darkreading
Please support the site operations by clicking ads.
Critical Infrastructure Under Siege: OT Security Still Lags
1 year 4 months ago
With critical infrastructure facing constant cyber threats from the Typhoons and other corners, federal agencies and others are warning security for the OT network, a core technology in many critical sectors, is not powered up enough.
Alexander Culafi, Senior News Writer, Dark Reading
Infosec Layoffs Aren't the Bargain That Boards May Think
1 year 4 months ago
Salary savings come with hidden costs, including insider threats and depleted cybersecurity defenses, conveying advantages to skilled adversaries, experts argue.
Becky Bracken
AI Agents May Have a Memory Problem
1 year 4 months ago
A new study by researchers at Princeton University and Sentient shows it's surprisingly easy to trigger malicious behavior from AI agents by implanting fake "memories" into the data they rely on for making decisions.
Jai Vijayan, Contributing Writer
Cyber-Risk Calculator Takes the Guesswork Out of Assessment
1 year 4 months ago
Resilience's new tool aims to help organizations better understand their risk profiles and make more informed decisions about improving their security posture.
Arielle Waldman
Ivanti EPMM Zero-Day Flaws Exploited in Chained Attack
1 year 4 months ago
The security software maker said the vulnerabilities in Endpoint Manager Mobile have been exploited in the wild against "a very limited number of customers" — for now — and stem from open source libraries.
Rob Wright
Marks & Spencer Confirms Customer Data Stolen in Cyberattack
1 year 4 months ago
The British retailer said no account passwords were compromised in last month's cyberattack, but the company will require customers to reset passwords "for extra peace of mind."
Kristina Beek, Associate Editor, Dark Reading
Congress Should Tackle Cyber Threats, Not Competition
1 year 4 months ago
Some members of Congress seem more intent on grabbing headlines than actually working to make America more cyber secure.
Greg Guice
Orca Security Gets AI-Powered Remediation From Opus Deal
1 year 4 months ago
The acquisition will enhance Orca's CNAPP offering with autonomous vulnerability remediation and prevention technologies from Opus.
Jeffrey Schwartz
Hacktivists Make Little Impact During India-Pakistan Conflict
1 year 4 months ago
While hacktivists claimed more than 100 successful attacks against Indian government, education, and military targets, the attacks were overblown in most cases and often did not even happen.
Robert Lemos, Contributing Writer
Building Effective Security Programs Requires Strategy, Patience, and Clear Vision
1 year 4 months ago
Capital One executives share insights on how organizations should design their security programs, implement passwordless technologies, and reduce their attack surface.
Arielle Waldman
Windows Zero-Day Bug Exploited for Browser-Led RCE
1 year 4 months ago
Microsoft's May 2025 Patch Tuesday update also contains four other actively exploited zero-day security vulnerabilities, two publicly known bugs, and 12 critical patches.
Tara Seals
Chinese Actor Hit Taiwanese Drone Makers, Supply Chains
1 year 4 months ago
Tidrone concentrated on military entities and the satellite sector, using their associated service providers and ERP software to infect not just drones but all the entities that are part of their supply chains.
Jai Vijayan, Contributing Writer
What Does EU's Bug Database Mean for Vulnerability Tracking?
1 year 4 months ago
The EU cyber agency ENISA has launched its vulnerability database, the EUVD; security experts shared their thoughts regarding what this means for CVEs, as well as the larger conversation around how bugs are tracked.
Alexander Culafi, Senior News Writer, Dark Reading
CISA Warns of TeleMessage Vuln Despite Low CVSS Score
1 year 4 months ago
Though the app claims to use end-to-end encryption, hackers have reportedly accessed archived data on the app's servers via a new vulnerability.
Kristina Beek, Associate Editor, Dark Reading
DeepSeek, Deep Research Mean Deep Changes for AI Security
1 year 4 months ago
Why securing the inference chain is now the top priority for AI applications and infrastructure.
Liam Crilly
North Korea's TA406 Targets Ukraine for Intel
1 year 4 months ago
The threat group's goal is to help Pyongyang assess risk to its troops deployed in Ukraine and to figure out if Moscow might want more.
Jai Vijayan, Contributing Writer
Fortra Expands SSE Capabilities With Lookout's Cloud Security Business
1 year 4 months ago
Fortra strengthens its endpoint-to-cloud security platform with the acquisition of Lookout's cloud application security broker, zero-trust network access, and secure Web gateway technologies.
Jeffrey Schwartz
NSO Group's Legal Loss May Do Little to Curtail Spyware
1 year 4 months ago
The $168 million judgment against NSO Group underscores how citizens put little store in the spyware industry's justifications for circumventing security — but will it matter?
Robert Lemos, Contributing Writer
Attackers Lace Fake Generative AI Tools With 'Noodlophile' Malware
1 year 4 months ago
Threat actors are scamming users by advertising legitimate-looking generative AI websites that, when visited, install credential-stealing malware onto the victim's computer.
Alexander Culafi, Senior News Writer, Dark Reading
Checked
18 hours 37 minutes ago
Public RSS feed
darkreading feed