darkreading Public RSS feed
- Incident Response Playbooks: Are You Prepared?by James Bruhl on December 2, 2024 at 3:00 pm
The playbooks that accompany your incident response plan provide efficiency and consistency in responses, help reduce downtime and dwell time, and can be a cost-saving and reputational-saving measure for your organization.
- Microsoft Boosts Device Security With Windows Resiliency Initiativeby Jeffrey Schwartz on December 2, 2024 at 1:37 pm
Microsoft is readying a new release of Windows in 2025 that will have significant security controls such as more resilient drivers and “self-defending” operating system kernel.
- How AI Is Enhancing Security in Ridesharingby Rachita Naik on November 29, 2024 at 5:00 pm
Whether it’s detecting fraudulent activity, preventing phishing, or protecting sensitive data, AI is transforming cybersecurity in ridesharing.
- Ransomware Gangs Seek Pen Testers to Boost Qualityby Robert Lemos, Contributing Writer on November 29, 2024 at 2:00 pm
Qualified applicants must be able to test ransomware encryption and find bugs that might enable defenders to jailbreak the malware.
- ‘Operation Undercut’ Adds to Russia Malign Influence Campaignsby Jai Vijayan, Contributing Writer on November 27, 2024 at 6:36 pm
Just like Russia’s Doppelgänger effort, the goal is to spread misinformation about Ukraine and Western efforts to help Ukraine in its war with Russia.
- Sneaky Skimmer Malware Targets Magento Sites Ahead of Black Fridayby Elizabeth Montalbano, Contributing Writer on November 27, 2024 at 5:19 pm
A stealthy JavaScript injection attack steals data from the checkout page of sites, either by creating a fake credit card form or extracting data directly from payment fields.
- How Learning to Fly Made Me a Better Cybersecurity CEOby Yochai Corem on November 27, 2024 at 3:00 pm
The lessons I’ve learned soaring through the skies have extended far beyond the runway.
- Russian Script Kiddie Assembles Massive DDoS Botnetby Jai Vijayan, Contributing Writer on November 27, 2024 at 2:00 pm
Over the past year, “Matrix” has used publicly available malware tools and exploit scripts to target weakly secured IoT devices — and enterprise servers.
- News Desk 2024: The Rise of Cybersecurity Platformsby Becky Bracken, Senior Editor, Dark Reading on November 27, 2024 at 1:37 pm
Enterprise cybersecurity teams tell Omdia’s Maxine Holt that they want to dig out from underneath mounting tech and pivot to a simpler platform model — but they are finding that tricky to pull off.
- News Desk 2024: Can GenAI Write Secure Code?by Becky Bracken, Senior Editor, Dark Reading on November 27, 2024 at 1:10 pm
GenAI’s 30%-50% coding productivity boost comes with a downside — it’s also generating vulnerabilities. Veracode’s Chris Wysopal talks about what he finds out in this News Desk interview during Black Hat USA.
- Microsoft Finally Releases Recall as Part of Windows Insider Previewon November 27, 2024 at 1:06 pm
The preview version now includes multiple security-focused additions Microsoft had promised to add, such as SecureBoot, BitLocker, and Windows Hello.
- Israel Defies VC Downturn With More Cybersecurity Investmentsby Robert Lemos, Contributing Writer on November 27, 2024 at 7:00 am
With a focus on creating technologies for other markets, Israel continues to be a valued destination for venture capital in cybersecurity outside the US and Europe.
- 8 Tips for Hiring and Training Neurodivergent Talentby Joan Goodchild on November 26, 2024 at 9:38 pm
Neurodivergent talent can add so much to a cybersecurity team. How can companies ensure they have the right hiring and onboarding practices in place to help these employees succeed?
- ‘RomCom’ APT Mounts Zero-Day, Zero-Click Browser Escapes in Firefox, Torby Nate Nelson, Contributing Writer on November 26, 2024 at 9:36 pm
The innocuously named Russian-sponsored cyber threat actor has combined critical and serious vulnerabilities in Windows and Firefox products in a zero-click code execution exploit.
- Geico, Travelers Fined $11.3M for Lax Data Securityby Dark Reading Staff on November 26, 2024 at 9:12 pm
New York state regulators punish insurers after cybercriminals illegally access customer info they then used to file scam unemployment claims during the COVID-19 pandemic.
- Salt Typhoon Builds Out Malware Arsenal With GhostSpiderby Nate Nelson, Contributing Writer on November 26, 2024 at 8:13 pm
The APT, aka Earth Estries, is one of China’s most effective threat actors, performing espionage for sometimes years on end against telcos, ISPs, and governments before being detected.
- AWS Rolls Out Updates to Amazon Cognitoby Jennifer Lawinski on November 26, 2024 at 7:02 pm
Amazon Web Services’ identity and access management platform has added new features that help developers implement secure, scalable, and customizable authentication solutions for their applications.
- OpenSea Phishers Aim to Drain Crypto Wallets of NFT Enthusiastsby Elizabeth Montalbano, Contributing Writer on November 26, 2024 at 6:53 pm
Cyberattackers have been targeting the online NFT marketplace with emails claiming to make an offer to a targeted user; in reality, clicking on a malicious link takes victims to a crypto-draining site.
- CyberRatings.org Announces Test Results for Cloud Service Provider Native Firewallson November 26, 2024 at 4:19 pm
Protection ranged from 0.38% to 50.57% for security effectiveness.
- CyCognito Report Highlights Rising Cybersecurity Risks in Holiday E-Commerceon November 26, 2024 at 4:11 pm
Findings reveal growing cybersecurity risks in ecommerce, exposing vulnerabilities in PII handling and lack of basic security protections like HTTPS and WAFs