FreshRSS

🔒
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ ☆ ✇ Dark Reading:

Student Medical Records Exposed After LAUSD Breach

By: Dark Reading Staff, Dark Reading — February 23rd 2023 at 22:33
"Hundreds" of special education students' psych records have turned up on the Dark Web. School records like these are covered by FERPA, not HIPAA, so parents have little recourse.

☐ ☆ ✇ Dark Reading:

Cyberattack on Dole Causes Temporary Salad Shortage

By: Dark Reading Staff, Dark Reading — February 23rd 2023 at 20:40
The produce company said it suffered a ransomware attack earlier this month.

☐ ☆ ✇ Dark Reading:

US Military Emails Exposed via Cloud Account

By: Dark Reading Staff, Dark Reading — February 22nd 2023 at 19:25
A DoD email server hosted in the cloud (and now secured) had no password protection in place for at least two weeks.

☐ ☆ ✇ Dark Reading:

Inglis Retires as National Cyber Director Ahead of Biden's Cybersecurity EO

By: Dark Reading Staff, Dark Reading — February 17th 2023 at 19:00
The long-time NSA and cyber specialist says he's exiting the public sector.

☐ ☆ ✇ Dark Reading:

Not Stoked: Burton Snowboards' Online Orders Disrupted After Cyberattack

By: Dark Reading Staff, Dark Reading — February 17th 2023 at 18:20
The snow sports specialist is investigating to see what caused the operations-disrupting "cyber incident."

☐ ☆ ✇ Dark Reading:

ESXi Ransomware Update Outfoxes CISA Recovery Script

By: Dark Reading Staff, Dark Reading — February 16th 2023 at 22:34
New ESXiArgs-ransomware attacks include a workaround for CISA's decryptor, researchers find.

☐ ☆ ✇ Dark Reading:

Atlassian: Leaked Data Stolen via Third-Party App

By: Dark Reading Staff, Dark Reading — February 16th 2023 at 22:10
SiegedSec threat group leaked data that Atlassian says was taken from app used to coordinate in-office resources.

☐ ☆ ✇ Dark Reading:

Oligo Security Takes Aim at Open Source Vulnerabilities

By: Dark Reading Staff, Dark Reading — February 16th 2023 at 01:00
The startup's software helps organizations secure their containers in the cloud by teasing out which packages are running and which are vulnerable.

☐ ☆ ✇ Dark Reading:

GAO Calls for Improved Data Privacy Protections

By: Dark Reading Staff, Dark Reading — February 15th 2023 at 20:18
US federal watchdog agency outlines key measures for better protecting sensitive data under the federal government's control.

☐ ☆ ✇ Dark Reading:

What Purple Teams Wish Companies Knew

By: Dark Reading Staff, Dark Reading — February 15th 2023 at 19:00
Here are some of the easily avoidable mistakes most companies made last year, gleaned from hundreds of cybersecurity engagements by red and blue teams.

☐ ☆ ✇ Dark Reading:

Expel Tackles Cloud Threats With MDR for Kubernetes

By: Dark Reading Staff, Dark Reading — February 15th 2023 at 01:00
The new managed detection and response platform simplifies cloud security for Kubernetes applications.

☐ ☆ ✇ Dark Reading:

Oakland City Services Struggle to Recover From Ransomware Attack

By: Dark Reading Staff, Dark Reading — February 14th 2023 at 19:50
Fire emergency, 911 services functioning, along with Oakland financial systems, city says.

☐ ☆ ✇ Dark Reading:

Hospitals Sued for Using Meta's Ad-Tracking Code, Violating HIPAA

By: Dark Reading Staff, Dark Reading — February 14th 2023 at 18:59
Lawsuits say hospitals using Meta Pixel code violated patient privacy — sharing conditions, medications, and more with Facebook.

☐ ☆ ✇ Dark Reading:

9 Scammers Busted for 5M Euro Phishing Fraud Ring

By: Dark Reading Staff, Dark Reading — February 13th 2023 at 22:24
The network is alleged to have operated 100 bank accounts and stolen millions from American people and companies.

☐ ☆ ✇ Dark Reading:

Russian Hackers Disrupt NATO Earthquake Relief Operations

By: Dark Reading Staff, Dark Reading — February 13th 2023 at 19:50
Killnet claims DDoS attack against NATO Special Operations Headquarters, Strategic Airlift Capability, and more.

☐ ☆ ✇ Dark Reading:

Google Cloud Connects Chronicle to Health ISAC Feed

By: Dark Reading Staff, Dark Reading — February 10th 2023 at 02:00
Members of the Health-ISAC can ingest threat indicators directly into Chronicle to investigate whether the threat is present in their environment.

