darkreading
Name That Toon Contest
2 weeks 2 days hence
[Virtual Event] Anatomy of a Data Breach: What to Do if it Happens to You
1 week 1 day hence
Silent Ransom Group Hits US Law Firms in Escalating Extortion Attacks
1 day 7 hours ago
The financially motivated group is combining vishing, IT impersonation, and in-person office intrusions to steal data and extort victims.
Jai Vijayan
Check Point VPN Flaw Exploited Since Early May
1 day 8 hours ago
A newly discovered, critical zero-day vulnerability is under attack; a Qilin ransomware affiliate has been blamed for at least one incident.
Alexander Culafi
Iran Signed a Ceasefire — Its Hackers Didn't
1 day 9 hours ago
An extension of the Geneva Conventions could impose restrictions on cyberwarfare under ceasefire conditions and close a major loophole in international conflict.
Emil Sayegh
'Hades' Campaign Against PyPI Puts New Spin on Shai-Hulud
1 day 12 hours ago
The latest attacks, which hit 37 PyPI wheels and 19 code packages, show a continued evolution of the persistent software supply chain threat.
Elizabeth Montalbano
Exposed Fuel Tank Gauges Under Attack in the US
4 days 9 hours ago
Threat actors are taking advantage of Internet-exposed tank gauges by breaching gas stations, opening the door to disruption.
Nate Nelson
Adaptive, Agentic AI Worms Loom as Next Enterprise Threat
4 days 13 hours ago
AI worms, or "viruses with wings and brains," adapt to new environments, seek out vulnerabilities, and will likely strike within a year, researchers say.
Robert Lemos
Trump AI Order Seeks Voluntary Frontier Model Testing
4 days 15 hours ago
The White House's executive order establishes voluntary framework for early government access to frontier models while investing in federal security.
Alexander Culafi
Rust-Written IronWorm Hits NPM Supply Chain
5 days 6 hours ago
Like Shai-Hulud, the campaign targets developers to steal credentials and reuses them to propagate across the software supply channel.
Jai Vijayan
China's TA4922 Expands Cybercrime Attacks Globally
5 days 7 hours ago
One of the world's most diverse, least-focused cybercrime groups is enlarging its footprint beyond East Asia.
Nate Nelson
4 Critical Threats Where Attackers Have the Advantage
5 days 7 hours ago
Gartner analysts issued a call to action to bolster defenses against several emerging critical threats, such as deepfakes and prompt injections.
Rob Wright
Bugcrowd Launches EU Data Residency Option For Evolving Data Sovereignty Needs
5 days 14 hours ago
Organizations are growing serious about which nation's rules apply to their data. Experts point to geopolitical tensions as a main contributing factor.
Arielle Waldman
Pakistan Spies on Afghan Finance Ministry With Xeno RAT
6 days ago
Despite broadly connected digital infrastructure, standard fare TTPs are enough to cause trouble for Afghanistan's porous cybersecurity.
Nate Nelson
Attackers Use AI to Automate EDR Evasion Testing
6 days 7 hours ago
Python scripts were used to test malware against endpoint detection and response agents from Sophos, CrowdStrike, and Windows Defender.
Alexander Culafi
Tropical Blend: Cyber & Politics Ramp Up Across Latin America
6 days 8 hours ago
China-linked espionage groups have attacked at least a dozen nations in the region, gathering information on maritime shipping, oil production, and other geopolitical interests.
Robert Lemos
Cyber Insurance Rates Are Dropping, but Exclusions Widen
6 days 9 hours ago
Cyber insurance coverage is slowly changing, and some policies may not provide coverage for social engineering attacks like ClickFix.
Rob Wright
Coding Gaffe Exposes Microsoft 365 Accounts to Widespread Takeover
6 days 9 hours ago
A disabled security setting meant to protect authentication across Android versions of key apps like Word, PowerPoint, and Excel paved the way for attackers to steal logins and data.
Elizabeth Montalbano
Malicious Notifications Could Trick Google Gemini Users
6 days 16 hours ago
A prompt injection flaw in Google Gemini's voice assistant let attackers hide malicious commands in notifications, enabling social engineering and more.
Alexander Culafi
Checked
13 hours 37 minutes ago
Public RSS feed
darkreading feed