Dark Reading

VPN Flaw Allows Criminal Access to Everything on Victims' Computers

12/05/2019
Vulnerability in the Aviatrix VPN client, since patched, gives an attacker unlimited access to a breached system.

US Sets $5 Million Bounty For Russian Hacker Behind Zeus Banking Thefts

12/05/2019
Maksim Yakubets and his crew stole tens of millions using Zeus and Dridex, with victims including Bank of America, Key Bank, GenLabs, and United Dairy, DoJ says.

With Aporeto, Palo Alto Looks Away from the Firewall and Toward the Future

12/05/2019
Seeing its firewall sales softening, the security vendor makes another acquisition to reorient itself for the cloud era.

10 Security 'Chestnuts' We Should Roast Over the Open Fire

12/05/2019
These outdated security rules we all know (and maybe live by) no longer apply.

SOC 2s & Third-Party Assessments: How to Prevent Them from Being Used in a Data Breach Lawsuit

12/05/2019
Assessments can be used against your company in court proceedings. Here's how to mitigate this potential risk.

Microsoft Defender ATP Brings EDR Capabilities to macOS

12/05/2019
Mac computers will now have the option to use Microsoft Defender Advanced Threat Protection's endpoint and detection response.

The Human Factor: 5 Reasons Why Cybersecurity Is a People Problem

12/05/2019
The industry can only go so far in treating security as a challenge that can be resolved only by engineering.

Black Hat Europe Q&A: Understanding the Ethics of Cybersecurity Journalism

12/04/2019
Investigative journalist Geoff White chats about why now is the right time for his Black Hat Europe Briefing on hackers, journalists, and the ethical ramifications of cybersecurity journalism.

Shades of Shamoon: New Disk-Wiping Malware Targets Middle East Orgs

12/04/2019
'ZeroCleare' shares some of the same features as its more notorious predecessor, IBM Security says.

(Literally) Put a Ring on It: Protecting Biometric Fingerprints

12/04/2019
Kaspersky creates a prototype ring you can wear on your finger for authentication.

The Edge Cartoon Contest: You Better Watch Out ...

12/04/2019
Feeling creative this holiday season? Submit your caption in the comments, and our panel of experts will reward the winner with a $25 Amazon gift card.

Navigating Security in the Cloud

12/04/2019
Underestimating the security changes that need to accompany a shift to the cloud could be fatal to a business. Here's why.

Microsoft Issues Advisory for Windows Hello for Business

12/04/2019
An issue exists in Windows Hello for Business when public keys persist after a device is removed from Active Directory, if the AD exists, Microsoft reports.

Attackers Continue to Exploit Outlook Home Page Flaw

12/04/2019
FireEye issues guidance on locking down Outlook, claiming that security researchers, at least, are able to work around the patch issued by Microsoft.

Application & Infrastructure Risk Management: You've Been Doing It Backward

12/04/2019
Before getting more scanning tools, think about what's needed to defend your organization's environment and devise a plan to ensure all needed tools can work together productively.

TrickBot Expands in Japan Ahead of the Holidays

12/03/2019
Data indicates TrickBot operators are modifying its modules and launching widespread campaigns around the world.

When Rogue Insiders Go to the Dark Web

12/03/2019
Employees gone bad sell stolen company information, sometimes openly touting their companies, researchers say.

What Security Leaders Can Learn from Marketing

12/03/2019
Employees can no longer be pawns who must be protected all the time. They must become partners in the battle against threats.

Smith & Wesson Is Magecart's Latest Target

12/03/2019
Researchers estimate the gun manufacturer's website was compromised sometime before Black Friday.

Siemens Offers Workarounds for Newly Found PLC Vulnerability

12/03/2019
An undocumented hardware-based special access feature recently found by researchers in Siemens' S7-1200 can be used by attackers to gain control of the industrial devices.