Dark Reading

Sharing Knowledge at 44CON

10/06/2022
The infosec conference named after the UK's calling code returned this year with a focus on building a healthy community.

macOS Archive Utility Bug Lets Malicious Apps Bypass Security Checks

10/06/2022
Exploit allows unsigned and unnotarized macOS applications to bypass Gatekeeper and other security, without notifying the user.

Russian Hackers Shut Down US State Government Websites

10/06/2022
Russian-speaking cyberattackers boast they are behind disruption of Colorado, Kentucky, and Mississippi government websites.

US Consumers Are Finally Becoming More Security & Privacy Conscious

10/06/2022
The trend, spotted by Consumer Reports, could mean good news for organizations struggling to contain remote work challenges.

Hackers Have It Out for Microsoft Email Defenses

10/06/2022
Cybercriminals are focusing more and more on crafting special email attacks that evade Microsoft Defender and Office security.

Russia-Linked Cybercrime Group Hawks Combo of Malicious Services With LilithBot

10/06/2022
The malware-as-a-service group Eternity is selling a one-stop shop for various malware modules it's been distributing individually via a subscription model on Telegram.

School Is in Session: 5 Lessons for Future Cybersecurity Pros

10/06/2022
Opportunities in the field continue to grow — and show no signs of slowing down.

7 IoT Devices That Make Security Pros Cringe

10/06/2022
A look at everything from truly dumb smart devices to cool-looking IoT tech with huge cybersecurity and privacy implications.

New SonicWall Survey Data Reveals 91% of Organizations Fear Ransomware Attacks in 2022

10/06/2022
Amid an economic downturn, cybersecurity staffing shortages, and endless cyberattacks, financially motivated attacks are the top concern among IT professionals.

Research Reveals Microsoft Teams Security and Backup Flaws, With Over Half of Users Sharing Business-Critical Informatio

10/06/2022
Most backup and security vendors overlook this vital communication channel.

Contrast Security Launches Expanded Security Testing Tools for JavaScript and Popular Angular, React, and jQuery Framewo

10/06/2022
New language and framework support empowers developers to analyze front-end code for vulnerabilities throughout the development lifecycle.

Relentless Russian Cyberattacks on Ukraine Raise Important Policy Questions

10/05/2022
Microsoft cybersecurity executive John Hewie explained cyberwar developments and what they mean for Western democratic policy going forward.

Ikea Smart Light System Flaw Lets Attackers Turn Bulbs on Full Blast

10/05/2022
With just one malformed Zigbee frame, attackers could take over certain Ikea smart lightbulbs, leaving users unable to turn the lights down.

CISA: Multiple APT Groups Infiltrate Defense Organization

10/05/2022
Advanced attackers gained access to Microsoft Exchange services, conducted searches of email, and used an open source toolkit to collect data from the network for nearly a year.

Secure Your Application Layer, Secure Your Business

10/05/2022
Users and malicious actors interact with your business through the application layer. Build trust in your software by securing this first line of defense.

NullMixer Dropper Delivers a Multimalware Code Bomb

10/05/2022
In one shot, Trojan dropper NullMixer installs a suite of downloaders, banking Trojans, stealers, and spyware on victims' systems.

Giving Away the Keys to Your Backups? Here’s How to Keep Out Hackers

10/05/2022
As threat actors' sophistication has grown dramatically in the last few years, organizations haven't kept up with implementing the necessary countermeasure controls.

NetSPI Raises $410 Million in Growth Funding from KKR

10/05/2022
New investment to fuel the offensive security leader's record-breaking growth and innovation pipeline.

7 Practical Considerations for Effective Threat Intelligence

10/05/2022
If your security team is considering, planning, building, or operating a threat intelligence capability, this advice can help.

Why Don't CISOs Trust Their Employees?

10/05/2022
Executives fear "malicious insiders" as top cyber threat to companies, research shows. Reasonable steps to secure and monitor systems may prevent reputational damage but are not enough.