darkreading
Brazilian Ad Fraud Network 'Camu' Hits 2B+ Daily Bid Requests
6 months 1 week ago
The global Internet helps just about everything to scale more easily, including piracy and ad fraud.
Nate Nelson, Contributing Writer
SANS Institute Unveils Critical Infrastructure Strategy Guide for 2024
6 months 1 week ago
Top Travel Sites Have Some First-Class Security Issues to Clean Up
6 months 1 week ago
Public-facing vulnerabilities, cloud sprawl, access to back-end servers are just a few of the challenges travel and hospitality companies must address.
Elizabeth Montalbano, Contributing Writer
Exploited: CISA Highlights Apache OFBiz Flaw After PoC Emerges
6 months 1 week ago
The vulnerability carries nearly the highest score possible on the CVSS scale, at 9.8, impacting a system used by major companies around the world.
Kristina Beek, Associate Editor, Dark Reading
How Telecom Vulnerabilities Can Be a Threat to Cybersecurity Posture
6 months 1 week ago
Telecom-based attacks such as SMS toll fraud and 2FA hijacking have evolved into a mainstream concern for CISOs.
Ayan Halder
Dragos Expands Asset Visibility in Latest Platform Update
6 months 1 week ago
The latest release of the Dragos Platform provide industrial and critical infrastructure organizations with complete and enriched view of their OT environment.
Dark Reading Staff
South Korean APT Exploits 1-Click WPS Office Bug, Nabs Chinese Intel
6 months 1 week ago
The most popular office software suite in China actually has two critical vulnerabilities, which allowed hackers the opportunity for remote code execution. Time to patch.
Nate Nelson, Contributing Writer
CCTV Zero-Day Exposes Critical Infrastructure to Mirai Botnet
6 months 1 week ago
CISA warned about the RCE zero-day vulnerability in AVTECH IP cameras in early August, and now vulnerable systems are being used to spread malware.
Becky Bracken, Senior Editor, Dark Reading
BlackByte Targets ESXi Bug With Ransomware to Access Virtual Assets
6 months 1 week ago
The pivot is one of several changes the groups using the malware have used in recent attacks.
Jai Vijayan, Contributing Writer
Attackers Exploit Critical Atlassian Confluence Flaw for Cryptojacking
6 months 1 week ago
Novel attack vectors leverage the CVE-2023-22527 RCE flaw discovered in January, which is still under active attack, to turn targeted cloud environments into cryptomining networks.
Elizabeth Montalbano, Contributing Writer
Hitachi Energy Vulnerabilities Plague SCADA Power Systems
6 months 1 week ago
The company has assessed four of the five disclosed vulnerabilities as being of high to critical severity.
Jai Vijayan, Contributing Writer
Manufacturing Sector Under Fire From Microsoft Credential Thieves
6 months 1 week ago
The emails impersonate well-known companies in the industry, fooling the victim into thinking they are communicating with a legitimate entity.
Dark Reading Staff
Why LLMs Are Just the Tip of the AI Security Iceberg
6 months 1 week ago
With the right processes and tools, organizations can implement advanced AI security frameworks that make hidden risks visible, enabling security teams to track and address them before impact.
Diana Kelley
Hundreds of LLM Servers Expose Corporate, Health & Other Online Data
6 months 1 week ago
LLM automation tools and vector databases can be rife with sensitive data — and vulnerable to pilfering.
Nate Nelson, Contributing Writer
Zimbabwe Trains Government Officials in Cybersecurity Skills
6 months 1 week ago
African nation's proactive approach to cybersecurity comes amid a rise in painful cyberattacks, including the breach of a major bank.
Dark Reading Staff
77% of Educational Institutions Spotted a Cyberattack Within the Last 12 Months
6 months 1 week ago
PoC Exploit for Zero-Click Vulnerability Made Available to the Masses
6 months 1 week ago
The exploit can be accessed on GitHub and makes it easier for the flaw to be exploited by threat actors.
Dark Reading Staff
Microsoft's Sway Serves as Launchpad for 'Quishing' Campaign
6 months 1 week ago
The attack is a mashup of QR codes and phishing that gets users to click on links to malicious webpages.
Dark Reading Staff
China's Volt Typhoon Exploits Zero-Day in Versa's SD-WAN Director Servers
6 months 2 weeks ago
So far, the threat actor has compromised at least five organizations using CVE-2024-39717; CISA has added bug to its Known Exploited Vulnerability database.
Jai Vijayan, Contributing Writer
Checked
2 hours 9 minutes ago
Public RSS feed
darkreading feed