Dark Reading

Critical Infrastructure Security and a Case for Optimism in 2022

01/12/2022
The new US infrastructure law will fund new action to improve cybersecurity across rail, public transportation, the electric grid, and manufacturing.

Patch Management Today: A Risk-Based Strategy to Defeat Cybercriminals

01/12/2022
By combining risk-based vulnerability prioritization and automated patch intelligence, organizations can apply patches based on threat level. Part 2 of 3.

Let's Play! Raising the Stakes for Threat Modeling With Card Games

01/11/2022
On a recent Friday night, three security experts got together to play custom games that explore attack risks in an engaging way.

Kiteworks Acquires Email Encryption Leader totemo

01/11/2022
Further closes intelligence gap inhibiting companies from tracking and controlling private content communications.

Microsoft Kicks Off 2022 With 96 Security Patches

01/11/2022
Nine of the Microsoft patches released today are classified as critical, 89 are Important, and six are publicly known.

Cloud Apps Replace Web as Source for Most Malware Downloads

01/11/2022
Two-thirds of all malware distributed to enterprise networks last year originated from cloud apps such as Google Drive, OneDrive, and numerous other cloud apps, new research shows.

Honeywell Adds Deception Tech to Building Automation Systems Security

01/11/2022
New OT security platform directs attackers toward phony assets to deflect threats.

Enterprise Security at CES 2022 Marked by IoT, Biometrics, and PC Chips

01/11/2022
Amid the onslaught of mostly consumer-oriented announcements in Las Vegas, a few key items pertaining to enterprise security emerged.

FBI, NSA & CISA Issue Advisory on Russian Cyber Threat to US Critical Infrastructure

01/11/2022
Advisory explains how to detect, respond to, and mitigate cyberattacks from Russian state-sponsored hacking groups.

Details Released on SonicWall Flaws in SMA-100 Devices

01/11/2022
The most serious of the five vulnerabilities disclosed today can lead to unauthenticated remote code execution on affected devices.

Why the Insider Threat Will Motivate Cyber and Physical Teams to Collaborate More Than Ever in 2022

01/11/2022
It's hard to have a crystal ball in the world of security, but if one were to make a safe prediction, it's this: Organizations will need to further integrate their cybersecurity and physical security functions throughout 2022 and beyond. So argues former chief psychologist for the US Secret Service, Dr. Marisa Randazzo, who now heads up Ontic's Center of Excellence.

Remotely Exploitable NetUSB Flaw Puts Millions of Devices at Risk

01/11/2022
A vulnerability in a third-party component used by many networking firms puts consumer and small business routers at risk for remote exploitation.

Businesses Suffered 50% More Cyberattack Attempts per Week in 2021

01/11/2022
The rise — partly due to Log4j — helped boost cyberattack attempts to an all-time high in Q4 2021, new data shows.

Why Security Awareness Training Should Begin in the C-Suite

01/11/2022
It's not just the rights and privileges that CXOs have on the network. They can also set an example of what good security hygiene looks like.

Kaspersky Research Uncovers Cybersecurity Budgets, Insurance, and Vendor Expectations for 2022

01/11/2022
Kaspersky commissioned a survey in October 2021 targeting 600 employees based in the US and Canada who are key decision makers for the cybersecurity sector within their company.

5 Things to Know About Next-Generation SIEM

01/11/2022
NG-SIEM is emerging as a cloud- and analytics-driven alternative to legacy SIEMs. Based on new research, Omdia highlights five important new insights for anyone considering a NG-SIEM purchase.

What Editing Crosswords Can Teach Us About Security Leadership

01/10/2022
When security leaders look for mistakes, they often find them before customers do.

No Significant Intrusions Related to Log4j Flaw Yet, CISA Says

01/10/2022
But that could change anytime, officials warn, urging organizations to prioritize patching against the critical remote code execution flaw.

Microsoft: macOS 'Powerdir' Flaw Could Enable Access to User Data

01/10/2022
The vulnerability could allow an attacker to bypass the macOS Transparency, Consent, and Control measures to access a user's protected data.

Microsoft: macOS 'Powerdir' Flaw Could Let Attackers Gain Access to User Data

01/10/2022
The vulnerability could allow an attacker to bypass the macOS Transparency, Consent, and Control measures to access a user's protected data.