Dark Reading

Microsoft Tracks Attack Campaign Against Customer Support Agents

06/28/2021
The company attributes the attack to Nobelium, the same group it linked to the SolarWinds campaign earlier this year.

An Interesting Approach to Cyber Insurance

06/28/2021
What if insurers were to offer companies an incentive -- say, a discount -- for better protecting themselves? You know, the way car insurance companies offer lower premiums to customers who take a driver's ed course.

The Danger of Action Bias: Is It Always Better to Act Quickly?

06/28/2021
Experts discuss the meaning of action bias and how it presents a threat to IT security leaders, practitioners, and users.

The Role of Encryption in Protecting LGBTQ+ Community Members

06/28/2021
The Internet is a vital tool that helps LGBTQ+ community members communicate without fear of persecution -- and strong encryption is a critical part of this equation.

New CPU Baseline for Windows 11 Will Ensure Better Security, Microsoft Says

06/25/2021
Redmond's latest OS will run only on systems with TPM 2.0 chips.

Amazon Acquires Secure Messaging Platform Wickr

06/25/2021
AWS CISO Stephen Schmidt says the acquisition is strategic amid the proliferation of remote work.

Data Privacy Is in 23andMe CSO's DNA

06/25/2021
How serious is the company about safeguarding its customers and their genetic information? "We're hiding data even from ourselves," says the biotech and genetic testing company's head of security.

School's Out for Summer, but Don't Close the Book on Cybersecurity Training

06/25/2021
Strengthening their security posture should be at the top of school IT departments' summer to-do list.

High-Level FIN7 Member Sentenced to 7 Years in Prison

06/25/2021
Andrii Kolpakov, who served as a high-level pentester for the criminal group, was also ordered to pay $2.5 million in restitution.

7 Unconventional Pieces of Password Wisdom

06/25/2021
Challenging common beliefs about best practices in password hygiene.

74% of Q1 Malware Was Undetectable Via Signature-Based Tools

06/24/2021
Attackers have improved on tweaking old malware to continue sneaking it past traditional threat detection controls, researchers report.

D3FEND Framework Seeks to Lay Foundation for Cyber Defense

06/24/2021
The MITRE project, funded by the National Security Agency, aims to create a foundation for analyzing and discussing cyber defenses and could shake up the vendor community.

Tulsa Officials Warn Ransomware Attackers Leaked City Files

06/24/2021
The group behind the May 2021 attack has shared more than 18,000 files via the Dark Web, mostly internal department files and police citations.

Preinstalled Firmware Updater Puts 128 Dell Models at Risk

06/24/2021
A feature of the computer maker's update utility does not correctly handle certificates, leaving systems open to firmware-level compromises.

Boardroom Perspectives on Cybersecurity: What It Means for You

06/24/2021
Because board members are paying close attention to security, security leaders must be able to respond to and alleviate their concerns with data.

Storms & Silver Linings: Avoiding the Dangers of Cloud Migration

06/24/2021
We hear a lot about the sunlit uplands of cloud-powered business, but what about the risks of making information available across the organization?

John McAfee, Creator of McAfee Antivirus Software, Dead at 75

06/24/2021
McAfee, who was being held in a Spanish jail on US tax-evasion charges, had learned on Monday he would be extradited to the US.

rMTD: A Deception Method That Throws Attackers Off Their Game

06/24/2021
Through a variety of techniques, rotational Moving Target Defense makes existing OS and app vulnerabilities difficult to exploit. Here's how.

79% of Third-Party Libraries in Apps Are Never Updated

06/23/2021
A lack of contextual information and concerns over application disruption among contributing factors.

VMs Help Ransomware Attackers Evade Detection, But It's Uncommon

06/23/2021
Some ransomware attackers use virtual machines to bypass security detection, but adoption is slow for the complicated technique.