Dark Reading

Extortion Economics: Ransomware's New Business Model

11/08/2022
Ransomware-as-a-service lowers the barriers to entry, hides attackers’ identities, and creates multitier, specialized roles in service of ill-gotten gains.

Instagram Star Gets 11 Years for Cybercrimes Used to Fund His Lavish Lifestyle

11/08/2022
Prolific online scammer and social media influencer 'Hushpuppi' sentenced for bank cyber heists, BEC campaigns, money laundering, and more.

It's Time to See Cybersecurity Regulation as a Friend, Not a Foe

11/08/2022
There's real value in having a better perspective around future regulation and compliance requirements.

Cyber.org Range Offers Cybersecurity Job Paths for K-12 Students

11/08/2022
The classroom-based curriculum addresses the cybersecurity workforce gap with free training labs and virtual cyberattack environments to hone the skills of the next generation of talent.

The Shifting Role of the CISO

11/08/2022
My year as a venture capital CISO-in-residence.

Bugcrowd Names David Gerry Chief Executive Officer

11/08/2022
AppSec and Cybersecurity veteran will leverage his strong institutional experience as demand for crowdsourced cybersecurity solutions grows.

Retail Sector Prepares for Annual Holiday Cybercrime Onslaught

11/08/2022
Retailers and hospitality companies expect to battle credential harvesting, phishing, bots, and various malware variants.

Living Security and CybSafe Propose the First Human Risk Management Maturity Model

11/08/2022
Call on security industry to collaborate on a standard framework to close the gap on the human element in cybersecurity.

OpenText Security Solutions Global SMB Ransomware Survey Reveals Heightened Worry about Increased Cyberattacks Due to Ge

11/08/2022
SMBs concerned about tightening security budgets despite increased risks.

How Does DNS Telemetry Help Detect and Stop Threats?

11/07/2022
Administrators and security teams who have lost visibility into their own networks can use DNS telemetry to home in on anomalous traffic.

Microsoft's Certificate-Based Authentication Enables Phishing-Resistant MFA

11/07/2022
Microsoft added certificate-based authentication (CBA) to the Azure Active Directory to help organizations enable phishing-resistant MFA that complies with US federal requirements. The change paves the way for enterprises to migrate their Active Directory implementations to the cloud.

SolarWinds Faces Potential SEC Enforcement Act Over Orion Breach

11/07/2022
In the nearly two years since the company discovered the cyber intrusion, SolarWinds has fundamentally rearchitected its development environment to make it much harder to compromise, CISO Tim Brown tells Dark Reading.

National Guard Cyber Forces 'Surging' to Help States Protect Midterm Elections

11/07/2022
Fourteen states, including Arizona, Iowa, and Pennsylvania, have called in the Guard to help with election network risk assessments and threat mitigation.

Cybercrime Group OPERA1ER Stole $11M From 16 African Businesses

11/07/2022
One attack used 400 mule accounts to steal money by making fraudulent withdrawals, researchers say.

Unencrypted Traffic Still Undermining Wi-Fi Security

11/07/2022
An analysis by RSA Conference's security operations center found 20% of data over its network was unencrypted and more than 55,000 passwords were sent in the clear.

OpenText Security Solutions Global SMB Ransomware Survey Reveals Heightened Worry About Increased Cyberattacks Due to Ge

11/07/2022
SMBs concerned about tightening security budgets despite increased risks.

Out of Stealth: New SURF Zero-Trust Enterprise Browser

11/07/2022
Investment round led by 11.2 Capital, Okta Ventures, and Mango Capital.

Beyond the Pen Test: How to Protect Against Sophisticated Cybercriminals

11/07/2022
Why are we still doing perfunctory penetration testing when we can be emulating realistic threats and stress-testing the systems most at risk?

Human Security Tackles Malvertising With Clean.io Buy

11/04/2022
Dark Reading's analysis suggests that Human Security's acquisition of clean.io will significantly expand the company's fraud prevention and anti-malvertising portfolio.

Microsoft Warns on Zero-Day Spike as Nation-State Groups Shift Tactics

11/04/2022
The software giant also recorded an increase in attacks on IT services companies as state-backed threat actors have adapted to better enterprise defenses and cast a wider net, Microsoft says.