FreshRSS

🔒
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ ☆ ✇ Dark Reading:

Pirated Final Cut Pro for macOS Offers Stealth Malware Delivery

By: Jai Vijayan, Contributing Writer, Dark Reading — February 23rd 2023 at 21:54
The number of people who have made the weaponized software available for sharing via torrent suggests that many unsuspecting victims may have downloaded the XMRig coin miner.

☐ ☆ ✇ Dark Reading:

Wiper Malware Surges Ahead, Spiking 53% in 3 Months

By: Jai Vijayan, Contributing Writer, Dark Reading — February 23rd 2023 at 18:50
Cybercriminals and hacktivists have joined state-backed actors in using sabotage-bent malware in destructive attacks, new report shows.

☐ ☆ ✇ Dark Reading:

Analysts Slam Twitter's Decision to Disable SMS-Based 2FA

By: Jai Vijayan, Contributing Writer, Dark Reading — February 21st 2023 at 23:00
Making the option available only to paid subscribers — while also claiming SMS authentication is broken — doesn't make sense, some say. Is it a cash grab?

☐ ☆ ✇ Dark Reading:

Majority of Ransomware Attacks Last Year Exploited Old Bugs

By: Jai Vijayan, Contributing Writer, Dark Reading — February 20th 2023 at 14:00
New research shows that 57 vulnerabilities that threat actors are currently using in ransomware attacks enable everything from initial access to data theft.

☐ ☆ ✇ Dark Reading:

Novel Spy Group Targets Telecoms in 'Precision-Targeted' Cyberattacks

By: Jai Vijayan, Contributing Writer, Dark Reading — February 17th 2023 at 21:34
The primary victims so far have been employees of telcos in the Middle East, who were hit with custom backdoors via the cloud, in a likely precursor to a broader attack.

☐ ☆ ✇ Dark Reading:

Window Snyder's Startup Launches Security Platform for IoT Device Makers

By: Jai Vijayan, Contributing Writer, Dark Reading — February 16th 2023 at 15:35
Thistle's technology will give device makers a way to easily integrate features for secure updates, memory management, and communications into their products, Snyder says.

☐ ☆ ✇ Dark Reading:

9 New Microsoft Bugs to Patch Now

By: Jai Vijayan, Contributing Writer, Dark Reading — February 14th 2023 at 22:20
78 new CVEs patched in this month's batch — nearly half of which are remotely executable and three of which attackers already are exploiting.

☐ ☆ ✇ Dark Reading:

Embattled VMware ESXi Hypervisor Flaw Exploitable in Myriad Ways

By: Jai Vijayan, Contributing Writer, Dark Reading — February 14th 2023 at 13:00
It's not just Internet-accessible hosts that are vulnerable, researchers say.

☐ ☆ ✇ Dark Reading:

Healthcare in the Crosshairs of North Korean Cyber Operations

By: Jai Vijayan, Contributing Writer, Dark Reading — February 13th 2023 at 20:50
CISA, FBI, and South Korean intelligence agencies warn that the North Korean government is sponsoring ransomware attacks to fund its cyber-espionage activities.

☐ ☆ ✇ Dark Reading:

Malicious Game Mods Target Dota 2 Game Users

By: Jai Vijayan, Contributing Writer, Dark Reading — February 10th 2023 at 17:38
Valve's unpatched JavaScript engine and incomplete modification vetting process for Steam-delivered mods led to user systems being backdoored.

☐ ☆ ✇ Dark Reading:

CISA Releases Recovery Script for Victims of ESXiArgs Ransomware

By: Jai Vijayan, Contributing Writer, Dark Reading — February 8th 2023 at 22:31
The malware has affected thousands of VMware ESXi hypervisors in the last few days.

☐ ☆ ✇ Dark Reading:

Fresh, Buggy Clop Ransomware Variant Targets Linux Systems

By: Jai Vijayan, Contributing Writer, Dark Reading — February 7th 2023 at 22:21
For the moment, victims can decrypt data without paying a ransom. But Clop is a ransomware variant that has caused havoc on Windows systems, so that's bound to change.

