Dark Reading

Microsoft Patch Tuesday: 4 Critical CVEs, 3 Publicly Known, 1 Wormable

05/11/2021
Microsoft releases security patches for 55 vulnerabilities in its monthly roundup, which includes a critical, wormable flaw in the HTTP protocol stack.

Cartoon Caption Winner: Greetings, Earthlings

05/11/2021
And the winner of Dark Reading's April cartoon caption contest is ...

3 Cybersecurity Myths to Bust

05/11/2021
Deeply rooted cybersecurity misconceptions are poisoning our ability to understand and defend against attacks.

Critical Infrastructure Under Attack

05/11/2021
Several recent cyber incidents targeting critical infrastructure prove that no open society is immune to attacks by cybercriminals. The recent shutdown of key US energy pipeline marks just the tip of the iceberg.

Colonial Pipeline Cyberattack: What Security Pros Need to Know

05/10/2021
As the massive US pipeline operator works to restore operations after a DarkSide ransomware attack late last week, experts say it's a cautionary tale for critical infrastructure providers.

Tulsa Deals With Aftermath of Ransomware Attack

05/10/2021
Weekend attack shuts down several city sites and service.

Four Plead Guilty to RICO Conspiracy Involving Hosting Services for Cybercrime

05/10/2021
The "bulletproof hosting" organization hosted malware including Zeus, SpyEye, Citadel, and the Blackhole Exploit Kit.

10 Security Awareness Training Mistakes to Avoid

05/10/2021
Give your cybersecurity culture a boost by adding these to the "don't" column of your cybersecurity awareness training do's and don'ts list.

Exchange Exploitation: Not Dead Yet

05/10/2021
The mass exploitation of Exchange Servers has been a wake-up call, and it will take all parties playing in concert for the industry to react, respond, and recover.

How North Korean APT Kimsuky Is Evolving Its Tactics

05/07/2021
Researchers find differences in Kimsuky's operations that lead them to divide the APT into two groups: CloudDragon and KimDragon.

Most Organizations Feel More Vulnerable to Breaches Amid Pandemic

05/07/2021
More than half of business see the need for significant long-term changes to IT due to COVID-19, research finds.

FBI, NSA, CISA & NCSC Issue Joint Advisory on Russian SVR Activity

05/07/2021
The report provides additional details on tactics of Russia's Foreign Intelligence Service following public attribution of the group to last year's SolarWinds attack.

The Edge Pro Quote: Password Empowerment

05/07/2021
Despite being a pain in the neck, passwords may hold a psychological purpose that security pros should take into account.

Defending Against Web Scraping Attacks

05/07/2021
Web scraping attacks, like Facebook's recent data leak, can easily lead to more significant breaches.

11 Reasons Why You Sorta Love Passwords

05/07/2021
We asked you to tell the truth about why you secretly love passwords. From the heartfelt to the hilarious, here's what you had to say.

Troy Hunt: Organizations Make Security Choices Tough for Users

05/06/2021
The Have I Been Pwned founder took the virtual stage at Black Hat Asia to share stories about his work and industrywide challenges.

Google Plans to Automatically Enable Two-Factor Authentication

05/06/2021
The company plans to automatically enroll users in two-step verification if their accounts are properly configured.

CISA Publishes Analysis on New 'FiveHands' Ransomware

05/06/2021
Attackers used publicly available tools, FiveHands ransomware, and SombRAT to successfully target an organization, officials report.

Cloud-Native Businesses Struggle with Security

05/06/2021
More companies moved to cloud-native infrastructure in the past year, and security incidents and malware moved right along with them.

Securing the Internet of Things in the Age of Quantum Computing

05/06/2021
Internet security, privacy, and authentication aren't new issues, but IoT presents unique security challenges.