Major New OpenSSL Released A key part of the cryptographic infrastructure of the Internet, OpenSSL has turned 3.0, but rival Rust-based TLS, Rustls, promises to head off future security vulnerabilities.
New Malware Uses Novel Fileless Technique to Evade Detection PRIVATELOG and its installer STASHLOG first to use Common Log File System to stash secondary payload, Mandiant researchers say.
Attackers Moving Faster Inside Target Networks Criminals begin moving laterally inside a target network within 92 minutes of gaining access and demonstrate new stealthy capabilities, a new report shows.
Cybercriminals See Bountiful Harvest in Food Supply Chain Agriculture and food companies are seeing increased attacks from ransomware groups targeting the industry, prompting the DoJ and security firms to issue warnings.
The Great Payment Debate: How to Evaluate Your Ransomware Response With ransomware attacks on the rise, all organizations must assume they will eventually be a target and start putting prevention and mitigation strategies in place now.
I Moved to Cybersecurity After a Decade in Finance — Here's How You Can Too The cybersecurity industry needs employees with nontraditional backgrounds who can offer fresh perspectives. Here are tips for making a career switch to this growing and exciting field.
Hackers Shut Down a Pipeline. How Should the Energy Sector Respond? With all eyes on cybersecurity, the energy and utilities industries are adopting zero-trust frameworks. Here are three key steps to implementing zero trust for critical industries.
Back to School Pivots to Hack the School Any state with a vibrant economy — and schools — should be considered big targets for ransomware attackers.
Microsoft Windows Zero-Day Under Attack Microsoft has published mitigations and workarounds for a remote code execution vulnerability in MSHTML.
Faced with COVID Challenges, Enterprises Increase Security Spending Joint survey from Dark Reading and Omdia finds security spending went up amid COVID, but many organizations still feel their risk mitigation efforts fell short.
Ragnar Locker Threatens to Leak Data if Victims Contact Authorities The ransomware group says it will leak victims' stolen data if they seek help from law enforcement or data encryption experts.
CISA Releases Zero Trust Maturity Model for Public Comment The maturity model was drafted in June to help federal agencies comply with an executive order and is now ready for feedback.