Security
Headlines
HeadlinesLatestCVEs

Source

DARKReading

Encouraging Industry Voices to Write for the Commentary Section

Dark Reading will continue to publish Tech Talks and Ask the Expert pieces in the Commentary section. Read on for submission guidelines.

DARKReading
Attackers Exploited Gogs Zero-Day Flaw for Months

Wiz disclosed a still-unpatched vulnerability in self-hosted Git service Gogs, which is a bypass for a previous RCE bug disclosed last year.

#vulnerability#git#rce#zero_day
AI in OT Sparks Cascade of Complex Challenges

Using artificial intelligence in operational technology environments could be a bumpy ride full of trust issues and security challenges.

Copilot's No-Code AI Agents Liable to Leak Company Data

Microsoft puts the power of AI in the hands of everyday non-technical Joes. It's a nice idea, and a surefire recipe for security issues.

Storm-0249 Abuses EDR Processes in Stealthy Attacks

The initial access broker has been weaponizing endpoint detection and response (EDR) platforms and Windows utilities in recent high-precision attacks.

ClickFix Style Attack Uses Grok, ChatGPT for Malware Delivery

A new twist on the social engineering tactic is making waves, combining SEO poisoning and legitimate AI domains to install malware on victims' computers.

Feds: Pro-Russia Hacktivists Target US Critical Infrastructure

So far the attacks, which compromise virtual network computing (VNC) connections in OT systems, have not been particularly destructive, but this could change as they evolve.

Japanese Firms Suffer Long Tail of Ransomware Damage

Ransomware actors have targeted manufacturers, retailers, and the Japanese government, with many organizations requiring months to recover.

Microsoft Fixes Exploited Zero Day in Light Patch Tuesday

Proof-of-concept exploit code is publicly available for two other flaws in this month's Patch Tuesday. In total, the company issued patches for more than 1,150 flaws this year.

Packer-as-a-Service Shanya Hides Ransomware, Kills EDR

Shanya is the latest in an emerging field of packing malware, selling obfuscation functionality in order to help ransomware actors reach their target.