Dark Reading

Cybellum Releases Enhanced SBOM Management and Compliance Oversight for Manufacturers with New Release of its Product Se

01/26/2023
Advanced workflow, approval process, and management dashboard enhance control, distribution, and supervision, while reducing errors and streamlining the entire SBOM management process.

NIST Risk Management Framework Aims to Improve Trustworthiness of Artificial Intelligence

01/26/2023
New guidance seeks to cultivate trust in AI technologies and promote AI innovation while mitigating risk

Organizations Must Brace for Privacy Impacts This Year

01/26/2023
Expect more regulatory and enforcement action in the US and around the world.

Snyk Gets Nod of Approval With ServiceNow Strategic Investment

01/25/2023
One of the most closely watched security startups continues to build bank because its platform appeals to both developers and security pros.

KORE Delivers IoT SAFE Solution for Massive IoT Use Cases with AWS

01/25/2023
Delivering secure, global IoT device connectivity, deployment, and management at scale.

Microsoft Azure-Based Kerberos Attacks Crack Open Cloud Accounts

01/25/2023
Two common attacks against on-premises Kerberos authentication servers — known as Pass the Ticket and Silver Ticket — can be used against Microsoft's Azure AD Kerberos, a security firms says.

Zacks Investment Research Hack Exposes Data for 820K Customers

01/25/2023
Zacks Elite sign-ups for the period 1999–2005 were accessed, including name, address, email address, phone number, and the password associated with Zacks.com.

Google Pushes Privacy to the Limit in Updated Terms of Service

01/25/2023
In the Play Store's ToS, a paragraph says Google may remove "harmful" applications from users' devices. Is that a step too far?

Despite Slowing Economy, Demand for Cybersecurity Workers Remains Strong

01/25/2023
New Cyberseek™ data shows US is short nearly 530,000 skilled cybersecurity staff.

Researchers Pioneer PoC Exploit for NSA-Reported Bug in Windows CryptoAPI

01/25/2023
The security vulnerability allows attackers to spoof a target certificate and masquerade as any website, among other things.

GoTo Encrypted Backups Stolen in LastPass Breach

01/25/2023
Encrypted backups for several GoTo remote work tools were exfiltrated from LastPass, along with encryption keys.

Log4j Vulnerabilities Are Here to Stay — Are You Prepared?

01/25/2023
Don't make perfect the enemy of good in vulnerability management. Context is key — prioritize vulnerabilities that are actually exploitable. Act quickly if the vulnerability is on a potential attack path to a critical asset.

North Korea's Top APT Swindled $1B From Crypto Investors in 2022

01/25/2023
The DPRK has turned crypto scams into big business to replenish its depleted state coffers.

Multicloud Security Challenges Will Persist in 2023

01/25/2023
Some predictions about impending security challenges, with a few tips for proactively addressing them.

Cybersecurity Budgets Increase for Retail & Hospitality Industry

01/25/2023
Despite economic headwinds and layoffs in other areas, most retail and hospitality CISOs expect to add staff in 2023, according to a new report.

BlackBerry's Inaugural Quarterly Threat Intelligence Report Reveals Threat Actors Launch One Malicious Threat Every Minu

01/25/2023
Report identifies 1.75m cyberattacks were stopped by BlackBerry in the last 90 days.

Can't Fill Open Positions? Rewrite Your Minimum Requirements

01/25/2023
If you or your company can't find good infosec candidates, consider changing up the qualifications to find more nontraditional talent.

Skyhawk Security Launches Multicloud Runtime Threat Detection and Response Platform

01/24/2023
Skyhawk Synthesis extends cloud security misconfiguration detection across multiple clouds, the company says — throwing cloud security posture management in for free.

View from Davos: The Changing Economics of Cybercrime

01/24/2023
Participants in a working session on ransomware at the World Economic Forum discussed how planning ahead can reduce cyber risk.

Ticketmaster Blames Bots in Taylor Swift 'Eras' Tour Debacle

01/24/2023
Ticketmaster testified in the Senate that a cyberattack was to blame for the high-profile Taylor Swift concert sales collapse, but some senators aren't so sure.