Security
Headlines
HeadlinesLatestCVEs

Source

DARKReading

Chinese Hackers Allegedly Pose as US Lawmaker

Chinese state-backed threat actors are suspected of posing as Michigan congressman John Moolenaar in a series of spear-phishing attacks.

DARKReading
The Quiet Revolution in Kubernetes Security

As Kubernetes becomes the foundation of enterprise infrastructure, the underlying operating system must evolve alongside it.

#kubernetes
Dormant macOS Backdoor ChillyHell Resurfaces

With multiple persistence mechanisms, the modular malware can brute-force passwords, drop payloads, and communicate over different protocols.

Southeast Asian Scam Centers Face More Financial Sanctions

Firms cooperating with cybercrime syndicates in Burma and Cambodia face sanctions by the US government and enforcement actions by China, but the scams continue to grow.

EoP Flaws Again Lead Microsoft Patch Day

Nearly half the CVEs Microsoft disclosed in its September security update, including one publicly known bug, enable escalation of privileges.

Is the Browser Becoming the New Endpoint?

While the jury is still out, it's clear that use has skyrocketed and security needs to align.

Qantas Reduces Executive Pay Following Cyberattack

The data breach, which occurred earlier this year, saw threat actors compromise a third-party platform to obtain Qantas customers' personal information.

Huge NPM Supply Chain Attack Goes Out With Whimper

Threat actors phished Qix's NPM account, then used their access to publish poisoned versions of 18 popular open source packages accounting for more than 2 billion weekly downloads.

Salty2FA Takes Phishing Kits to Enterprise Level

Cybercriminal operations use the same strategy and planning as legitimate organizations as they arm adversarial phishing kits with advanced features.

SentinelOne Announces Plans to Acquire Observo AI

The combined company will help customers separate data ingestion from SIEM to improve threat detection and response.