☐ ☆ ✇ Dark Reading:

Reddit Breached With Stolen Employee Credentials

By: Dark Reading Staff, Dark Reading — February 9th 2023 at 23:36
Reddit code, internal documents, dashboards, and business systems were compromised in the cyberattack.

☐ ☆ ✇ Dark Reading:

Cryptographers Decode Secret Letters of Mary, Queen of Scots

By: Dark Reading Staff, Dark Reading — February 9th 2023 at 19:53
Nearly a half-millennium after her execution, encrypted letters from the imprisoned royal offer a fascinating look into early cryptography.

☐ ☆ ✇ Dark Reading:

NIST Picks IoT Standard for Small Electronics Cybersecurity

By: Dark Reading Staff, Dark Reading — February 9th 2023 at 18:10
NIST announces that it will use Ascon as a cryptography standard for lightweight IoT device protection.

☐ ☆ ✇ Dark Reading:

Jailbreak Trick Breaks ChatGPT Content Safeguards

By: Dark Reading Staff, Dark Reading — February 8th 2023 at 22:05
Jailbreak command creates ChatGPT alter ego DAN, willing to create content outside of its own content restriction controls.

☐ ☆ ✇ Dark Reading:

GAO Calls for Action to Protect Cybersecurity of Critical Energy, Communications Networks

By: Dark Reading Staff, Dark Reading — February 8th 2023 at 18:45
Enhanced industrial control systems cybersecurity for energy and communications sector among top recommendations in new GAO cybersecurity assessment.

☐ ☆ ✇ Dark Reading:

Cloud Apps Still Demand Way More Privileges Than They Use

By: Dark Reading Staff, Dark Reading — February 7th 2023 at 23:35
Hackers can't steal a credential that doesn't exist.

☐ ☆ ✇ Dark Reading:

DPRK Using Unpatched Zimbra Devices to Spy on Researchers

By: Dark Reading Staff, Dark Reading — February 7th 2023 at 21:05
Lazarus Group used a known Zimbra bug to steal data from medical and energy researchers.

☐ ☆ ✇ Dark Reading:

New Banking Trojan Targeting 100M Pix Payment Platform Accounts

By: Dark Reading Staff, Dark Reading — February 7th 2023 at 19:18
New malware demonstrates how threat actors are pivoting toward payment platform attacks, researchers say.

☐ ☆ ✇ Dark Reading:

Keeping KillNet at Bay: Use the IP Address Blocklist

By: Dark Reading Staff, Dark Reading — February 7th 2023 at 01:00
Security teams can use a blocklist containing tens of thousands of proxy IP addresses used by the pro-Russian hacktivist group to defend their organizations from DDoS attacks.

☐ ☆ ✇ Dark Reading:

Global Ransomware Attack on VMware EXSi Hypervisors Continues to Spread

By: Dark Reading Staff, Dark Reading — February 6th 2023 at 22:11
The fresh "ESXiArgs" malware is exploiting a 2-year-old RCE security vulnerability (tracked as CVE-2021-21974), resulting in thousands of unpatched servers falling prey to the campaign.

☐ ☆ ✇ Dark Reading:

MITRE Releases Tool to Design Cyber-Resilient Systems

By: Dark Reading Staff, Dark Reading — February 3rd 2023 at 03:00
Engineers can use the Cyber Resiliency Engineering Framework Navigator to visuzalize their cyber-resiliency capabilities.

☐ ☆ ✇ Dark Reading:

Patch Critical Bug Now: QNAP NAS Devices Ripe for the Slaughter

By: Dark Reading Staff, Dark Reading — February 2nd 2023 at 16:08
QNAP NAS devices are vulnerable to CVE-2022-27596, which allows unauthenticated, remote SQL code injection.

☐ ☆ ✇ Dark Reading:

CISA to Open Supply Chain Risk Management Office

By: Dark Reading Staff, Dark Reading — February 1st 2023 at 21:31
A new supply chain risk management office aims to help public and private sectors implement recent CISA policies and guidance.

☐ ☆ ✇ Dark Reading:

Google Fi Users Caught Up in T-Mobile Breach

By: Dark Reading Staff, Dark Reading — February 1st 2023 at 14:18
Google Fi mobile customers have been alerted that their SIM card serial numbers, phone numbers, and other data were exposed in T-Mobile hack.

☐ ☆ ✇ Dark Reading:

Checkmarx Launches Threat Intelligence for Open Source Packages

By: Dark Reading Staff, Dark Reading — February 1st 2023 at 05:00
The new API incorporates threat intelligence research and employs machine learning to identify threats in the supply chain.

