas, as companies protect hard-to-find skill sets.

SideWinder APT Spotted Targeting Crypto

02/16/2023
The nation-state threat group has been attacking a wider range of victims and regions than previously thought.

Window Snyder's Startup Launches Security Platform for IoT Device Makers

02/16/2023
Thistle's technology will give device makers a way to easily integrate features for secure updates, memory management, and communications into their products, Snyder says.

Simplify to Survive: How Organizations Can Navigate Cyber-Risk

02/16/2023
Simplification can result in efficiencies, reduced overhead, and the ability to respond to cyber threats more quickly.