Dark Reading

Don't Have a COW: Containers on Windows and Other Container-Escape Research

07/12/2022
Several pieces of Black Hat USA research will explore container design weaknesses and escalation of privilege attacks that can lead to container escapes.

One-Third of Users Without Security Awareness Training Click on Phishing URLs

07/12/2022
New data from security training provider shows half of untrained users in consulting, energy, and healthcare industries fall for phishing attacks.

5 Traits That Differentiate CISOs From CIROs

07/12/2022
Chief information risk officers must have a keen understanding of — and interaction with — the business.

How Confidential Computing Locks Down Data, Regardless of Its State

07/12/2022
Whether data's in motion, at rest, or in use, confidential computing makes moving workloads to the public cloud safer, and can enhance data security in other deployments.

Accessible Cybersecurity Awareness Training Reduces Your Risk of Cyberattack

07/12/2022
If you're not teaching all of your employees proper security hygiene, you are leaving the door open to risk. Close that door by providing accessible training.

Ransomware Scourge Drives Price Hikes in Cyber Insurance

07/12/2022
Cybersecurity insurance costs are rising, and insurers are likely to demand more direct access to organizational metrics and measures to make more accurate risk assessments.

Paladin Cloud Launches New Cloud Security and Governance Platform

07/11/2022
The new open source security-as-code platform will help developers and security teams automatically detect security policy violations across the organization's cloud infrastructure.

Fake Google Software Updates Spread New Ransomware

07/11/2022
"HavanaCrypt" is also using a command-and-control server that is hosted on a Microsoft Hosting Service IP address, researchers say.

'Luna Moth' Group Ransoms Data Without the Ransomware

07/11/2022
Unsophisticated campaigns use off-the-shelf RATs and other tools to exfiltrate data and demand a ransom to keep it private.

Online Payment Fraud Expected to Cost $343B Over Next 5 Years

07/11/2022
Fraudster innovation will continue to drive successful phishing, business email compromise, and socially engineered attacks, researchers say.

Proposed SEC Rules Require More Transparency About Cyber-Risk

07/11/2022
The new guidelines would require public companies to file periodic disclosures about their cybersecurity practices and notify the SEC within 96 hours of a material breach.

Diversity in Cybersecurity: Fostering Gender-Inclusive Teams That Perform Better

07/11/2022
Proactive steps in recruiting women to cybersecurity teams, along with policies focused on diversity, equity, and inclusion, help make cybersecurity teams more effective. Addressing specific barriers that female candidates face will make those teams more inclusive and more representative.

New Phishing Attacks Shame, Scare Victims into Surrendering Twitter, Discord Credentials

07/11/2022
Scams pressure victims to "resolve an issue that could impact their status, business."

Microsoft Reverses Course on Blocking Office Macros by Default

07/08/2022
Security experts criticize company for reversing course, albeit temporarily, on a decision it made just this February to block macros in files downloaded from the Internet.

DoJ Charges CEO for Dealing $1B in Fake Cisco Gear

07/08/2022
Fraudster allegedly passed off refurbished, modified Cisco equipment as new to hospitals, schools, and even the military.

Welcome-Back-to-the-Future Shock

07/08/2022
This year's RSA Conference saw a strange mix of selling the future and the past — for good reason.