Security
Headlines
HeadlinesLatestCVEs

Source

DARKReading

CISA, MITRE Look to Take ATT&CK Framework Out of the Weeds

The Decider tool is designed to make the ATT&CK framework more accessible and usable for security analysts of every level, with an intuitive interface and simplified language.

DARKReading
#web#intel
Biden's Cybersecurity Strategy Calls for Software Liability, Tighter Critical Infrastructure Security

The new White House plan outlines proposed minimum security requirements in critical infrastructure — and for shifting liability for software products to vendors.

BlackLotus Bookit Found Targeting Windows 11

Sold for around $5,000 in hacking forums, the BlackLotus UEFI bootkit is capable of targeting even updated systems, researchers find.

What GoDaddy's Years-Long Breach Means for Millions of Clients

The same "sophisticated" threat actor has pummeled the domain host on an ongoing basis since 2020, making off with customer logins, source code, and more. Here's what to do.

Sale of Stolen Credentials and Initial Access Dominate Dark Web Markets

Access-as-a-service took off in underground markets with more than 775 million credentials for sale and thousands of ads for access-as-a-service.

Everybody Wants Least Privilege, So Why Isn't Anyone Achieving It?

Overcoming the obstacles of this security principle can mitigate the damages of an attack.

New Report: Inside the High Risk of Third-Party SaaS Apps

A new report from Adaptive Shield looks at the how volume of applications being connected to the SaaS stack and the risk they represent to company data.

Booking.com's OAuth Implementation Allows Full Account Takeover

Researchers exploited issues in the authentication protocol to force an open redirection from the popular hotel reservations site when users used Facebook to log in to accounts.

Hackers Target Young Gamers: How Your Child Can Cause Business Compromise

It's 10 p.m. Do you know what your children are playing? In the age of remote work, hackers are actively targeting kids, with implications for enterprises.

On Shaky Ground: Why Dependencies Will Be Your Downfall

There's never enough time or staff to scan code repositories. To avoid dependency confusion attacks, use automated CI/CD tools to make fixes in hard-to-manage software dependencies.