darkreading
CISA Warns: Old DNS Trick 'Fast Flux' Is Still Thriving
8 months 1 week ago
An old DNS switcheroo technique is still helping attackers keep their infrastructure alive. But is it really a pressing issue in 2025?
Nate Nelson, Contributing Writer
Minnesota Tribe Struggles After Ransomware Attack
8 months 1 week ago
Hotel and casino operations for the Lower Sioux Indians have been canceled or postponed, and the local health center is redirecting those needing medical or dental care.
Kristina Beek, Associate Editor, Dark Reading
Medusa Rides Momentum From Ransomware-as-a-Service Pivot
8 months 1 week ago
Shifting to a RaaS business model has accelerated the group's growth, and targeting critical industries like healthcare, legal, and manufacturing hasn't hurt either.
Robert Lemos, Contributing Writer
CISA Layoffs Are a Momentary Disruption, Not a Threat
8 months 1 week ago
Layoffs may cause short-term disruptions, but they don't represent a catastrophic loss of cybersecurity capability — because the true cyber operations never resided solely within CISA to begin with.
John Spencer-Taylor
Secure Communications Evolve Beyond End-to-End Encryption
8 months 1 week ago
Signal, Wickr, WhatsApp, and Cape all have different approaches to security and privacy, yet most are finding ways to make secure communications more private.
Robert Lemos, Contributing Writer
Rafts of Security Bugs Could Rain Out Solar Grids
8 months 1 week ago
At least three major energy solution and renewable energy companies have nearly 50 vulnerabilities — many of them "basic" mistakes — indicating a lack of developed cybersecurity safeguards.
Kristina Beek, Associate Editor, Dark Reading
Microsoft Boosts Email Sender Rules for Outlook
8 months 1 week ago
Beginning on May 5, the tech giant will enforce new email authentication protocols for Outlook users who send large volumes of email.
Arielle Waldman
China-Linked Threat Group Exploits Ivanti Bug
8 months 1 week ago
The vendor had originally assessed the flaw as low risk but now says it is a critical issue that enables remote code execution.
Jai Vijayan, Contributing Writer
Disclosure Drama Clouds CrushFTP Vulnerability Exploitation
8 months 1 week ago
CrushFTP CEO Ben Spink slammed several cybersecurity companies for creating confusion around a critical authentication bypass flaw that's currently under attack.
Rob Wright
Counterfeit Phones Carrying Hidden Revamped Triada Malware
8 months 1 week ago
The malware, first discovered in 2016, has been updated over the years, and the latest version is now hiding in the firmware of counterfeit mobile phones.
Kristina Beek, Associate Editor, Dark Reading
Runtime Ventures Launches New Fund for Seed, Pre-Seed Startups
8 months 1 week ago
Co-founders Michael Sutton and David Endler raised $32 million to invest in early-stage cybersecurity startups and provide mentoring support.
Fahmida Y. Rashid
Social Engineering Just Got Smarter
8 months 1 week ago
Polices that forbid employees from divulging company details are worthless if the same information can be obtained from sources employees have no control over.
Steve Stasiukonis
Emerging Risks Require IT/OT Collaboration to Secure Physical Systems
8 months 1 week ago
With an increase in cyber-physical attacks that can cause significant disruptions, financial fallout and safety concerns for victim organizations, IT and OT security teams cannot keep working in silos.
Arielle Waldman
Google Quick Share Bug Bypasses Allow Zero-Click File Transfer
8 months 1 week ago
Google addresses patch bypasses for CVE-2024-38272 and CVE-2024-38271, part of the previously announced "QuickShell" silent RCE attack chain against Windows users.
Tara Seals, Managing Editor, News, Dark Reading
Israel Enters 'Stage 3' of Cyber Wars With Iran Proxies
8 months 1 week ago
While Israel and Iranian proxies fight it out IRL, their conflict in cyberspace has developed in parallel. These days attacks have decelerated, but advanced in sophistication.
Nate Nelson, Contributing Writer
DPRK 'IT Workers' Pivot to Europe for Employment Scams
8 months 1 week ago
By using fake references and building connections with recruiters, some North Korean nationals are landing six-figure jobs that replenish DPRK coffers.
Kristina Beek, Associate Editor, Dark Reading
SolarWinds Adds Incident Management Tool From Squadcast
8 months 1 week ago
The IT service management and observability tools company acquired Squadcast last month and is adding the automated incident response platform to the SolarWinds portfolio.
Jeffrey Schwartz
In Salt Typhoon's Wake, Congress Mulls Potential Options
8 months 1 week ago
While the House Committee on Government Reform was looking for retaliatory options, cybersecurity experts pointed them toward building better defenses.
Alexander Culafi, Senior News Writer, Dark Reading
New PCI DSS Rules Say Merchants on Hook for Compliance, Not Providers
8 months 2 weeks ago
Merchants and retailers will now face penalties for not being compliant with PCI DSS 4.0.1, and the increased security standards make it clear they cannot transfer compliance responsibility to third-party service providers.
Arielle Waldman
Checked
23 hours 4 minutes ago
Public RSS feed
darkreading feed