darkreading
Following Data Breach, Multiple Stalkerware Apps Go Offline
9 months ago
The same easily exploitable vulnerability was found in three of the apps that led to the compromise of victims' data.
Kristina Beek, Associate Editor, Dark Reading
Russian Threat Actor TAG-110 Goes Phishing in Tajikistan
9 months ago
While Ukraine remains Russia's major target for cyberattacks, TAG-110 is part of a strategy to preserve "a post-Soviet sphere of influence" by embedding itself in other countries' infrastructures.
Alexander Culafi, Senior News Writer, Dark Reading
3AM Ransomware Adopts Email Bombing, Vishing Combo Attack
9 months ago
The emerging threat group is the latest to adopt the combo attack tactic, which Black Basta and other groups already are using to gain initial access for ransomware deployment.
Elizabeth Montalbano, Contributing Writer
UK Retail Cyberattacks May Drive Up US Insurance Premiums
9 months ago
Insurance experts weigh in on how the recent barrage of attacks against UK retailers could affect premium rates and policy requirements, as well as how to work toward improving risk assessment.
Arielle Waldman
CISA: Russia's Fancy Bear Targeting Logistics, IT Firms
9 months ago
The mission is to gather information that could help Russia in its war against Ukraine.
Jai Vijayan, Contributing Writer
Blurring Lines Between Scattered Spider & Russian Cybercrime
9 months ago
The loosely affiliated hacking group has shifted closer to ransomware gangs, raising questions about Scattered Spider's ties to the Russian cybercrime underground.
Rob Wright
Security Threats of Open Source AI Exposed by DeepSeek
9 months ago
DeepSeek's risks must be carefully considered, and ultimately mitigated, in order to enjoy the many benefits of generative AI in a manner that is safe and secure for all organizations and users.
Maurice Uenuma
Keeping LLMs on the Rails Poses Design, Engineering Challenges
9 months ago
Despite adding alignment training, guardrails, and filters, large language models continue to give up secrets, make unfiltered statements, and provide dangerous information.
Robert Lemos, Contributing Writer
GitLab's AI Assistant Opened Devs to Code Theft
9 months ago
Prompt injection risks in GitLab's AI assistant could have allowed attackers to steal source code, or indirectly deliver developers malware, dirty links, and more.
Nate Nelson, Contributing Writer
SideWinder APT Caught Spying on India's Neighbor Gov'ts
9 months ago
A recent spear-phishing campaign against countries in South Asia aligns with broader political tensions in the region.
Nate Nelson, Contributing Writer
Experts Chart Path to Creating Safer Online Spaces for Women
9 months ago
Gaps in laws, technology, and corporate accountability continue to put women's safety and privacy online at risk.
Joan Goodchild
Lumma Stealer Takedown Reveals Sprawling Operation
9 months ago
The FBI and partners have disrupted "the world's most popular malware," a sleek enterprise with thousands of moving parts, responsible for millions of cyberattacks in every part of the world.
Tara Seals
Ivanti EPMM Exploitation Tied to Previous Zero-Day Attacks
9 months ago
Wiz researchers found an opportunistic threat actor has been targeting vulnerable edge devices, including Ivanti VPNs and Palo Alto firewalls.
Rob Wright
Marks & Spencer Projects Cyberattack Cost of $400M
9 months ago
The company expects it will continue to struggle with online disruptions until at least July, due to the attack.
Kristina Beek, Associate Editor, Dark Reading
Pandas Galore: Chinese Hackers Boost Attacks in Latin America
9 months ago
Vixen Panda, Aquatic Panda — both Beijing-sponsored APTs and financially motivated criminal groups continued to pose the biggest threat to organizations in Central and South America last year, says CrowdStrike.
Jai Vijayan, Contributing Writer
Unimicron, Presto Attacks Mark Industrial Ransomware Surge
9 months ago
A number of major industrial organizations suffered ransomware attacks last quarter, such as PCB manufacturer Unimicron, appliance maker Presto, and more — a harbinger of a rapidly developing and diversifying threat landscape.
Alexander Culafi, Senior News Writer, Dark Reading
Coinbase Breach Compromises Nearly 70K Customers' Information
9 months ago
Coinbase asserts that this number is only a small fraction of the number of its verified users, though it's still offering a $20 million reward to catch the criminals.
Kristina Beek, Associate Editor, Dark Reading
Unpatched Windows Server Flaw Threatens Active Directory Users
9 months ago
Attackers can exploit a vulnerability present in the delegated Managed Service Account (dMSA) feature that fumbles permission handling and is present by default.
Elizabeth Montalbano, Contributing Writer
NIST's 'LEV' Equation to Determine Likelihood a Bug Was Exploited
9 months ago
The new 'Likely Exploited Vulnerabilities' metric could be a game-changer for SecOps teams and vulnerability patch prioritization.
Alexander Culafi, Senior News Writer, Dark Reading
Checked
50 minutes 50 seconds ago
Public RSS feed
darkreading feed