☐ ☆ ✇ Dark Reading:

Iran-Backed Actor Behind 'Holy Souls' Cyberattack on Charlie Hebdo, Microsoft Says

By: Jai Vijayan, Contributing Writer, Dark Reading — February 3rd 2023 at 21:41
The January attack was in retaliation for the satirical French magazine's decision to launch a cartoon contest to lampoon Iran's Supreme Leader.

☐ ☆ ✇ Dark Reading:

Scores of Redis Servers Infested by Sophisticated Custom-Built Malware

By: Jai Vijayan, Contributing Writer, Dark Reading — February 3rd 2023 at 16:00
At least 1,200 Redis servers worldwide have been infected with "HeadCrab" cryptominers since 2021.

☐ ☆ ✇ Dark Reading:

Discrepancies Discovered in Vulnerability Severity Ratings

By: Jai Vijayan, Contributing Writer, Dark Reading — February 2nd 2023 at 11:01
Differences in how the National Vulnerability Database (NVD) and vendors score bugs can make patch prioritization harder, study says.

☐ ☆ ✇ Dark Reading:

Inside Killnet: Pro-Russia Hacktivist Group's Support and Influence Grows

By: Jai Vijayan, Contributing Writer, Dark Reading — February 1st 2023 at 20:20
Killnet is building its profile, inspiring jewelry sales and rap anthems. But the impact of its DDoS attacks, like the ones that targeted 14 major US hospitals this week, remain largely questionable.

☐ ☆ ✇ Dark Reading:

Russia's Sandworm APT Launches Swarm of Wiper Attacks in Ukraine

By: Jai Vijayan, Contributing Writer, Dark Reading — January 30th 2023 at 22:32
The incidents are the latest indication of the growing popularity of dangerous disk wipers, created to disrupt and degrade critical infrastructure and other organizations.

☐ ☆ ✇ Dark Reading:

Convincing, Malicious Google Ads Look to Lift Password Manager Logins

By: Jai Vijayan, Contributing Writer, Dark Reading — January 30th 2023 at 17:15
Users searching for Bitwarden and 1Password's Web vaults on Google have recently reported seeing paid ads with links to cleverly spoofed sites for stealing credentials to their password vaults.

☐ ☆ ✇ Dark Reading:

How Noob Website Hackers Can Become Persistent Threats

By: Jai Vijayan, Contributing Writer, Dark Reading — January 27th 2023 at 15:49
An academic analysis of website defacement behavior by 241 new hackers shows there are four clear trajectories they can take in the future, researchers say.

☐ ☆ ✇ Dark Reading:

Researchers Pioneer PoC Exploit for NSA-Reported Bug in Windows CryptoAPI

By: Jai Vijayan, Contributing Writer, Dark Reading — January 25th 2023 at 20:30
The security vulnerability allows attackers to spoof a target certificate and masquerade as any website, among other things.

☐ ☆ ✇ Dark Reading:

TSA No-Fly List Snafu Highlights Risk of Keeping Sensitive Data in Dev Environments

By: Jai Vijayan, Contributing Writer, Dark Reading — January 23rd 2023 at 17:05
A Swiss hacker poking around in an unprotected Jenkins development server belonging to CommuteAir accessed the names and birthdates of some 1.5 million people on a TSA no-fly list from 2019.

☐ ☆ ✇ Dark Reading:

Ransomware Profits Decline as Victims Dig In, Refuse to Pay

By: Jai Vijayan, Contributing Writer, Dark Reading — January 20th 2023 at 21:18
Two new reports show ransomware revenues for threat actors dropped sharply in 2022 as more victims ignored ransom demands.

☐ ☆ ✇ Dark Reading:

Attackers Crafted Custom Malware for Fortinet Zero-Day

By: Jai Vijayan, Contributing Writer, Dark Reading — January 19th 2023 at 21:30
The "BoldMove" backdoor demonstrates a high level of knowledge of FortiOS, according to Mandiant researchers, who said the attacker appears to be based out of China.

☐ ☆ ✇ Dark Reading:

Cybercriminals Target Telecom Provider Networks

By: Jai Vijayan, Contributing Writer, Dark Reading — January 19th 2023 at 14:00
The growing use of mobile devices for MFA and the proliferation of 5G and VoIP in general could result in more attacks in future, experts say.

