Dark Reading

The Ethics of Network and Security Monitoring

03/17/2023
The chances of getting hacked are no longer low. Companies need to rethink their data collection and monitoring strategies to protect employee privacy and corporate integrity.

Low-Budget 'Winter Vivern' APT Awakens After 2-Year Hibernation

03/17/2023
The "underreported" APT has returned to focus after attacks promoting Russian and Belarusian government interests and going after targets with humor, zest, and scrappiness.

Meta Proposes Revamped Approach to Online Kill Chain Frameworks

03/17/2023
A more holistic model beyond MITRE et al is needed to help defenders better identify and understand commonalities in different online threat campaigns, the Facebook parent company says.

DirectDefense Reports the Top Threats From 2022 and What's Trending for 2023

03/15/2023
Research found that phishing threats were low in 2022, while foreign login activity and application process analysis accounted for nearly 50% of incident alerts.

Cyberattackers Continue Assault Against Fortinet Devices

03/15/2023
Patched earlier this month, a code-execution vulnerability is the latest FortiOS weakness to be exploited by attackers, who see the devices as well-placed targets for initial access operations.

SecurityScorecard Appoints Former US Congressman John Katko As Senior Advisor

03/15/2023
Capitol Hill cybersecurity leader joins the company’s Cybersecurity Advisory Board to drive further adoption of security ratings in the public and private sectors.

'Vile' Gang Duo Breaches Police Database, Impersonates Officers in Extortion Gambit

03/15/2023
Two gang members are being charged for allegedly threatening to release personal information and impersonating law enforcement in an effort to dox victims.

Telerik Bug Exploited to Steal Federal Agency Data, CISA Warns

03/15/2023
An unpatched Microsoft Web server allowed multiple cybersecurity threat groups to steal data from a federal civilian executive branch.

Analysts Spot a Wave of SVB-Related Cyber Fraud Striking the Business Sector

03/15/2023
Over the weekend, cybercriminals laid the groundwork for Silicon Valley Bank-related fraud attacks that they're now starting to cash in on. Businesses are the targets and, sometimes, the enablers.

Meet Data Privacy Mandates With Cybersecurity Frameworks

03/15/2023
Protection laws are always evolving. Here's how you can streamline your compliance efforts .

GoatRAT Android Banking Trojan Targets Mobile Automated Payment System

03/15/2023
The new malware was discovered targeting three banks in Brazil.

Why Security Practitioners Should Understand Their Business

03/15/2023
The sooner CISOs become proactive in understanding the flip side of the organizations they protect, the better they'll be at their jobs.

SMBs Orgs Want Help, but Cybersecurity Expertise Is Scarce

03/15/2023
Smaller firms are boosting cybersecurity budgets, but there's a long way to go to address a deep lack of cyber preparedness among SMBs.

Are We Doing Enough to Protect Our Unstructured Data?

03/15/2023
Organizations are coming under pressure to protect their data, but does all data need the same security? To secure it, you first need to know what and where it is.

Google Proposes Reducing TLS Cert Life Span to 90 Days

03/14/2023
Organizations will likely have until the end of 2024 to gain visibility and control over their keys and certificates.

How Patch Tuesday Keeps the Beat After 20 Years

03/14/2023
Patch Tuesday turned security updates from chaotic events into a routine. Here's how we got here and where things might be heading.

Optiv More Than Doubles Federal Presence With ClearShark Acquisition

03/14/2023
Convergence of two leading cybersecurity companies creates federal sector powerhouse.

Microsoft Zero-Day Bugs Allow Security Feature Bypass

03/14/2023
Security vendors urge organizations to fix the actively exploited bugs, in Microsoft Outlook and the Mark of the Web feature, immediately.

LockBit Threatens to Leak Stolen SpaceX Schematics

03/14/2023
The ransomware group sent a message directly to Elon Musk: Pay or the confidential SpaceX information goes up for grabs on the Dark Web.

CISA Trials Ransomware Warning System for Critical Infrastructure Orgs

03/14/2023
An agency team will identify vulnerabilities being exploited by ransomware groups and alert organizations ahead of attacks, CISA says.