darkreading
Get Out of Security Debt by Tackling the Exposure Problem
2 months ago
Teams digging out of security debt need to answer only two simple questions: Which vulnerabilities in our systems are exposed, and how long should they stay that way?
Chris Wysopal
EU Gets a Head Start in Developing 6G Network Security
2 months ago
"Shield-6G" will combine AI threat detection, digital twins, honeypots, and more, to help carriers protect 6G networks against the threats of tomorrow.
Nate Nelson
INC Ransomware Thrives by Mastering the Basics
2 months ago
And one of those basics is focusing on sectors where a ransomware disruption creates immediate pressure to pay up, like with healthcare.
Alexander Culafi
Sweeping Credential-Harvesting Heist Compromises 30K+ Fortinet Devices
2 months ago
Attackers are actively targeting various sectors across nearly 200 countries and already have compiled a list of working credentials for tens of thousands of compromised devices.
Elizabeth Montalbano
UK Social Media Ban for Minors Has Privacy Experts Worried
2 months ago
The UK will ban adolescents under 16 years old from user-to-user social media platforms, despite age verification issues and privacy concerns.
Robert Lemos
Fileless Phantom Stealer Targets Browser Credentials
2 months ago
In addition to executing entirely in memory, the malware's infection chain incorporates other anti-analysis techniques designed to evade detection.
Jai Vijayan
Security Community Slams US Ban on Exporting Mythos, Fable
2 months ago
An open letter signed by dozens of security experts asked the government to reverse export restrictions on Anthropic's Claude Fable 5 and Mythos 5 models.
Alexander Culafi
SprySOCKS Windows Variant Abuses Kernel Drivers to Evade Detection
2 months ago
FishMonger, a China-nexus threat group, has deployed an undocumented version of the Linux backdoor against government targets in Honduras, Taiwan, Thailand, and Pakistan.
Rob Wright
Rokarolla Android Trojan Levels Up to Full Device Control, Persistence
2 months ago
The emerging malware, spread via fake TikTok and Chrome downloads, has evolved by combining banking fraud with extensive device surveillance and remote control.
Elizabeth Montalbano
'Lorem Ipsum' Malware Pivots to ClickFix Delivery
2 months ago
New analysis shows the campaign, which uses compromised WordPress sites, may be linked to the ransomware and data extortion group Vice Society.
Jai Vijayan
HTTP/2 Bomb Attacks Put Telcos, Healthcare Orgs at Risk
2 months ago
The denial-of-service (DoS) exploit takes advantage of two features in HTTP/2 that were designed to save Internet bandwith, not power massive amplification attacks.
Nate Nelson
Copilot 'SearchLeak' Attack Allows 1-Click Data Theft
2 months ago
The critical, three-stage attack is now patched, but it's part of a new group of AI prompt-injection issues that use hidden URLs and other variables.
Alexander Culafi
China-Nexus Actor Spies on US Researchers Undetected for a Year
2 months 1 week ago
Google discovered and disrupted the sprawling campaign, which stole RedCAP credentials to breach numerous institutions and exfiltrate sensitive data.
Elizabeth Montalbano
Most CISOs Report Pressure to Bury Bad Security News
2 months 1 week ago
Executive leaders may not be saying it aloud, but business objectives and priorities don't always promote timely disclosures.
Arielle Waldman
The Beginning of the End of Social Engineering
2 months 1 week ago
AI-native operating systems are shifting the responsibility to stay vigilant against social engineering cyberattacks from the user onto the system itself.
Arun Vishwanath
US Cracks Down on Anthropic AI Models Amid Abuse Concerns
2 months 1 week ago
Anthropic abruptly suspended all access to Fable 5 and Mythos 5 after receiving an export control directive that banned foreign nationals from using the technology.
Robert Lemos
ShinyHunters Uses Oracle Zero-Day to Rampage Higher Ed
2 months 1 week ago
A major bug in Oracle's ERP software disproportionately affected American universities, and hackers have capitalized by stealing gobs of data.
Nate Nelson
Claude Fable 5 Doesn't Change the Mythos Security Story
2 months 1 week ago
Stay cool: Mythos 5 is an upgrade over Mythos Preview while Fable 5 is Mythos "made safe for general use," Anthropic explains.
Alexander Culafi
Phishing Attack Volume Down 20%, But Risk Still Rising
2 months 1 week ago
Hackers are valuing quality over quantity, using AI to upgrade their phishing attacks rather than multiply them.
Nate Nelson
Checked
14 hours 10 minutes ago
Public RSS feed
darkreading feed