☐ ☆ ✇ Dark Reading:

Initial Access Broker Market Booms, Posing Growing Threat to Enterprises

By: Jai Vijayan, Contributing Writer, Dark Reading — January 17th 2023 at 22:08
A rapid increase in the number of operators in the space — the "locksmiths" of the cyber underground — has made it substantially cheaper for cybercriminals to buy access to target networks.

☐ ☆ ✇ Dark Reading:

US Airports in Cyberattack Crosshairs for Pro-Russian Group Killnet

By: Jai Vijayan, Contributing Writer, Dark Reading — October 10th 2022 at 20:45
Killnet calls on other groups to launch similar attacks against US civilian infrastructure, including marine terminals and logistics facilities, weather monitoring centers, and healthcare systems.

☐ ☆ ✇ Dark Reading:

Meta Flags Malicious Android, iOS Apps Affecting 1M Facebook Users

By: Jai Vijayan, Contributing Writer, Dark Reading — October 7th 2022 at 19:00
Some 400 mobile apps have posed as legitimate software on Google Play and the Apple App Store over the past year, and were designed to steal Facebook user credentials.

☐ ☆ ✇ Dark Reading:

US Consumers Are Finally Becoming More Security & Privacy Conscious

By: Jai Vijayan, Contributing Writer, Dark Reading — October 6th 2022 at 18:30
The trend, spotted by Consumer Reports, could mean good news for organizations struggling to contain remote work challenges.

☐ ☆ ✇ Dark Reading:

Microsoft Updates Mitigation for Exchange Server Zero-Days

By: Jai Vijayan, Contributing Writer, Dark Reading — October 4th 2022 at 20:27
Researchers had discovered that Microsoft's original mitigation steps for the so-called "ProxyNotShell" flaws was easily bypassed.

☐ ☆ ✇ Dark Reading:

Bumblebee Malware Loader's Payloads Significantly Vary by Victim System

By: Jai Vijayan, Contributing Writer, Dark Reading — October 3rd 2022 at 20:56
On some systems the malware drops infostealers and banking Trojans; on others it installs sophisticated post-compromise tools, new analysis shows.

☐ ☆ ✇ Dark Reading:

Reshaping the Threat Landscape: Deepfake Cyberattacks Are Here

By: Jai Vijayan, Contributing Writer, Dark Reading — September 30th 2022 at 19:10
It's time to dispel notions of deepfakes as an emergent threat. All the pieces for widespread attacks are in place and readily available to cybercriminals, even unsophisticated ones.

☐ ☆ ✇ Dark Reading:

Dangerous New Attack Technique Compromising VMware ESXi Hypervisors

By: Jai Vijayan, Contributing Writer, Dark Reading — September 29th 2022 at 19:26
China-based threat actor used poisoned vSphere Installation Bundles to deliver multiple backdoors on systems, security vendor says.

☐ ☆ ✇ Dark Reading:

Sophisticated Covert Cyberattack Campaign Targets Military Contractors

By: Jai Vijayan, Contributing Writer, Dark Reading — September 28th 2022 at 20:59
Malware used in the STEEP#MAVERICK campaign features rarely seen obfuscation, anti-analysis, and evasion capabilities.

☐ ☆ ✇ Dark Reading:

FBI Helping Australian Authorities Investigate Massive Optus Data Breach: Reports

By: Jai Vijayan, Contributing Writer, Dark Reading — September 27th 2022 at 20:27
Initial reports suggest a basic security error allowed the attacker to access the company's live customer database via an unauthenticated API.

☐ ☆ ✇ Dark Reading:

Despite Recession Jitters, M&A Dominates a Robust Cybersecurity Market

By: Jai Vijayan, Contributing Writer, Dark Reading — September 26th 2022 at 20:30
Funding has been somewhat lower than last year, but investment remains healthy, analysts say, amid thirst for cloud security in particular.

☐ ☆ ✇ Dark Reading:

Developer Leaks LockBit 3.0 Ransomware-Builder Code

By: Jai Vijayan, Contributing Writer, Dark Reading — September 22nd 2022 at 20:48
Code could allow other attackers to develop copycat versions of the malware, but it could help researchers understand the threat better as well.

