darkreading
Karl Triebes Joins Ivanti as Chief Product Officer
3 months ago
CISA and US and International Partners Publish Guidance for OT Owners and Operators
3 months ago
SEALSQ in Cooperation With WISeKey Expands Post-Quantum Footprint in Saudi Arabia
3 months ago
FTC Orders GoDaddy to Fix Inadequate Security Practices
3 months ago
The FTC claims that the Web hosting company's security failures led to several major breaches in the past few years.
Kristina Beek, Associate Editor, Dark Reading
Strategic Approaches to Threat Detection, Investigation & Response
3 months ago
By staying vigilant, agile, and prepared, organizations can turn TDIR from a defensive strategy into a proactive enabler of security and operational excellence.
Sameer Bhanushali
Risk, Reputational Scores Enjoy Mixed Success as Security Tools
3 months ago
Part predictive analysis, part intuition, risk and reputation services are imperfect instruments at best — and better than nothing for most organizations and insurers.
Robert Lemos, Contributing Writer
Trusted Apps Sneak a Bug Into the UEFI Boot Process
3 months ago
Seven system recovery programs contained what amounted to a backdoor for injecting any untrusted file into the system startup process.
Nate Nelson, Contributing Writer
CISA's AI Playbook Pushes For More Information Sharing
3 months ago
The Joint Cyber Defense Collaborative playbook seeks to establish a "a unified approach" on how to handle AI-related cybersecurity threats.
Edge Editors
Attackers Hijack Google Advertiser Accounts to Spread Malware
3 months ago
It's an especially brazen form of malvertising, researchers say, striking at the heart of Google's business; the tech giant says it's aware of the issue and is working quickly to address the problem.
Jai Vijayan, Contributing Writer
CISA: Second BeyondTrust Vulnerability Added to KEV Catalog
3 months ago
BeyondTrust has patched all cloud instances of the vulnerability and has released patches for self-hosted versions.
Kristina Beek, Associate Editor, Dark Reading
Extension Poisoning Campaign Highlights Gaps in Browser Security
3 months ago
Evidence suggests that some of the payloads and extensions may date as far back as April 2023.
Elizabeth Montalbano, Contributing Writer
North Korea's Lazarus APT Evolves Developer-Recruitment Attacks
3 months ago
"Operation 99" uses job postings to lure freelance software developers into downloading malicious Git repositories. From there, malware infiltrates developer projects to steal source code, secrets, and cryptocurrency.
Elizabeth Montalbano, Contributing Writer
OWASP's New LLM Top 10 Shows Emerging AI Threats
3 months ago
Ultimately, there is no replacement for an intuitive, security-focused developer working with the critical thinking required to drive down the risk of both AI and human error.
Matias Madou
As Tensions Mount With China, Taiwan Sees Surge in Cyberattacks
3 months ago
In 2024, the Taiwanese government saw the daily average of attempted attacks by China double to 2.4 million, with a focus on government targets and telecommunications firms.
Robert Lemos, Contributing Writer
Microsoft Rings in 2025 With Record Security Update
3 months ago
Company has issued patches for an unprecedented 159 CVEs, including eight zero-days, three of which attackers are already exploiting.
Jai Vijayan, Contributing Writer
1Password's Trelica Buy Part of Broader Shadow IT Play
3 months ago
The acquisition accelerates 1Password's ongoing efforts to expand the role of the password manager with secure SaaS management.
Jeffrey Schwartz
Apple Bug Allows Root Protections Bypass Without Physical Access
3 months ago
Emergent macOS vulnerability lets adversaries circumvent Apple's System Integrity Protection (SIP) by loading third-party kernels.
Becky Bracken, Senior Editor, Dark Reading
FBI Wraps Up Eradication Effort of Chinese 'PlugX' Malware
3 months ago
Two hacker groups were paid to develop malware targeting victims in the US, Europe, and Asia, as well as various Chinese dissident groups.
Kristina Beek, Associate Editor, Dark Reading
Zero-Day Security Bug Likely Fueling Fortinet Firewall Attacks
3 months ago
An ongoing campaign targeting FortiGate devices with management interfaces exposed on the public Internet is leading to unauthorized administrative logins and configuration changes, creating new accounts, and performing SSL VPN authentication.
Elizabeth Montalbano, Contributing Writer
Checked
3 hours 14 minutes ago
Public RSS feed
darkreading feed