Security
Headlines
HeadlinesLatestCVEs

Source

DARKReading

Google Sheds Light on ShinyHunters' Salesforce Tactics

Mandiant provided proactive defenses against UNC6040's social engineering attacks that have led to several Salesforce breaches.

DARKReading
#google
Shutdown Threatens US Intel Sharing, Cyber Defense

Lapse of critical information sharing and mass furloughs at CISA are just some of the concerns.

A $50 'Battering RAM' Can Bust Confidential Computing

Researchers have demonstrated an attack that can break through modern Intel and AMD processor technologies that protect encrypted data stored in memory.

Undead Operating Systems Haunt Enterprise Security Networks

Windows 10 reaches end-of-life on Oct. 14, which will triple the number of vulnerable enterprise systems and create a massive attack surface for cybercriminals.

China Imposes One-Hour Reporting Rule for Major Cyber Incidents

The sweeping new regulations show that China's serious about hardening its own networks after launching widespread attacks on global networks.

New China APT Strikes With Precision and Persistence

Phantom Taurus demonstrates a deep understanding of Windows environments, including advanced components like IIServerCore, a fileless backdoor that executes in memory to evade detection.

'Klopatra' Trojan Makes Bank Transfers While You Sleep

A sophisticated new banking malware is hard to detect, capable of stealing lots of money, and infecting thousands of people in Italy and Spain.

China Exploited New VMware Bug for Nearly a Year

A seemingly benign privilege-escalation process in VMware and other software has likely benefited attackers and other malware strains for years, researchers noted.

Can Shadow AI Risks Be Stopped?

Agentic AI has introduced abundant shadow artificial intelligence (AI) risks. Cybersecurity startup Entro Security extends its platform to help enterprises combat the growing issue.

'Trifecta' of Google Gemini Flaws Turn AI Into Attack Vehicle

Flaws in individual models of Google's AI suite created significant security and privacy risks for users, demonstrating the need for heightened defenses.