Security
Headlines
HeadlinesLatestCVEs

Source

DARKReading

SafePay Claims Ingram Micro Breach, Sets Ransom Deadline

The ransomware gang claims to have stolen 3.5TB of data, and told the technology distributor to pay up or suffer a data breach.

DARKReading
3 Things CFOs Need to Know About Mitigating Threats

To reposition cybersecurity as a strategic, business-critical investment, CFOs and CISOs play a critical role in articulating the significant ROI that robust security measures can deliver.

Russia's Secret Blizzard APT Gains Embassy Access via ISPs

An ongoing AitM campaign by the infamous Moscow-sponsored cyber-threat actor has widened its scope, dropping the dangerous ApolloShadow custom backdoor malware thanks to lawful intercept systems.

#backdoor
Getting a Cybersecurity Vibe Check on Vibe Coding

Following a number of high-profile security and development issues surrounding the use of LLMs and GenAI to code and create applications, it's worth taking a temperature check to ask: Is this technology ready for prime time?

What the Coinbase Breach Says About Insider Risk

The lesson from the breach is not just about what went wrong — but what could have gone right.

Dark Reading Confidential: Funding the CVE Program of the Future

Dark Reading Confidential Episode 8: Federal funding for the CVE Program expires in April 2026, and a trio of experts agree the industry isn't doing enough to deal with the looming crisis. Bugcrowd's Trey Ford, expert Adam Shostack, and vulnerability historian Brian Martin sit down with Dark Reading to help us figure out what a "good" future of the CVE Program would look like and how to get there.

Low-Code Tools in Microsoft Azure Allowed Unprivileged Access

Using the API Connections for Azure Logic Apps, a security researcher found unauthenticated users could access sensitive data of other customers.

Koreans Hacked, Blackmailed by 250+ Fake Mobile Apps

A swath of copycat Korean apps are hiding spyware, occasionally leading to highly personal, disturbing extortions.

Tonic Security Harnesses AI to Combat Remediation Challenges

Attackers are becoming faster at exploiting vulnerabilities, but this startup seeks to stop threats before they lead to breaches.

Palo Alto Networks Grabs IAM Provider CyberArk for $25B

The deal shakes up the identity and access management landscape and expands Palo Alto Networks' footprint in the cybersecurity market.