Security
Headlines
HeadlinesLatestCVEs

Source

DARKReading

Preventing Cyberattacks on Schools Starts With K–12 Cybersecurity Education

By investing in a strong future cybersecurity workforce, we can prevent future attacks on US critical infrastructure before they occur.

DARKReading
#dos#ssh
SolarWinds Execs Targeted by SEC, CEO Vows to Fight

CEO says SEC penalties related to the 2020 SolarWinds supply chain attacks are unwarranted and is ready to mount a defense to any legal actions against the company or its employees.

China's 'Volt Typhoon' APT Turns to Zoho ManageEngine for Fresh Cyberattacks

A recent campaign shows that the politically motivated threat actor has more tricks up its sleeve than previously known, targeting an old RCE flaw and wiping logs to cover their tracks.

ITDR Combines and Refines Familiar Cybersecurity Approaches

Identity threat detection and response adds user entity behavioral analytics to fraud detection, creating a powerful tool for real-time protection.

Silobreaker Unveils Geopolitical Threat Intelligence Capabilities With RANE at Infosecurity Europe 2023

Integration provides threat intel teams with an early warning system for geopolitical events that could trigger cyberattacks.

NSA: BlackLotus BootKit Patching Won't Prevent Compromise

It's unclear why the NSA issued in-depth mitigation guidance for the software boot threat now, but orgs should take steps to harden their environments.

Suspicious Smartwatches Mailed to US Army Personnel

Unknown senders have been shipping smartwatches to service members, leading to questions regarding what kind of ulterior motive is at play, malware or otherwise.

Microsoft Teams Attack Skips the Phish to Deliver Malware Directly

Exploiting a flaw in how the app handles communication with external tenants gives threat actors an easy way to send malicious files from a trusted source to an organization's employees, but no patch is imminent.

Why Legacy System Users Prioritize Uptime Over Security

For line-of-business execs, the fear of grinding mission-critical systems to a halt overrides the fear of ransomware. How can CISOs overcome this?