A service that allows organizations to back up data in the cloud can accidentally leak sensitive data to the public Internet, paving the way for abuse by threat actors.
Follow Dark Reading:
 November 17, 2022
LATEST SECURITY NEWS & COMMENTARY
Thousands of Amazon RDS Snapshots Are Leaking Corporate PII
A service that allows organizations to back up data in the cloud can accidentally leak sensitive data to the public Internet, paving the way for abuse by threat actors.
MITRE Engenuity Launches Evaluations for Security Service Providers
The results are labor-intensive to parse, so knowing how to interpret them is key, security experts say.
China-Based Billbug APT Infiltrates Certificate Authority
Access to digital certificates would allow the Chinese-speaking espionage group to sign its custom malware and skate by security scanners.
Ukraine's 'IT Army' Stops 1,300 Cyberattacks in 8 Months of War
President Zelensky offers hard-won Ukrainian cybersecurity expertise to other countries that want to protect citizen populations.
BoostSecurity Emerges From Stealth With SaaS DevSecOps Platform
Fresh startup BoostSecurity has an SaaS platform for developers and security teams that provides automated tools to shore up cybersecurity within the software supply chain.
Cybersecurity Best Practice Is Critical for Winning the New Space Race
The race is actually a relay — one that requires collaboration to win.
New Ransomware Data Is In: What's Happening and How to Fight Back
Be proactive about data defense. Start with the right data, leverage domain expertise, and create models that help you target the most critical vulnerabilities.
MORE NEWS / MORE COMMENTARY
HOT TOPICS
Misconfigurations, Vulnerabilities Found in 95% of Applications
Weak configurations for encryption and missing security headers topped the list of software issues found during a variety of penetration and application security tests.

How Routine Pen Testing Can Reveal the Unseen Flaws in Your Cybersecurity Posture
Testing is an ongoing mission, not a one-and-done fix.

Evolving Security for Government Multiclouds
As the threat landscape increases, public cloud security needs to evolve.

MORE
EDITORS' CHOICE
Wipermania: Malware Remains a Potent Threat, 10 Years Since 'Shamoon'
An in-depth analysis of system-destroying malware families presented at Black Hat Middle East & Africa shows a growing nuance in terms of how they're deployed.
LATEST FROM THE EDGE

Are We Ready for AI-Generated Code?
Autocompleted code is convenient and quick, but it may expose your organization to security and compliance risks.
LATEST FROM DR TECHNOLOGY

Swimlane Introduces Low-Code, Automation Approach to OT Security
Automating security for OT infrastructure can help organizations combat a rising volume of cyber threats in an era when security professionals are in short supply.
WEBINARS
  • How to Protect Your Legacy Software Applications

    Agile development and continuous integration/continuous deployment have changed the game for application development practices, leading enterprises to "shift left" and build security into the software development lifecycle to catch any vulnerabilities before applications go into production. But what about ...

  • Cybersecurity: What You Don't Know Can Hurt You

    Do your attackers have a better view of your risks in your environment than you? With the aggressive move to the cloud comes an expanding and complex attack surface that adversaries are waiting to exploit. As a result, organizations are ...

View More Dark Reading Webinars >>
WHITE PAPERS
FEATURED REPORTS
View More Dark Reading Reports >>
PRODUCTS & RELEASES
CURRENT ISSUE
DOWNLOAD THIS ISSUE
VIEW BACK ISSUES
Dark Reading Daily
-- Published By Dark Reading
Informa Tech Holdings LLC | Registered in the United States
with number 7418737 | 605 Third Ave., 22nd Floor, New York, New York 10158, USA
To opt-out of any future Dark Reading Daily Newsletter emails, please respond here.
Thoughts about this newsletter? Give us feedback.
Keep This Newsletter Out Of Your SPAM Folder
Don't let future editions go missing. Take a moment to add the newsletter's address to your anti-spam white list:
If you're not sure how to do that, ask your administrator or ISP. Or check your anti-spam utility's documentation.
We take your privacy very seriously. Please review our Privacy Statement.