Dark Reading

School's Out for Summer, but Don't Close the Book on Cybersecurity Training

06/25/2021
Strengthening their security posture should be at the top of school IT departments' summer to-do list.

High-Level FIN7 Member Sentenced to 7 Years in Prison

06/25/2021
Andrii Kolpakov, who served as a high-level pentester for the criminal group, was also ordered to pay $2.5 million in restitution.

7 Unconventional Pieces of Password Wisdom

06/25/2021
Challenging common beliefs about best practices in password hygiene.

74% of Q1 Malware Was Undetectable Via Signature-Based Tools

06/24/2021
Attackers have improved on tweaking old malware to continue sneaking it past traditional threat detection controls, researchers report.

D3FEND Framework Seeks to Lay Foundation for Cyber Defense

06/24/2021
The MITRE project, funded by the National Security Agency, aims to create a foundation for analyzing and discussing cyber defenses and could shake up the vendor community.

Tulsa Officials Warn Ransomware Attackers Leaked City Files

06/24/2021
The group behind the May 2021 attack has shared more than 18,000 files via the Dark Web, mostly internal department files and police citations.

Preinstalled Firmware Updater Puts 128 Dell Models at Risk

06/24/2021
A feature of the computer maker's update utility does not correctly handle certificates, leaving systems open to firmware-level compromises.

Boardroom Perspectives on Cybersecurity: What It Means for You

06/24/2021
Because board members are paying close attention to security, security leaders must be able to respond to and alleviate their concerns with data.

Storms & Silver Linings: Avoiding the Dangers of Cloud Migration

06/24/2021
We hear a lot about the sunlit uplands of cloud-powered business, but what about the risks of making information available across the organization?

John McAfee, Creator of McAfee Antivirus Software, Dead at 75

06/24/2021
McAfee, who was being held in a Spanish jail on US tax-evasion charges, had learned on Monday he would be extradited to the US.

rMTD: A Deception Method That Throws Attackers Off Their Game

06/24/2021
Through a variety of techniques, rotational Moving Target Defense makes existing OS and app vulnerabilities difficult to exploit. Here's how.

79% of Third-Party Libraries in Apps Are Never Updated

06/23/2021
A lack of contextual information and concerns over application disruption among contributing factors.

VMs Help Ransomware Attackers Evade Detection, But It's Uncommon

06/23/2021
Some ransomware attackers use virtual machines to bypass security detection, but adoption is slow for the complicated technique.

Microsoft Tracks New BazaCall Malware Campaign

06/23/2021
Attackers use emails to prompt victims to call a fraudulent call center, where attackers instruct them to download a malicious file.

New DNS Name Server Hijack Attack Exposes Businesses, Government Agencies

06/23/2021
Researchers found a "novel" class of DNS vulnerabilities in AWS Route53 and other DNS-as-a-service offerings that leak sensitive information on corporate and government customers, with one simple registration step.

Survey Seeks to Learn How 2020 Changed Security

06/23/2021
Respondents to a new Dark Reading/Omdia survey will be entered into a drawing for a Black Hat Black Card.

When Will Cybersecurity Operations Adopt the Peter Parker Principle?

06/23/2021
Having a prevention mindset means setting our prevention capabilities to "prevent" instead of relying on detection and response.

Expecting the Unexpected: Tips for Effectively Mitigating Ransomware Attacks in 2021

06/23/2021
Cybercriminals continually innovate to thwart security protocols, but organizations can take steps to prevent and mitigate ransomware attacks.

Despite Heightened Cyber-Risks, Few Security Leaders Report to CEO

06/22/2021
A new report suggests that top management at most companies still don't get security.

Transmit Security Announces $543M Series A Funding Round

06/22/2021
The passwordless technology provider says the funding will be used to increase its reach and expand primary business functions.