Security
Headlines
HeadlinesLatestCVEs

Source

DARKReading

Iranian APT Actors Breach US Government Network

CISA says Federal Civilian Executive Branch systems were compromised through a Log4Shell vulnerability in an unpatched VMware Horizon server.

DARKReading
#vulnerability#vmware
Zero-Trust Initiatives Stall, as Cyberattack Costs Rocket to $1M per Incident

Researchers find current data protections strategies are failing to get the job done, and IT leaders are concerned, while a lack of qualified IT security talent hampers cyber-defense initiatives.

Instagram Impersonators Target Thousands, Slipping by Microsoft's Cybersecurity

The socially engineered campaign used a legitimate domain to send phishing emails to large swaths of university targets.

Spacecraft Vulnerable to Failure, Thanks to Aerospace Networking Bug

A single device with malicious code can foil a networking protocol used by spacecraft, aircraft, and industrial control systems, resulting in unpredictable operations and possible failures.

TMI Tech: How to Stop Vulnerable Software from 'Oversharing'

Stop chatty apps from oversharing and eliminate a hacker backdoor — train developers on "security first" while subjecting APIs to least-privilege zero-trust policies.

Cyber Monday Will Be the Most Fraudulent Day of the Season, Says SEON

Online fraud prevention company predicts Cyber Monday will see a 100% increase in online fraud attempts.

China-Based Billbug APT Infiltrates Certificate Authority

Access to digital certificates would allow the Chinese-speaking espionage group to sign its custom malware and skate by security scanners.

MITRE Engenuity Launches Evaluations for Security Service Providers

The results are labor-intensive to parse, so knowing how to interpret them is key, security experts say.