☐ ☆ ✇ Dark Reading:

Threat Actor Abuses LinkedIn's Smart Links Feature to Harvest Credit Cards

By: Jai Vijayan, Contributing Writer, Dark Reading — September 21st 2022 at 20:30
The tactic is just one in a constantly expanding bag of tricks that attackers are using to get users to click on links and open malicious documents.

☐ ☆ ✇ Dark Reading:

ChromeLoader Malware Evolves into Prevalent, More Dangerous Cyber Threat

By: Jai Vijayan, Contributing Writer, Dark Reading — September 20th 2022 at 20:33
Microsoft and VMware are warning that the malware, which first surfaced as a browser-hijacking credential stealer, is now being used to drop ransomware, steal data, and crash systems at enterprises.

☐ ☆ ✇ Dark Reading:

Uber: Lapsus$ Targeted External Contractor With MFA Bombing Attack

By: Jai Vijayan, Contributing Writer, Dark Reading — September 19th 2022 at 21:24
The ride-sharing giant says a member of the notorious Lapsus$ hacking group started the attack by compromising an external contractor's credentials, as researchers parse the incident for takeaways.

☐ ☆ ✇ Dark Reading:

Attacker Apparently Didn't Have to Breach a Single System to Pwn Uber

By: Jai Vijayan, Contributing Writer, Dark Reading — September 16th 2022 at 20:37
Alleged teen hacker claims he found an admin password in a network share inside Uber that allowed complete access to ride-sharing giant's AWS, Windows, Google Cloud, VMware, and other environments.

☐ ☆ ✇ Dark Reading:

Malware on Pirated Content Sites a Major WFH Risk for Enterprises

By: Jai Vijayan, Contributing Writer, Dark Reading — September 15th 2022 at 19:37
Malware-laced ads are hauling in tens of millions of dollars in revenue for operators of pirated-content sites — posing a real risk to enterprises from remote employees.

☐ ☆ ✇ Dark Reading:

TeamTNT Hits Docker Containers via 150K Malicious Cloud Image Pulls

By: Jai Vijayan, Contributing Writer, Dark Reading — September 14th 2022 at 13:00
Honeypot activity exposed two credentials that the threat actor is using to host and distribute malicious container images, security vendor says.

☐ ☆ ✇ Dark Reading:

ShadowPad Threat Actors Return With Fresh Government Strikes, Updated Tools

By: Jai Vijayan, Contributing Writer, Dark Reading — September 13th 2022 at 19:43
Cyber spies are using legitimate apps for DLL sideloading, deploying an updated range of malware, including the new "Logdatter" info-stealer.

☐ ☆ ✇ Dark Reading:

Attackers Exploit Zero-Day WordPress Plug-in Vulnerability in BackupBuddy

By: Jai Vijayan, Contributing Writer, Dark Reading — September 9th 2022 at 17:56
The critical flaw in BackupBuddy is one of thousands of security issues reported in recent years in products that WordPress sites use to extend functionality.

☐ ☆ ✇ Dark Reading:

Darktrace Shares Plunge After Thoma Bravo Acquisition Falls Apart

By: Jai Vijayan, Contributing Writer, Dark Reading — September 8th 2022 at 19:19
No agreement could be reached on terms of a firm offer, the provider of AI-based cybersecurity products says.

☐ ☆ ✇ Dark Reading:

Vulnerability Exploits, Not Phishing, Are the Top Cyberattack Vector for Initial Compromise

By: Jai Vijayan, Contributing Writer, Dark Reading — September 8th 2022 at 15:20
A slew of Microsoft Exchange vulnerabilities (including ProxyLogon) fueled a surge in attacks targeting software flaws in 2021, but the trend has continued this year.

☐ ☆ ✇ Dark Reading:

Defenders Be Prepared: Cyberattacks Surge Against Linux Amid Cloud Migration

By: Jai Vijayan, Contributing Writer, Dark Reading — September 6th 2022 at 13:00
Ransomware in particular poses a major threat, but security vendors say there has been an increase in Linux-targeted cryptojacking, malware, and vulnerability exploits as well, and defenders need to be ready.

☐ ☆ ✇ Dark Reading:

Threat Actor Phishing PyPI Users Identified

By: Jai Vijayan, Contributing Writer, Dark Reading — September 1st 2022 at 20:35
"JuiceLedger" has escalated a campaign to distribute its information stealer by now going after developers who published code on the widely used Python code repository.