☐ ☆ ✇ Dark Reading:

Poser Hackers Impersonate LockBit in SMB Cyberattacks

By: Dark Reading Staff, Dark Reading — January 31st 2023 at 19:44
Recent cyberattacks against SMBs across Europe have been traced back to copycat groups using leaked LockBit locker malware.

☐ ☆ ✇ Dark Reading:

Facebook Bug Allows 2FA Bypass Via Instagram

By: Dark Reading Staff, Dark Reading — January 30th 2023 at 19:00
The Instagram rate-limiting bug, found by a rookie hunter, could be exploited to bypass Facebook 2FA in vulnerable apps, researcher reports.

☐ ☆ ✇ Dark Reading:

Enterprises Don't Know What to Buy for Responsible AI

By: Dark Reading Staff, Dark Reading — January 27th 2023 at 22:30
Organizations are struggling to procure appropriate technical tools to address responsible AI, such as consistent bias detection in AI applications.

☐ ☆ ✇ Dark Reading:

Critical RCE Lexmark Printer Bug Has Public Exploit

By: Dark Reading Staff, Dark Reading — January 27th 2023 at 18:02
A nasty SSRF bug in Web Services plagues a laundry list of enterprise printers.

☐ ☆ ✇ Dark Reading:

Dutchman Detained for Dealing Details of Tens of Millions of People

By: Dark Reading Staff, Dark Reading — January 26th 2023 at 20:00
The accused sold an enormous data set stolen from the Austrian radio and television licensing authority — to an undercover cop.

☐ ☆ ✇ Dark Reading:

German Government, Airports, Banks Hit With Killnet DDoS Attacks

By: Dark Reading Staff, Dark Reading — January 26th 2023 at 19:26
After Berlin pledged tanks for Ukraine, some German websites were knocked offline temporarily by Killnet DDoS attacks.

☐ ☆ ✇ Dark Reading:

Zacks Investment Research Hack Exposes Data for 820K Customers

By: Dark Reading Staff, Dark Reading — January 25th 2023 at 21:43
Zacks Elite sign-ups for the period 1999–2005 were accessed, including name, address, email address, phone number, and the password associated with Zacks.com.

☐ ☆ ✇ Dark Reading:

GoTo Encrypted Backups Stolen in LastPass Breach

By: Dark Reading Staff, Dark Reading — January 25th 2023 at 19:35
Encrypted backups for several GoTo remote work tools were exfiltrated from LastPass, along with encryption keys.

☐ ☆ ✇ Dark Reading:

Skyhawk Security Launches Multicloud Runtime Threat Detection and Response Platform

By: Dark Reading Staff, Dark Reading — January 25th 2023 at 00:34
Skyhawk Synthesis extends cloud security misconfiguration detection across multiple clouds, the company says — throwing cloud security posture management in for free.

☐ ☆ ✇ Dark Reading:

Wallarm Aims to Reduce the Harm From Compromised APIs

By: Dark Reading Staff, Dark Reading — January 23rd 2023 at 23:29
API Leak Management software discovers exposed API keys and other secrets, blocks their use, and monitors for abuse, the company says.

☐ ☆ ✇ Dark Reading:

Pair of Galaxy App Store Bugs Offer Cyberattackers Mobile Device Access

By: Dark Reading Staff, Dark Reading — January 23rd 2023 at 22:00
Devices running Android 12 and below are at risk of attackers downloading apps that direct users to a malicious domain.

☐ ☆ ✇ Dark Reading:

FanDuel Sportsbook Bettors Exposed in Mailchimp Breach

By: Dark Reading Staff, Dark Reading — January 23rd 2023 at 17:48
Amid all the NFL playoff action, FanDuel has sent an email warning to gamblers that their data was exposed in its third-party breach, putting them at risk for phishing attacks.

☐ ☆ ✇ Dark Reading:

Massive Adware Campaign Shuttered

By: Dark Reading Staff, Dark Reading — January 19th 2023 at 22:00
Mainly Apple iOS in-app ads were targeted, injecting malicious JavaScript code to rack up phony views.

☐ ☆ ✇ Dark Reading:

Data Security in Multicloud: Limit Access, Increase Visibility

By: Dark Reading Staff, Dark Reading — January 19th 2023 at 02:00
Ensuring that data can be easily discovered, classified, and secured is a crucial cornerstone of a data security strategy.

