Security
Headlines
HeadlinesLatestCVEs

Source

DARKReading

1Password and Fastmail Partner to Boost Online Privacy

Allows users to securely generate unique email aliases, adding an extra layer of online privacy.

DARKReading
Cyberspace, Cybergames, and Cyberspies

How cyberspace has become a global cybergames stage, where all of us are actors.

Russian Officials Arrest Group-IB CEO, Accuse Him of Treason

Ilya Sachkov, founder and CEO of the massive cybersecurity firm, was arrested on treason charges and will be in custody for two months.

Why Should I Care About HTTP Request Smuggling?

HTTP request smuggling is a growing vulnerability, but you can manage the risk with proper server configuration.

DAST to the Future: Shifting the Modern AppSec Paradigm

NTT Application Security's Modern AppSec Framework takes a DAST-first approach to defend applications where breaches happen — in production.

Sneaky Android Trojan Siphons Millions Using Premium SMS

More than 200 applications on the Google Play store have, until recently, allowed cybercriminals to deliver malicious Web content to victims' phones, likely garnering tens of millions of dollars.

75K Email Inboxes Hit in New Credential Phishing Campaign

Attacker used a legitimate — but likely deprecated — domain to sneak malicious emails past security filters, vendor says.

Outsourced Software Pose Greater Risks to Enterprise Application Security

In the wake of SolarWinds and other third-party attacks, security teams worry that outsourced applications pose risks to the organization's application security, according to Dark Reading's recent "How Enterprises Are Developing Secure Applications" report.

NSA, CISA Issue Guidelines for Selecting and Securing VPNs

Joint document includes configuration recommendations for hardening VPNs, and recommendations on how to select the most secure ones.

Most Large Enterprises Fail to Protect Their Domain Names

Of the largest 2,000 companies in the world, 81% fail to take simple security measures, such as locking their domain with the registrar, leaving them open to domain shenanigans.