Security
Headlines
HeadlinesLatestCVEs

Source

DARKReading

Ribbon Communications Breach Marks Latest Telecom Attack

The US telecom company disclosed that suspected nation-state actors first gained access to its network in December of last year, though it's unclear if attackers obtained sensitive data.

DARKReading
Government Approach to Disrupt Cyber Scams is 'Fragmented'

Users contend with cybersecurity scams throughout their day; a new Cyber Civic Engagement program wants to provide them with the skills to fight back.

Cyber's Role in the Rapid Rise of Digital Authoritarianism

Dark Reading Confidential Episode 11: Enterprise cyber teams are in prime position to push back against our current "Golden Age of Surveillance," according to our guests Ronald Deibert from Citizen Lab and David Greene from the EFF.

#git#auth
Zombie Projects Rise Again to Undermine Security

Companies left them for dead, but the remnants of old infrastructure and failed projects continue to haunt businesses' security teams.

An 18-Year-Old Codebase Left Smart Buildings Wide Open

Researcher Gjoko Krstic’s "Project Brainfog" exposed hundreds of zero-day vulnerabilities in building-automation systems still running hospitals, schools, and offices worldwide.

US Stands Out in Refusal to Sign UN Cybercrime Treaty

The agreement aims to help law enforcement prosecute cross-border cybercrime, but the final treaty could allow unchecked surveillance and human-rights abuses, critics say; and, it includes no protection for pen testers.

Critical Claroty Authentication Bypass Flaw Opened OT to Attack

CVE-2025-54603 gave attackers an opening to disrupt critical operational technology (OT) environments and critical infrastructure, plus steal data from them.

LotL Attack Hides Malware in Windows Native AI Stack

Security programs trust AI data files, but they shouldn't: they can conceal malware more stealthily than most file types.

Cloud Outages Highlight the Need for Resilient, Secure Infrastructure Recovery

Two massive technical outages over the past year underscore the need for cybersecurity teams to consider how to recover safely from disruptions without creating new security risks.

Data Leak Outs Students of Iran's MOIS Training Academy

A school for the Iranian state hackers of tomorrow has itself, ironically, been hacked.