☐ ☆ ✇ Dark Reading:

Sophos Cuts Jobs to Focus on Cybersecurity Services

By: Dark Reading Staff, Dark Reading — January 18th 2023 at 19:24
Layoffs intended to cut costs, help company shift its focus on cybersecurity services, Sophos says.

☐ ☆ ✇ Dark Reading:

ChatGPT Could Create Polymorphic Malware Wave, Researchers Warn

By: Dark Reading Staff, Dark Reading — January 18th 2023 at 19:21
The powerful AI bot can produce malware without malicious code, making it tough to mitigate.

☐ ☆ ✇ Dark Reading:

Okta Expands No-Code Offerings for Identity Cloud

By: Dark Reading Staff, Dark Reading — January 18th 2023 at 01:00
With Actions Integrations, Okta is expanding its no-code offerings to help administrators manage and customize their identity workflow.

☐ ☆ ✇ Dark Reading:

OT Cybersecurity Leader Paul Brager Passes Away

By: Dark Reading Staff, Dark Reading — October 11th 2022 at 17:53
The IT security executive led ICS/OT, IT/OT integration, and other security programs, as well as diversity and inclusion efforts in the industry.

☐ ☆ ✇ Dark Reading:

Intel Processor UEFI Source Code Leaked

By: Dark Reading Staff, Dark Reading — October 11th 2022 at 17:49
Exposed code included private key for Intel Boot Guard, meaning it can no longer be trusted, according to a researcher.

☐ ☆ ✇ Dark Reading:

Zimbra RCE Bug Under Active Attack

By: Dark Reading Staff, Dark Reading — October 10th 2022 at 18:17
A flaw in unpatched Zimbra email servers could allow attackers to obtain remote code execution by pushing malicious files past filters.

☐ ☆ ✇ Dark Reading:

Cybersecurity Will Account for Nearly One-Quarter of AI Software Market Through 2025

By: Dark Reading Staff, Dark Reading — October 7th 2022 at 19:59
A boom in artificial intelligence-powered detection and remediation tools pushes security spending to the top of the AI market, according to Forrester.

☐ ☆ ✇ Dark Reading:

Patch Now: Fortinet FortiGate & FortiProxy Contain Critical Vuln

By: Dark Reading Staff, Dark Reading — October 7th 2022 at 16:45
The bug is under active exploitation; Fortinet issued a customer advisory urging customers to apply its update immediately.

☐ ☆ ✇ Dark Reading:

macOS Archive Utility Bug Lets Malicious Apps Bypass Security Checks

By: Dark Reading Staff, Dark Reading — October 6th 2022 at 20:45
Exploit allows unsigned and unnotarized macOS applications to bypass Gatekeeper and other security, without notifying the user.

☐ ☆ ✇ Dark Reading:

Russian Hackers Shut Down US State Government Websites

By: Dark Reading Staff, Dark Reading — October 6th 2022 at 19:56
Russian-speaking cyberattackers boast they are behind disruption of Colorado, Kentucky, and Mississippi government websites.

☐ ☆ ✇ Dark Reading:

Ikea Smart Light System Flaw Lets Attackers Turn Bulbs on Full Blast

By: Dark Reading Staff, Dark Reading — October 5th 2022 at 20:00
With just one malformed Zigbee frame, attackers could take over certain Ikea smart lightbulbs, leaving users unable to turn the lights down.

☐ ☆ ✇ Dark Reading:

NullMixer Dropper Delivers a Multimalware Code Bomb

By: Dark Reading Staff, Dark Reading — October 5th 2022 at 17:45
In one shot, Trojan dropper NullMixer installs a suite of downloaders, banking Trojans, stealers, and spyware on victims' systems.

☐ ☆ ✇ Dark Reading:

Aussie Telco Telstra Breached, Reportedly Exposing 30,000 Employees' Data

By: Dark Reading Staff, Dark Reading — October 4th 2022 at 17:55
The Telstra cyber incident comes just weeks after its main rival Optus suffered a major compromise of its customer database.

☐ ☆ ✇ Dark Reading:

Former NSA Employee Faces Death Penalty for Selling Secrets

By: Dark Reading Staff, Dark Reading — October 4th 2022 at 17:10
Suspect allegedly thought he was swapping secrets with a foreign government for crypto — but the contact turned out to be an FBI agent.

☐ ☆ ✇ Dark Reading:

Worried About the Exchange Zero-Day? Here's What to Do

By: Dark Reading Staff, Dark Reading — September 30th 2022 at 22:14
While organizations wait for an official patch for the two zero-day flaws in Microsoft Exchange, they should scan their networks for signs of exploitation and apply these mitigations.

❌