Dark Reading

What CISOs Can Do About Brand Impersonation Scam Sites

02/03/2023
Apply these nine tips to proactively fight fraudulent websites that use your brand to rip people off.

Iran-Backed Actor Behind 'Holy Souls' Cyberattack on Charlie Hebdo, Microsoft Says

02/03/2023
The January attack was in retaliation for the satirical French magazine's decision to launch a cartoon contest to lampoon Iran's Supreme Leader.

Scores of Redis Servers Infested by Sophisticated Custom-Built Malware

02/03/2023
At least 1,200 Redis servers worldwide have been infected with "HeadCrab" cryptominers since 2021.

How the Cloud Is Shifting CISO Priorities

02/03/2023
The greatly expanding attack surface created by the cloud needs to be protected.

MITRE Releases Tool to Design Cyber-Resilient Systems

02/02/2023
Engineers can use the Cyber Resiliency Engineering Framework Navigator to visuzalize their cyber-resiliency capabilities.

Korelock Launches IOT Smart Lock Technology Company

02/02/2023
Denver-based business secures Series A Funding through partnerships with Iron Gate Capital and Kozo Keikaku Engineering.

Cyberattack on Fintech Firm Disrupts Derivatives Trading Globally

02/02/2023
The Russia-linked LockBit ransomware group claims to be behind the attack that fouled automated transactions for dozens of clients of financial technology firm ION Group.

6 Examples of the Evolution of a Scam Site

02/02/2023
Examining some key examples of recently found fraud sites that target the lucrative retail shoe industry helps us understand how brand impersonation sites evolve.

Rising ‘Firebrick Ostrich’ BEC Group Launches Industrial-Scale Cyberattacks

02/02/2023
The group's wanton attacks demonstrate that business email compromise is everything a hacker can want in one package: low risk, high reward, quick, easy, and low effort.

Patch Critical Bug Now: QNAP NAS Devices Ripe for the Slaughter

02/02/2023
Analysts find that 98% of QNAP NAS are vulnerable to CVE-2022-27596, which allows unauthenticated, remote SQL code injection.

Managing the Governance Model for Software Development in a No-Code Ecosystem

02/02/2023
Forward-leading business and technology leaders are seeing the value of the "do-It-yourself" approach.

AppSec Playbook 2023: Study of 829M Attacks on 1,400 Websites

02/02/2023
The total number of 61,000 open vulnerabilities, including 1,700 critical ones that have been open for 180+ days, exposes businesses to potential attacks.

Cybersecurity Leaders Launch First Attack Matrix for Software Supply Chain Security

02/02/2023
Current and former cybersecurity leaders from Microsoft, Google, GitLab, Check Point, OWASP, Fortinet and others have already joined the open framework initiative, which is being led by OX Security.

Discrepancies Discovered in Vulnerability Severity Ratings

02/02/2023
Differences in how the National Vulnerability Database (NVD) and vendors score bugs can make patch prioritization harder, study says.

Lazarus Group Rises Again, to Gather Intelligence on Energy, Healthcare Firms

02/02/2023
An OpSec slip from the North Korean threat group helps researchers attribute what was first suspected as a ransomware attack to nation-state espionage.

Why CISOs Should Care About Brand Impersonation Scam Sites

02/01/2023
Enterprises often don't know whose responsibility it is to monitor for spoofed brand sites and scams that steal customers' trust, money, and personally identifiable information.

Nearly All Firms Have Ties With Breached Third Parties

02/01/2023
The average organization does business with 11 third parties, and 98% of organizations do business with a third party who has suffered a breach, an analysis finds.

CISA to Open Supply Chain Risk Management Office

02/01/2023
A new supply chain risk management office aims to help public and private sectors implement recent CISA policies and guidance.

Greater Incident Complexity, Shift in How Threat Actors Use Stolen Data, Will Drive the Cyber Threat Landscape in 2023,

02/01/2023
Noting 13% year-over-year growth in fraudulent instruction as a cause of loss, report predicts organizations must get smarter about educating employees to spot fraudulent tactics.

Radiant Logic Signs Definitive Agreement to Acquire Brainwave GRC

02/01/2023
Move will strengthen position as a leader in the identity governance and analytics market.