Dark Reading

Security on a Shoestring? More Budget Means More Detection

03/30/2021
Companies that spend the smallest share of their IT budget on security see fewer threats, but that's not good news.

Publicly Available Data Enables Enterprise Cyberattacks

03/30/2021
Adversaries scour social media platforms and use other tactics to gather information that facilitates targeted enterprise attacks, research shows.

What We Know (and Don't Know) So Far About the 'Supernova' SolarWinds Attack

03/30/2021
A look at the second elusive attack targeting SolarWinds software that researchers at Secureworks recently cited as the handiwork of Chinese nation-state hackers.

White Ops Renames Company 'Human'

03/30/2021
The company first confirmed plans to change its name in October 2020.

What You Need to Know -- or Remember -- About Web Shells

03/30/2021
What's old is new again as Web shell malware becomes the latest attack vector in widespread Exchange exploits. Here's a primer on what Web shells are and what they do.

Watch Out for These Cyber-Risks

03/30/2021
It's difficult to predict what will materialize in the months ahead in terms of cyber-risks, which is why it's wise to review your organization's security posture now.

Ghost Users Haunt Healthcare Firms

03/30/2021
Data security hygiene severely lacking among healthcare firms, new research shows.

Beyond MITRE ATT&CK: The Case for a New Cyber Kill Chain

03/30/2021
The Cyber Kill Chain and MITRE ATT&CK are popular reference frameworks to analyze breaches, but amid the rise of XDR, we may need a new one.

In the Rush to Embrace Hybrid Cloud, Don't Forget About Security

03/30/2021
Cloud service providers typically only secure the infrastructure itself, while customers are responsible for their data and application security.

Manufacturing Firms Learn Cybersecurity the Hard Way

03/29/2021
Although 61% of smart factories have experienced a cybersecurity incident, IT groups and operational technology groups still don't collaborate enough on security.

Attackers Target PHP Git Server to Backdoor Source Code

03/29/2021
The PHP maintainers have decided to make GitHub the official source for PHP repositories going forward.

SolarWinds Hackers Accessed DHS Chief's Email

03/29/2021
Several high-level government accounts were also breached in the attack.

4 Open Source Tools to Add to Your Security Arsenal

03/29/2021
Open source solutions can offer an accessible and powerful way to enhance your security-testing capabilities.

CISA Builds Out Defensive Tools for Security Teams

03/29/2021
Need a tool to hunt for attacks in your network? The DHS agency bolsters the offerings in its open source toolbox.

SolarWinds Experimenting With New Software Build System in Wake of Breach

03/26/2021
CISO of SolarWinds now has complete autonomy to stop product releases if security concerns exist, CEO says.

40% of Apps Leaking Information

03/26/2021
Apps in manufacturing most at risk, according to WhiteHat Security.

Apple Patches iOS Zero-Day

03/26/2021
Apple today released iOS 14.4.2 to address a security vulnerability that may have been actively exploited.

Microsoft Shares Exchange Server Post-Compromise Attack Activity

03/26/2021
Microsoft shares the details of post-exploitation attack activity, including multiple ransomware payloads and a cryptocurrency botnet.

A Day in the Life of a DevSecOps Manager

03/26/2021
"Most days are good days," says Rally Health's Ari Kalfus. But they sure are busy, he tells The Edge.

Data Bias in Machine Learning: Implications for Social Justice

03/26/2021
Take historically biased data, then add AI and ML to compound and exacerbate the problem.