Dark Reading

High-Severity Bug in Kaspersky VPN Client Opens Door to PC Takeover

08/04/2022
The CVE-2022-27535 local privilege-escalation security vulnerability in the security software threatens remote and work-from-home users.

How Email Security Is Evolving

08/04/2022
Securing email communication has never been more critical for organizations, and it has never been more challenging to do so. Attack volumes have increased and become more sophisticated.

Massive China-Linked Disinformation Campaign Taps PR Firm for Help

08/04/2022
A global network of inauthentic news sites present themselves as independent news outlets, offering content favoring China's government and articles critical of the US.

Phylum Releases a Free Community Edition to Make Software Supply Chain Security More Accessible

08/04/2022
Users can identify risks across five domains, work on multiple projects, and take advantage of exclusive community benefits.

The Myth of Protection Online — and What Comes Next

08/04/2022
It's a myth that consuming and processing alerts qualifies as security. Today's technology allows better detection and prevention, rather than accepting the low bar for protection set by ingrained incident response reactions.

Deep Instinct Pioneers Deep-Learning Malware Prevention to Protect Mission-Critical Business Applications at Scale

08/04/2022
Agentless approach meets the attacker earlier to protect financial services and other large enterprises from an underserved attack vector.

35K Malicious Code Insertions in GitHub: Attack or Bug-Bounty Effort?

08/04/2022
In the last month, "Pl0xP" cloned several GitHub repositories, adding malicious code to the forks that would attempt to infect developer systems and steal sensitive files that included software keys.

Ping Identity to Go Private After $2.8B Acquisition

08/04/2022
The identity-services company is being acquired by Thoma Bravo software investment for cash, before being delisted.

Startup Footprint Tackles Identity Verification

08/03/2022
Early-stage startup Footprint's goal is to provide tools that change how enterprises verify, authentication, authorize, and secure identity.

How IT Teams Can Use 'Harm Reduction' for Better Cybersecurity Outcomes

08/03/2022
Copado's Kyle Tobener will discuss a three-pronged plan at Black Hat USA for addressing human weaknesses in cybersecurity with this medical concept — from phishing to shadow IT.

Critical RCE Bug in DrayTek Routers Opens SMBs to Zero-Click Attacks

08/03/2022
SMBs should patch CVE-2022-32548 now to avoid a host of horrors, including complete network compromise, ransomware, state-sponsored attacks, and more.

School Kid Uploads Ransomware Scripts to PyPI Repository as 'Fun' Project

08/03/2022
The malware packages had names that were common typosquats of a legitimate widely used Python library. One was downloaded hundreds of times.

Cyberattackers Drain Nearly $6M From Solana Crypto Wallets

08/03/2022
So far, the ongoing attack has impacted nearly 8,000 Solana hot wallets.

Zero-Day Defense: Tips for Defusing the Threat

08/03/2022
Because they leave so little time to patch and defuse, zero-day threats require a proactive, multilayered approach based on zero trust.

ShiftLeft Appoints Prevention-First, Cybersecurity Visionary and AI/ML Pioneer Stuart McClure as CEO

08/03/2022
Serial entrepreneur, cybersecurity leader, and industry veteran joins ShiftLeft to drive growth and AI/ML innovation globally.

Druva Introduces the Data Resiliency Guarantee of up to $10 Million

08/03/2022
The new program offers robust protection across all five data risk categories: cyber, human, application, operation, and environmental.

CompTIA CEO Outlines Initiative to Create the Pre-eminent Destination to Start, Build and ‘Supercharge’ a Tech Caree

08/03/2022
Todd Thibodeaux uses ChannelCon 2022 state of the industry remarks to unveil CompTIA’s Project Agora; invites broad industry participation in the effort to fight for tech talent.

Netskope Acquires Infiot, Will Deliver Fully Integrated, Single-Vendor SASE Platform

08/03/2022
Converged SASE platform provides AI-driven Zero trust security and simplified, optimized connectivity to any network location or device, including IoT.

American Express, Snapchat Open-Redirect Vulnerabilities Exploited in Phishing Scheme

08/03/2022
Phishing operators are taking advantage of security bugs in the Amex and Snapchat websites (the latter is unpatched) to steer victims to phishing pages looking to harvest Google and Microsoft logins.

Thousands of Mobile Apps Leaking Twitter API Keys

08/02/2022
New finding comes amid report of overall surge in threats targeting mobile and IoT devices over the past year.