Dark Reading

Cohesity Research Reveals that Reliance on Legacy Technology Is Undermining How Organizations Respond to Ransomware

08/30/2022
Nearly half of respondents say their company relies on outdated backup and recovery infrastructure — in some cases dating back to the 1990s, before today's sophisticated cyberattacks.

Phishing Campaign Targets PyPI Users to Distribute Malicious Code

08/30/2022
The first-of-its-kind campaign threatens to remove code packages if developers don’t submit their code to a "validation" process.

Building a Strong SOC Starts With People

08/30/2022
A people-first approach reduces fatigue and burnout, and it empowers employees to seek out development opportunities, which helps retention.

Google Expands Bug Bounties to Its Open Source Projects

08/30/2022
The search engine giant's Vulnerability Rewards Program now covers any Google open source software projects — with a focus on critical software such as Go and Angular.

Cerberus Sentinel Announces Acquisition of CUATROi

08/30/2022
US cybersecurity services firm expands services in Latin America.

A Peek Into CISA's Post-Quantum Cryptography Roadmap

08/29/2022
To help organizations with their plans, NIST and the Department of Homeland Security developed the Post-Quantum Cryptography Roadmap.

Receipt for €8M iOS Zero-Day Sale Pops Up on Dark Web

08/29/2022
Documents appear to show that Israeli spyware company Intellexa sold a full suite of services around a zero-day affecting both Android and iOS ecosystems.

3 Ways No-Code Developers Can Shoot Themselves in the Foot

08/29/2022
Low/no-code tools allow citizen developers to design creative solutions to address immediate problems, but without sufficient training and oversight, the technology can make it easy to make security mistakes.

Cyber-Insurance Firms Limit Payouts, Risk Obsolescence

08/29/2022
Businesses need to re-evaluate their cyber-insurance policies as firms like Lloyd's of London continue to add restrictions, including excluding losses related to state-backed cyberattackers.

NATO Investigates Dark Web Leak of Data Stolen from Missile Vendor

08/29/2022
Documents allegedly belonging to an EU defense dealer include those relating to weapons used by Ukraine in its fight against Russia.

The 3 Questions CISOs Must Ask to Protect Their Sensitive Data

08/29/2022
CISOs must adopt a new mindset to take on the moving targets in modern cybersecurity.

LastPass Suffers Data Breach, Source Code Stolen

08/26/2022
Researchers warned that cyberattackers will be probing the code for weaknesses to exploit later.

'Sliver' Emerges as Cobalt Strike Alternative for Malicious C2

08/26/2022
Microsoft and others say they have observed nation-state actors, ransomware purveyors, and assorted cybercriminals pivoting to an open source attack-emulation tool in recent campaigns.

'No-Party' Data Architectures Promise More Control, Better Security

08/26/2022
Consumers gain control of their data while companies build better relationships with their customers — but third-party ad-tech firms will likely continue to stand in the way.

How DevSecOps Empowers Citizen Developers

08/26/2022
DevSecOps can help overcome inheritance mentality, especially in low- and no-code environments.

Endpoint Protection / Antivirus Products Tested for Malware Protection

08/26/2022
Six out of the eight products achieved an "A" rating or higher for blocking malware attacks. Reports are provided to the community for free.

Capital One Joins Open Source Security Foundation

08/26/2022
OpenSSF welcomes Capital One as a premier member affirming its commitment to strengthening the open source software supply chain.

ReasonLabs Launches Free Online Security Tool to Power Secure Web Experience for Millions of Global Users

08/25/2022
Online Security autonomously blocks malicious URLs, extensions, ad trackers, and pop-ups 24/7, protecting consumers from complex and rapidly evolving cyber threats online.

More Bang for the Buck: Cross-Platform Ransomware Is the Next Problem

08/25/2022
As cryptocurrency valuations make strikes less lucrative, ransomware gangs like the new RedAlert and Monster groups are modifying their tools to attack across platforms.

Wyden Renews Call to Encrypt Twitter DMs, Secure Americans' Data From Unfriendly Foreign Governments

08/25/2022
Following whistleblower complaint, Oregon senator renews commitment to passing bipartisan legislation to address the national security risks.