Dark Reading

5 Lessons Learned From Hundreds of Penetration Tests

03/13/2023
Developers must balance creativity with security frameworks to keep applications safe. Correlating business logic with security logic will pay in safety dividends.

And the Cyberattack Goes To ... Oscar-Nominated Film Fans

03/10/2023
With the rise of cybercriminals targeting online piracy, this year's Oscar-nom fans need to be especially careful not to download malicious files while attempting to watch popular films for free.

ChatGPT Browser Extension Hijacks Facebook Business Accounts

03/10/2023
Between March 3 and March 9, at least 2,000 people a day downloaded the malicious "Quick access to ChatGPT" Chrome extension from the Google Play app store.

Pig Butchering & Investment Scams: The $3B Cybercrime Threat Overtaking BEC

03/10/2023
A novel take on investment scams mixes romance and the lure of crypto riches to con targets out of "the whole hog" of their assets.

Unpatched Zero-Day Bugs in Smart Intercom Allow Remote Eavesdropping

03/10/2023
A video-enabled smart intercom made by Chinese company Akuvox has major security vulnerabilities that allow audio and video spying, and the company has so far been unresponsive to the discoveries.

Make Sure Your Cybersecurity Budget Stays Flexible

03/10/2023
CISOs' ability to pivot tight budgets is key to defense plans that can stand up to attackers.

Proposed FCC Rule Redefines Data Breaches for Communications Carriers

03/09/2023
If the proposed rule is approved, organizations would need to disclose all data breaches, even ones that don't cause any harm, to affected customers.

Avast Introduces Avast One Platinum

03/09/2023
New premium service provides all-in-one personal protection beyond device security to include identity restoration and unlimited 24/7 tech support.

Forrester Study Reveals Businesses Are Insufficiently Prepared to Manage Enterprise Risks

03/09/2023
Study underscores the clear and pressing need for real-time physical and cyber threat alerts for effective enterprise risk management and business resilience.

ThreatBlockr Announces Partnership With Engaged Security Partners

03/09/2023
This strategic partnership highlights the importance of breach prevention and creating a proactive security culture.

IceFire Ransomware Portends a Broader Shift From Windows to Linux

03/09/2023
IceFire has changed up its OS target in recent cyberattacks, emblematic of ransomware actors increasingly targeting Linux enterprise networks, despite the extra work involved.

AT&T Vendor Breach Exposes Data on 9M Wireless Accounts

03/09/2023
AT&T is notifying customers of a Customer Proprietary Network Information compromise, exposing years-old upgrade details.

5 Reasons You Should Care About Unmanaged Assets

03/09/2023
Unmanaged devices pose a significant challenge and risk for many organizations. Here are the five reasons you should care about unmanaged devices and assets.

Inside Threat: Developers Leaked 10M Credentials, Passwords in 2022

03/09/2023
More than five out of every 1,000 commits to GitHub included a software secret, half again the rate in 2021, putting applications and businesses at risk.

How to Jump-Start Your Cybersecurity Career

03/09/2023
With more than 700,000 cybersecurity jobs available, now is a good time to consider a career change.

Iranian APT Targets Female Activists With Mahsa Amini Protest Lures

03/09/2023
A top Iranian, state-sponsored threat is a spear-phishing campaign that uses a fake Twitter persona to target women interested in Iranian political affairs and human rights.

Critical RCE Bug Opens Fortinet's Secure Web Gateway to Takeover

03/09/2023
Users should patch an unauthenticated remote code execution bug impacting FortiOS and FortiProxy administrative interfaces ASAP, Fortinet says.

5 Critical Components of Effective ICS/OT Security

03/09/2023
These agile controls and processes can help critical infrastructure organizations build an ICS security program tailored to their own risk profile.

'Skinny' Cyber-Insurance Policies Create Compliance Path

03/08/2023
It's getting hard to buy cyber insurance, but not having it is not always an option. Low-coverage plans could bridge the gap.

Edgeless Systems Raises $5M to Advance Confidential Computing

03/08/2023
Confidential computing will revolutionize cloud security in the decade to come and has become a top C-level priority for industry leaders such as Google, Intel and Microsoft. Edgeless Systems is leading these advancements to ensure all data is always encrypted.