The firmware threat offers ultimate stealth and persistence — and may be distributed via tainted firmware components in a supply chain play, researchers theorize.
Follow Dark Reading:
 July 26, 2022
LATEST SECURITY NEWS & COMMENTARY
Rare 'CosmicStrand' UEFI Rootkit Swings into Cybercrime Orbit
The firmware threat offers ultimate stealth and persistence — and may be distributed via tainted firmware components in a supply chain play, researchers theorize.
Supercharged Version of Amadey Infostealer & Malware Dropper Bypasses AVs
Several threat actors used Amadey Bot previously to steal information and distribute malware such as the GandCrab ransomware and the FlawedAmmy RAT.
Critical Filewave MDM Vulnerabilities Allow Attackers Full Mobile Device Control
Two previously unknown critical vulnerabilities within FileWave’s multiplatform MDM system could grant malicious actors access to the platform's most privileged user account.
Getting Ahead of Supply Chain Attacks
Attackers are willing to replicate entire networks, purchase domains, and persist for months, not to mention spend significantly to make these campaigns successful.
T-Mobile Pitches $4-Per-Customer Settlement for Data Leak Impacting 80M People
After leaking 80 million US customer data records in a cyberattack last summer, T-Mobile offers to settle a wide-ranging class action suit for just $350 million.
Qakbot Is Back With a New Trick: DLL Sideloading
In the latest iteration, Qakbot operators are using DLL sideloading to deliver malware, a technique that places legitimate and malicious files together in a common directory to avoid detection.
MORE NEWS / MORE COMMENTARY
HOT TOPICS
ICYMI: Neopets & the Gaming Problem; SolarWinds Hackers Are Back; Google Ads Abused
Dark Reading's weekly roundup of all the OTHER important stories of the week.

What Firewalls Can — and Can't — Accomplish
Understanding the limitations of firewalls is important to protecting the organization from evolving threats.

What InfoSec Pros Can Teach the Organization About ESG
Security pros' experience with transparency and evaluating third-party partners positions them to act as key environmental, social, and governance advisers.

MORE
EDITORS' CHOICE
Critical Bugs Threaten to Crack Atlassian Confluence Workspaces Wide Open
A hardcoded password associated with the Questions for Confluence app has been publicly released, which will likely lead to exploit attempts that give cyberattackers access to all Confluence content.
LATEST FROM THE EDGE

Why Layer 8 Is Great
To help discern legitimate traffic from fraud, it helps to understand user intent as shown through their behavior.
LATEST FROM DR TECHNOLOGY

OpenFHE Brings New Encryption Tools to Developers
The open source fully homomorphic encryption library from Duality Technologies is intended to help developers build their own FHE-enabled applications.
WEBINARS
  • How Supply Chain Attacks Work - And What You Can Do to Stop Them

    The headline-making attack against Solarwinds sent a shockwave through the world and had many security and business leaders reexamining the security of their own supply chains. In a supply chain - or third party - attack, criminals infiltrate and disrupt ...

  • Building and Maintaining Security at the Network Edge

    Advances in networking and new technologies have expanded the possibilities of deploying applications at the network edge. These edge devices bring with them their own security management challenges and risks. How do you scale your security to manage the sheer ...

View More Dark Reading Webinars >>
WHITE PAPERS
FEATURED REPORTS
View More Dark Reading Reports >>
PRODUCTS & RELEASES
CURRENT ISSUE
DOWNLOAD THIS ISSUE
VIEW BACK ISSUES
Dark Reading Daily
-- Published By Dark Reading
Informa Tech Holdings LLC | Registered in the United States
with number 7418737 | 605 Third Ave., 22nd Floor, New York, New York 10158, USA
To opt-out of any future Dark Reading Daily Newsletter emails, please respond here.
Thoughts about this newsletter? Give us feedback.
Keep This Newsletter Out Of Your SPAM Folder
Don't let future editions go missing. Take a moment to add the newsletter's address to your anti-spam white list:
If you're not sure how to do that, ask your administrator or ISP. Or check your anti-spam utility's documentation.
We take your privacy very seriously. Please review our Privacy Statement.