Dark Reading

CyberRatings.org Announces Results from First-of-its-Kind Comparative Test on Cloud Network Firewall

12/01/2022
Ratings ranged from AAA to CC, with security effectiveness scores from 27% to 100%.

CI Fuzz CLI Brings Fuzz Testing to Java Applications

11/30/2022
CI Fuzz CLI, the open source fuzzing tool with just three commands, integrates fuzz testing directly into the software development workflow.

Nvidia GPU Driver Bugs Threaten Device Takeover & More

11/30/2022
If unpatched, a host of GPU Display Driver flaws could expose gamers, graphic designers, and others to code execution, denial of service, data tampering, and more.

Google TAG Warns on Emerging Heliconia Exploit Framework for RCE

11/30/2022
The framework has ties back to a Spanish exploit broker called Variston IT, and offers a one-stop shop for compromising Chrome, Defender and Firefox.

How Banks Can Upgrade Security Without Affecting Client Service

11/30/2022
New protective measures work behind the scenes, with little impact on the customer experience.

New Exploit Broker on the Scene Pays Premium for Signal App Zero-Days

11/30/2022
Signal messaging app zero-day vulnerabilities have sparked a $1.5M bidding match, as gray-market exploit brokers flourish in today's geopolitical climate.

SPHERE Receives $31M for Series B Funding From Edison Partners, Forgepoint Capital

11/30/2022
New investment will accelerate growth and expansion of SaaS identity-hygiene platform.

The Evolution of Business Email Compromise

11/30/2022
The simplicity and profitability of these attacks continue to appeal to threat actors a decade later.

API Secrets: Where the Bearer Model Breaks Down

11/30/2022
Current authentication methods are based on the bearer model, but lack of visibility into the entities leveraging API secrets has made this untenable.

Critical Quarkus Flaw Threatens Cloud Developers With Easy RCE

11/30/2022
Red Hat has issued patches for a bug in an open source Java virtual machine software that opens the door to drive-by localhost attacks. Patch now, as it's easy for cyberattackers to exploit.

Identity Digital Releases Its First DNS Anti-Abuse Report

11/30/2022
The quarterly report, made possible by its Dynamic Defense™ service, demonstrates significant progress in mitigating domain abuse among its top-level domains (TLDs).

Delinea Introduces Granular Privileged Access Controls on Servers

11/30/2022
New functionality further reduces the risk of lateral movement.

CyberRatings.org Revives NSS Labs Research

11/30/2022
The NSS Labs archive, available with free registration, consists of over 800 test reports, analyst briefs, and research published by NSS Labs from 2013 — 2020.

Connect the Dots with Genetic Algorithms on CNAPP

11/29/2022
Cloud-native application protection platforms can apply machine-learning algorithms on cloud data to identify accounts with abnormal permissions and uncover potential threats.

Microsoft Defender Gets New Security Protections

11/29/2022
The new Microsoft Defender for Endpoint capabilities include built-in protection and scanning network traffic for malicious activity.

How to Use Cyber Deception to Counter an Evolving and Advanced Threat Landscape

11/29/2022
Organizations must be prepared to root out bad actors by any means possible, even if it means setting traps and stringing lures.

Cyberattackers Selling Access to Networks Compromised via Recent Fortinet Flaw

11/29/2022
The vulnerability, disclosed In October, gives an unauthenticated attacker a way to take control of an affected product.

Oracle Fusion Middleware Flaw Flagged by CISA

11/29/2022
The bug could allow unauthorized access and takeover, earning it a spot on the Known Exploited Vulnerabilities Catalog.

The Metaverse Could Become a Top Avenue for Cyberattacks in 2023

11/29/2022
Expect to see attackers expand their use of current consumer-targeting tactics while exploring new ways to target Internet users — with implications for businesses.