Avatar
Dark Reading
f9e52ebe8a51b90fdaacc735e822d6ee358d91dad406768f80af646b7c85d797
Dark Reading: Connecting the Information and Security Community

Group-IB: 'GoldDigger' Banking Trojan Targets Vietnamese Organizations

The malware uses software to evade detection while also making it difficult to analyze.

https://www.darkreading.com/threat-intelligence/group-ib-golddigger-banking-trojan-targeting-vietnamese-organizations

Unkillable? Qakbot Infections Fly On Even After Its High-Profile Raid

A literal seven-nation (cyber) army wasn't enough to hold back the famous initial access broker (IAB) for long — it's been chugging along, spreading ransomware, despite a massive takedown in August.

https://www.darkreading.com/attacks-breaches/qakbot-infections-continue-even-after-high-profile-raid

Critical Zero-Day Bug in Atlassian Confluence Under Active Exploit

Patch now: The Atlassian security vulnerability appears to be a remotely exploitable privilege-escalation bug that cyberattackers could use to crack collaboration environments wide open.

https://www.darkreading.com/application-security/critical-zero-day-atlassian-confluence-active-exploit

Could Cybersecurity Breaches Become Harmless in the Future?

With these five steps, organizations can develop stronger security practices and make the inevitable breaches inconsequential.

https://www.darkreading.com/vulnerabilities-threats/could-cybersecurity-breaches-become-harmless-in-the-future-

Insurance Companies Have a Lot to Lose in Cyberattacks

Not only do insurance companies collate sensitive information from their clients, but they also generate their own corporate data to protect.

https://www.darkreading.com/edge/insurance-companies-have-a-lot-to-lose-in-cyberattacks

Bing Chat LLM Tricked into Circumventing CAPTCHA Filter

By reframing the narrative of the filter, the large-language model chatbot was more willing to solve the visual puzzle and override its programming.

https://www.darkreading.com/application-security/bing-chat-llm-tricked-into-circumventing-captcha-filter

AWS Plans Multifactor Authentication Mandates for 2024

Amazon will add new MFA requirements for users with the highest privileges, with plans to include other user levels over time.

https://www.darkreading.com/cloud/aws-plans-multifactor-authentication-mandates-for-2024

On the Dark Web, Prices Are Down for Middle Eastern Network Access

A mere $35 can buy you stealth access to corporate networks across the region, according to new research.

https://www.darkreading.com/dr-global/on-the-dark-web-prices-are-down-for-middle-eastern-network-access

'Looney Tunables' Bug Opens Millions of Linux Systems to Root Takeover

The flaw poses a significant risk of unauthorized data access, system alterations, potential data theft, and complete takeover of vulnerable systems, especially in the IoT and embedded computing space...

https://www.darkreading.com/vulnerabilities-threats/millions-linux-systems-looney-tunables-bug-root-takeover

Breaches Are the Cost of Doing Business, but NIST Is Here to Help

Treating the NIST Cybersecurity Framework as a business requirement is a strong step toward preventing breaches.

https://www.darkreading.com/vulnerabilities-threats/breaches-are-the-cost-of-doing-business-but-nist-is-here-to-help

Turnkey Rootkit for Amateur Hackers Makes Supply Chain Attacks Easy

It's never been easier to hide malware in plain sight in open source software package repositories, and "DiscordRAT 2.0" now makes it easy to take advantage of those who stumble upon it.

https://www.darkreading.com/application-security/turnkey-rootkit-amateur-hackers-supply-chain-attacks

Patch Confusion for Critical Exim Bug Puts Email Servers at Risk--Again

Defenders have been left scrambling after the way patches were released for six flaws in the open source mail server, which is the most popular mail transfer agent on the Internet.

https://www.darkreading.com/cloud/patch-confusion-critical-exim-bug-email-servers-risk