Dark Reading

The Overlooked Problem of 'N-Day' Vulnerabilities

03/26/2018
N-days -- or known vulnerabilities -- are a goldmine for attackers of industrial control systems. It's time for a new defense strategy.

AMD Will Release Fixes for New Processor Flaws in a Few Weeks

03/23/2018
Security firm that disclosed flaws accuses chipmaker of downplaying flaws; says timeline is overly optimistic.

City of Atlanta Hit with Ransomware Attack

03/23/2018
FBI investigating computer outages in the city's network possibly tied to Samsam-type ransomware variant.

Winners and Losers in Password 'Bracketology'

03/23/2018
A recent study shows that there's a clear winner in the 'most used sports mascot' password competition.

DoJ Indicts 9 Iranians for Hacking into Hundreds of Universities, FERC, Dept. of Labor, Others

03/23/2018
Suspects were operating on behalf of Iranian government and the Iranian Revolutionary Guard, US officials said.

Looking Back to Look Ahead: Cyber Threat Trends to Watch

03/23/2018
Data from the fourth quarter of last year shows the state of application exploits, malicious software, and botnets.

Looking Back and Thinking Ahead on Cyberwar, Nation-State Attacks

03/23/2018
In the domain of cyber warfare, the effective strategies for fighting yesterday's cyberattacks will not work against tomorrow's, experts said.

New Survey Illustrates Real-World Difficulties in Cloud Security

03/22/2018
Depending on traditional models makes cloud security more challenging for organizations, according to a Barracuda Networks report.

Criminals Using Web Injects to Steal Cryptocurrency

03/22/2018
Man-in-the-browser attacks targeting Blockchain.info and Coinbase websites, SecurityScorecard says.

Is Application Security Dead?

03/22/2018
The nature of the field has changed greatly because of the move to the cloud and enterprise digital transformation.

Hunting Cybercriminals with AWS Honey Tokens

03/22/2018
Researchers at Black Hat Asia demonstrated how they used AWS honey tokens to detect security breaches at scale.

US Federal Spending Bill Includes $380 Million for Securing Election Systems

03/22/2018
Spending bill includes election technology grants for states to shore up security of their voting systems, reports say.

5 Ways to Get Ready for Public Cloud Deployment

03/22/2018
Syncing security and product development early is now a "must do."

7 Ways to Protect Against Cryptomining Attacks

03/22/2018
Implementing basic security hygiene can go a long way in ensuring your systems and website don't get hijacked.

Applications & Identities Initial Targets in 86% of Breaches: Report

03/22/2018
The startling numbers of breached data are sobering: 11.8 billion records compromised in 337 of 433 incidents examined by F5 researchers. They include 10.3 billion usernames, passwords, and email accounts.

Supply Chain Cyberattacks Surged 200% in 2017

03/22/2018
Symantec's annual Internet Security Threat Report also shows that zero-day exploits fizzled and cryptocurrency mining exploded.

GandCrab Ransomware Goes 'Agile'

03/21/2018
GandCrab ransomware's developers have iterated the code rapidly, researchers found.

Gartner Expects 2018 IoT Security Spending to Reach $1.5 Billion

03/21/2018
Regulations, breach concerns will push spending to over $3 billion by 2021, analyst firm says.

SOC in Translation: 4 Common Phrases & Why They Raise Flags

03/21/2018
By keeping an ear out for out for catchphrases like "Just ask Stu" or "I've got a bad feeling about this," CISOs can overcome the barriers that get between business leaders and their security teams.

DHS Chief: Election Security Now Top Priority Among Critical Systems

03/21/2018
Homeland Security Secretary Kirstjen Nielsen told Congress today that her department is working to assist states with their election systems' security.