Security
Headlines
HeadlinesLatestCVEs

Source

DARKReading

Cyberattackers Double Down on Bypassing MFA

As companies increasingly adopt MFA, cybercriminals are developing a variety of strategies to steal credentials and gain access to high-value accounts anyway.

DARKReading
#xss#web#auth
CISOs Share Their 3 Top Challenges for Cybersecurity Management

The biggest dilemmas in running a modern cybersecurity team are not all about software, said CISOs from HSBC, Citi, and Sepio.

Google Adds Client-Side Encryption to Gmail, Calendar

The data protection capability is now available across multiple Workspace applications: Gmail, Calendar, Drive, Docs, Slides, Sheets, and Meet.

Hoxhunt Launches Human Risk Management Platform

Platform uniquely designed to facilitate automated compliance, security behavior change.

LastPass DevOps Engineer Targeted for Cloud Decryption Keys in Latest Breach Revelation

The adversaries obtained a decryption key to a LastPass database containing multifactor authentication and federation information as well as customer vault data, company says.

Exfiltrator-22: The Newest Post-Exploitation Toolkit Nipping at Cobalt Strike's Heels

The framework-as-a-service signals an intensification of the cat-and-mouse game between defenders detecting lateral movement, and cybercriminals looking to go unnoticed.

US Marshals Ransomware Hit Is 'Major' Incident

Unknown attackers made off with a raft of PII, the Justice Department says — but witnesses in the protection program are still safe.

WannaCry Hero & Kronos Malware Author Named Cybrary Fellow

Marcus Hutchins, who set up a "kill switch" that stopped WannaCry's spread, later pled guilty to creating the infamous Kronos banking malware.

Pernicious Permissions: How Kubernetes Cryptomining Became an AWS Cloud Data Heist

The opportunistic "SCARLETEEL" attack on a firm's Amazon Web Services account turns into targeted data theft after the intruder uses an overpermissioned service to jump into cloud system.