Dark Reading

Quantum Decryption Breakthrough? Not So Fast

01/10/2023
A paper by two dozen Chinese researchers maintains that near-future quantum computers could crack RSA-2048 encryption, but experts call the claims misleading.

Microsoft: Kinsing Targets Kubernetes via Containers, PostgreSQL

01/10/2023
The cryptomining malware, which typically targets Linux, is exploiting weaknesses in an open source container tool for initial access to cloud environments.

NetSPI Acquires nVisium

01/10/2023
nVisium's cloud and application security experts join NetSPI to support, scale, and deliver the most comprehensive suite of offensive security solutions.

Vade Releases Advanced Threat Intel & Investigation Capabilities

01/10/2023
New Add-On Empowers SOCs and MSPs to Automate & Orchestrate Incident Response for Microsoft 365.

65% of Organizations Plan to Adopt a Security Service Edge Platform in Next 2 Years: Axis Security

01/10/2023
2023 Security Service Edge (SSE) Adoption Report finds that SSE technology addresses key pain points including much-needed solution consolidation, transition to hybrid work and need for hardened security.

Netskope Threat Research: Malware-Delivering Cloud Apps Nearly Tripled in 2022

01/10/2023
401 distinct cloud apps shown to deliver malware; Microsoft OneDrive delivered 30% of all cloud malware downloads.

Preparing for the Effects of Quantum-Centric Supercomputing

01/10/2023
While it has been a perennial forecast that efficient universal quantum computers are “a decade away,” that prospect now seems a legitimate possibility. Organizations need to get ready now.

Delinea 2022 State of Ransomware Report Reveals That Attacks Are Down 61% From the Previous Year, and Ransom Payments Ar

01/10/2023
Annual survey uncovers surprising data but warns against complacency.

Moving Analytics Launches Single Sign on to Strengthen Data Security and Improve User Experience

01/10/2023
Moving Analytics, leading provider of virtual cardiac rehabilitation and prevention, announced that it is launching single sign on authentication for its entire software platform.

Black Hat Flashback: The Deadly Consequences of Weak Medical Device Security

01/10/2023
Hacking to kill: Dark Reading's Fahmida Y. Rashid reflects on the monumental Black Hat 2011 moment when Jay Radcliffe showed how to hack his insulin pump.

Latest Firmware Flaws in Qualcomm Snapdragon Need Attention

01/09/2023
The issue concerns the boot layer of ARM chips, which are driving a low-power mobile ecosystem that includes 5G smartphones and base stations.

Attackers Are Already Exploiting ChatGPT to Write Malicious Code

01/09/2023
The AI-based chatbot is allowing bad actors with absolutely no coding experience to develop malware.

Serbia Slammed With DDoS Attacks

01/09/2023
The Serbian government reports that it staved off five attacks aimed at crippling Serbian infrastructure.

Rackspace Ransomware Incident Highlights Risks of Relying on Mitigation Alone

01/09/2023
Organizations often defer patching because of business disruption fears — but that didn't work out very well for Rackspace's Hosted Exchange service.

'Copyright Infringement' Lure Used for Facebook Credential Harvesting

01/09/2023
Business users receive a message from Facebook warning their accounts will be permanently suspended for using photos illegally if they don't appeal within 24 hours, leading victims to a credential-harvesting page instead.

JsonWebToken Security Bug Opens Servers to RCE

01/09/2023
The JsonWebToken package plays a big role in the authentication and authorization functionality for many applications.

7 Use Cases for Distributed Cloud Environments

01/09/2023
As infrastructure has grown more complex, the need to effectively manage it has grown, too – particularly for applications and APIs.

Web 3.0 Shifts Attack Surface and Highlights Need for Continuous Security

01/09/2023
A model of continuous authentication and identification is needed to keep consumers safe.

In Memoriam: Remembering Those Who Passed

01/06/2023
Security stands on the shoulders of giants. We take a moment to remember their contributions toward keeping people, data, and systems safe.

Russia-Linked Turla APT Sneakily Co-Opts Ancient Andromeda USB Infections

01/06/2023
Using command-and-control servers from the decade-old Andromeda malware, the group is installing reconnaissance tools and a backdoor on previously infected systems to target Ukrainian victims.