Dark Reading

Microsoft Tracks New BazaCall Malware Campaign

06/23/2021
Attackers use emails to prompt victims to call a fraudulent call center, where attackers instruct them to download a malicious file.

New DNS Name Server Hijack Attack Exposes Businesses, Government Agencies

06/23/2021
Researchers found a "novel" class of DNS vulnerabilities in AWS Route53 and other DNS-as-a-service offerings that leak sensitive information on corporate and government customers, with one simple registration step.

Survey Seeks to Learn How 2020 Changed Security

06/23/2021
Respondents to a new Dark Reading/Omdia survey will be entered into a drawing for a Black Hat Black Card.

When Will Cybersecurity Operations Adopt the Peter Parker Principle?

06/23/2021
Having a prevention mindset means setting our prevention capabilities to "prevent" instead of relying on detection and response.

Expecting the Unexpected: Tips for Effectively Mitigating Ransomware Attacks in 2021

06/23/2021
Cybercriminals continually innovate to thwart security protocols, but organizations can take steps to prevent and mitigate ransomware attacks.

Despite Heightened Cyber-Risks, Few Security Leaders Report to CEO

06/22/2021
A new report suggests that top management at most companies still don't get security.

Transmit Security Announces $543M Series A Funding Round

06/22/2021
The passwordless technology provider says the funding will be used to increase its reach and expand primary business functions.

Chart: Strength in Numbers

06/22/2021
More companies are heeding expert advice to beef up their incident-response teams.

NSA Funds Development & Release of D3FEND Framework

06/22/2021
The framework, now available through MITRE, provides countermeasures to attacks.

Identity Eclipses Malware Detection at RSAC Startup Competition

06/22/2021
All 10 finalists in the Innovation Sandbox were focused on identity, rather than security's mainstay for the last 20 years: Malware detection.

Majority of Web Apps in 11 Industries Are Vulnerable All the Time

06/22/2021
Serious vulnerabilities exist every day in certain industries, including utilities, public administration, and professional services, according to testing data.

7 Powerful Cybersecurity Skills the Energy Sector Needs Most

06/22/2021
Those looking to join the fight might want to polish up or acquire some (or all) of these hottest skills on the market.

Does Your Cyberattack Plan Include a Crisis Communications Strategy? 5 Tips to Get Started

06/22/2021
Don't overlook crisis communications in your cybersecurity incident response planning.

Did Companies Fail to Disclose Being Affected by SolarWinds Breach?

06/21/2021
The SEC has sent out letters to some investment firms and publicly listed companies seeking information, Reuters says.

Software-Container Supply Chain Sees Spike in Attacks

06/21/2021
Attackers target companies' container supply chain, driving a sixfold increase in a year, aiming to steal processing time for cryptomining and compromise cloud infrastructure.

Data Leaked in Fertility Clinic Ransomware Attack

06/21/2021
Reproductive Biology Associates says the data of 38,000 patients may have been compromised in the April cyberattack.

Baltimore County Public Schools' Ransomware Recovery Tops $8M

06/21/2021
The school district has spent seven months and a reported $8.1 million recovering from the November attack.

Are Ransomware Attacks the New Pandemic?

06/21/2021
Ransomware has been a problem for decades, so why is government just now beginning to address it?

Attackers Find New Way to Exploit Google Docs for Phishing

06/18/2021
Tactic continues recent trend by attackers to use trusted cloud services to send and host malicious content.

This Week in Database Leaks: Cognyte, CVS, Wegmans

06/18/2021
Billions of records were found exposed this week due to unprotected databases owned by major corporations and third-party providers.