Dark Reading

Palo Alto Networks Announces Medical IoT Security to Protect Connected Devices Critical to Patient Care

12/05/2022
The comprehensive zero trust security solution for medical devices lets healthcare organizations automate zero trust policy recommendations and manage new connected technologies quickly and securely.

OpenSSF Membership Exceeds 100, With Many New Members Dedicated to Securing Open Source Software

12/05/2022
Introduces a "Developing Secure Software" training course in Japanese at OpenSSF Day Japan.

Infostealer Malware Market Booms, as MFA Fatigue Sets In

12/05/2022
The successful combo of stolen credentials and social engineering to breach networks is increasing demand for infostealers on the Dark Web.

The Privacy War Is Coming

12/05/2022
Privacy standards are only going to increase. It's time for organizations to get ahead of the coming reckoning.

Ransomware Professionalization Grows as RaaS Takes Hold

12/05/2022
As ransomware's prevalence has grown over the past decade, leading ransomware groups such as Conti have added services and features as part of a growing trend toward professionalization.

Malware Authors Inadvertently Take Down Own Botnet

12/05/2022
A single improperly formatted command has effectively killed KmsdBot botnet, security vendor says.

Concern Over DDoS Attacks Falls Despite Rise in Incidents

12/02/2022
Almost a third of respondents in Fastly's Fight Fire with Fire survey view data breaches and data loss as the biggest cybersecurity threat.

SiriusXM, MyHyundai Car Apps Showcase Next-Gen Car Hacking

12/02/2022
A trio of security bugs allow remote attackers to unlock or start the car, operate climate controls, pop the trunk, and more — all via poorly coded mobile apps.

Newsroom Sues NSO Group for Pegasus Spyware Compromise

12/02/2022
Journalists in El Salvador haul NSO Group to US court for illegal surveillance that ultimately compromised their safety.

Where Advanced Cyberttackers Are Heading Next: Disruptive Hits, New Tech

12/02/2022
Following a year of increasingly disruptive attacks, advanced persistent threat groups will likely only become emboldened in 2023, security experts say.

SOC Turns to Homegrown Machine Learning to Catch Cyber-Intruders

12/02/2022
A do-it-yourself machine-learning system helped a French bank detect three types of exfiltration attacks missed by current rules-based systems, attendees will learn at Black Hat Europe.

A Risky Business: Choosing the Right Methodology

12/02/2022
Rather than regarding risk assessment as a negative exercise, consider it one that benefits your organization's aims, and then translate the risk level to its impact on operations, reputation, or finances.

AWS Unveils Amazon Security Lake at re:Invent 2022

12/01/2022
Amazon Security Lake will allow organizations to create a purpose-built, standards-based data lake to aggregate and store security data.

LastPass Discloses Second Breach in Three Months

12/01/2022
The threat actor behind an August intrusion used data from that incident to access customer data stored with a third-party cloud service provider, and affiliate GoTo reports breach of development environment.

Artifact Poisoning in GitHub Actions Imports Malware via Software Pipelines

12/01/2022
A vulnerability discovered in GitHub Actions could allow an attacker to poison a developer's pipeline, highlighting the risk that insecure software pipelines pose.

IBM Cloud Supply Chain Vulnerability Showcases New Threat Class

12/01/2022
The Hell's Keychain attack vector highlights common cloud misconfigurations and secrets exposure that can pose grave risk to enterprise customers.

Of Exploits and Experts: The Professionalization of Cybercrime

12/01/2022
No longer the realm of lone wolves, the world of cybercrime is increasingly strategic, commoditized, and collaborative.

Data Security Concerns Are Driving Changes in US Consumer Behavior and Demands

12/01/2022
As consumers catch on to the dangers, protection could become a major topic for legislative bodies.

Guidehouse Insights Anticipates Market for Automotive Cybersecurity Solutions Will Grow to More Than $445 Billion by 203

12/01/2022
Market drivers include new regulations, increasing automobile complexity, and new vehicle types.

CyberRatings.org Announces Results from First-of-its-Kind Comparative Test on Cloud Network Firewall

12/01/2022
Ratings ranged from AAA to CC, with security effectiveness scores from 27% to 100%.