☐ ☆ ✇ Dark Reading:

Google Fixes 24 Vulnerabilities With New Chrome Update

By: Jai Vijayan, Contributing Writer, Dark Reading — August 31st 2022 at 20:10
But one issue that lets websites overwrite content on a user's system clipboard appears unfixed in the new Version 105 of Chrome.

☐ ☆ ✇ Dark Reading:

New ODGen Tool Unearths 180 Zero-Days in Node.js Libraries

By: Jai Vijayan, Contributing Writer, Dark Reading — August 30th 2022 at 22:21
New graph-based tool offers a better alternative to current approaches for finding vulnerabilities in JavaScript code, they note.

☐ ☆ ✇ Dark Reading:

'Sliver' Emerges as Cobalt Strike Alternative for Malicious C2

By: Jai Vijayan, Contributing Writer, Dark Reading — August 26th 2022 at 15:45
Microsoft and others say they have observed nation-state actors, ransomware purveyors, and assorted cybercriminals pivoting to an open source attack-emulation tool in recent campaigns.

☐ ☆ ✇ Dark Reading:

Thousands of Organizations Remain at Risk From Critical Zero-Click IP Camera Bug

By: Jai Vijayan, Contributing Writer, Dark Reading — August 25th 2022 at 13:00
The US Cybersecurity and Infrastructure Security Agency had wanted federal agencies to implement the fix for the RCE flaw in Hikvision cameras by Jan. 24, 2022.

☐ ☆ ✇ Dark Reading:

Thoma Bravo Buying Spree Highlights Hot Investor Interest in IAM Market

By: Jai Vijayan, Contributing Writer, Dark Reading — August 23rd 2022 at 20:00
M&A activity in the identity and access management (IAM) space has continued at a steady clip so far this year.

☐ ☆ ✇ Dark Reading:

Fake DDoS Protection Alerts Distribute Dangerous RAT

By: Jai Vijayan, Contributing Writer, Dark Reading — August 22nd 2022 at 22:07
Adversaries are injecting malicious JavaScript into numerous WordPress websites that triggers phony bot-related checks.

☐ ☆ ✇ Dark Reading:

Patch Now: 2 Apple Zero-Days Exploited in Wild

By: Jai Vijayan, Contributing Writer, Dark Reading — August 19th 2022 at 21:19
The fact that the flaws enable remote code execution, exist across all major Apple OS technologies, and are being actively exploited heightens the need for a quick response.

☐ ☆ ✇ Dark Reading:

China's APT41 Embraces Baffling Approach for Dropping Cobalt Strike Payload

By: Jai Vijayan, Contributing Writer, Dark Reading — August 18th 2022 at 18:34
The state-sponsored threat actor has switched up its tactics, also adding an automated SQL-injection tool to its bag of tricks for initial access.

☐ ☆ ✇ Dark Reading:

'DarkTortilla' Malware Wraps in Sophistication for High-Volume RAT Infections

By: Jai Vijayan, Contributing Writer, Dark Reading — August 17th 2022 at 18:39
The stealthy crypter, active since 2015, has been used to deliver a wide range of information stealers and RATs at a rapid, widespread clip.

☐ ☆ ✇ Dark Reading:

Microsoft Disrupts Russian Group's Multiyear Cyber-Espionage Campaign

By: Jai Vijayan, Contributing Writer, Dark Reading — August 16th 2022 at 19:54
"Seaborgium" is a highly persistent threat actor that has been targeting organizations and individuals of likely interest to the Russian government since at least 2017, company says.

☐ ☆ ✇ Dark Reading:

Most Q2 Attacks Targeted Old Microsoft Vulnerabilities

By: Jai Vijayan, Contributing Writer, Dark Reading — August 15th 2022 at 18:56
The most heavily targeted flaw last quarter was a remote code execution vulnerability in Microsoft Office that was disclosed and patched four years ago.

☐ ☆ ✇ Dark Reading:

Microsoft: We Don't Want to Zero-Day Our Customers

By: Jai Vijayan, Contributing Writer, Dark Reading — August 11th 2022 at 23:54
The head of Microsoft's Security Response Center defends keeping its initial vulnerability disclosures sparse — it is, she says, to protect customers.

❌