Avatar
Dark Reading
f9e52ebe8a51b90fdaacc735e822d6ee358d91dad406768f80af646b7c85d797
Dark Reading: Connecting the Information and Security Community

Threat Group Using Rare Data Transfer Tactic in New RemcosRAT Campaign

UNC-0050 is targeting government agencies in Ukraine in what appears to be a politically motivated intelligence-gathering operation.

https://www.darkreading.com/cyberattacks-data-breaches/threat-group-using-rare-data-transfer-tactic-in-new-remcosrat-campaign

Apache ERP Zero-Day Underscores Dangers of Incomplete Patches

Apache fixed a vulnerability in its OfBiz enterprise resource planning (ERP) framework last month, but attackers and researchers found a way around the patch.

https://www.darkreading.com/vulnerabilities-threats/apache-erp-0day-underscores-dangers-of-incomplete-patches

Airbus Looks to Acquire Atos Cybersecurity Unit for Nearly $2 Billion

One of the world's largest aerospace companies is eyeing a cybersecurity upgrade.

https://www.darkreading.com/ics-ot-security/airbus-acquire-atos-cybersecurity-unit-2-billion

Russia Kyivstar Hack Should Alarm West, Ukraine Security Chief Warns

If Ukraine's core telephone network can be taken out, organizations in the West could easily be next, Ukraine's SBU chief says.

https://www.darkreading.com/cyberattacks-data-breaches/russia-kyivstar-hack-should-alarm-west-ukraine-cyber-spy-warns

Administrator Account For Middle East Internet Registry Hacked

The compromise reportedly led to corruption in the routing of a Spanish telecom provider's network.

https://www.darkreading.com/cyberattacks-data-breaches/administrator-account-for-middle-east-internet-registry-hacked

Mandiant's X (Twitter) Account Hacked to Promote Crypto Scam

The hours-long breach — since resolved — directed users to a suspicious website as attackers posing as crypto-wallet service Phantom took over the feed of the Google subsidiary.

https://www.darkreading.com/cyberattacks-data-breaches/mandiant-s-x-twitter-account-hacked-to-promote-crypto-scam

Navigating the New Age of Cybersecurity Enforcement

The SolarWinds SEC lawsuit illuminates the potential risks faced by CISOs and other cybersecurity executives.

https://www.darkreading.com/cyberattacks-data-breaches/navigating-new-age-cybersecurity-enforcement

'Cyber Toufan' Hacktivists Leaked 100-Plus Israeli Orgs in One Month

A new threat actor just concluded a month and a half of two major leaks per day. Now comes phase two: follow-on attacks.

https://www.darkreading.com/cyberattacks-data-breaches/-cyber-toufan-hacktivists-leaked-100-plus-israeli-orgs-in-one-month

Getting Started With Passkeys, One Service at a Time

Passkeys help do away with passwords for logging into websites and cloud services. This Tech Tip outlines ways to get started.

https://www.darkreading.com/identity-access-management-security/how-to-get-started-using-passkeys

Is the vCISO Model Right for Your Organization?

More and more organizations are working with virtual CISOs to handle security-related responsibilities. Here are tips on how to find the right fit.

https://www.darkreading.com/cyber-risk/is-the-vciso-model-right-for-your-organization

Russian Agents Hack Webcams to Guide Missile Attacks on Kyiv

Incident prompts Ukraine's security service to ask webcam operators in country to stop live broadcasts.

https://www.darkreading.com/ics-ot-security/russian-agents-use-residential-webcams-to-gather-info-for-missile-attack-on-kyiv

Cybercriminals Flood Dark Web With X (Twitter) Gold Accounts

Verified accounts for celebs and organizations deliver a deep vein of cybercrime riches for crooks.

https://www.darkreading.com/application-security/cybercriminals-flood-dark-web-x-twitter-gold-accounts

Ransomware Group Claims Cyber Breach of Xerox Subsidiary

After Xerox cybersecurity personnel discovered the breach, they brought in third-party experts to investigate.

https://www.darkreading.com/cyberattacks-data-breaches/ransomware-group-claims-cyber-breach-on-xerox-subsidiary

LastPass Hikes Password Requirements to 12 Characters

A phased rollout will also prompt LastPass customers to re-enroll their accounts in multifactor authentication (MFA) to prevent future breaches.

https://www.darkreading.com/cybersecurity-operations/lastpass-hikes-password-requirements-12-characters