Are data brokers misbehaving when it comes to compliance with CCPA? Are their actions sinister or simply part of their learning curve? A UCI study looked at these data brokers' actions. Here's my take in #DarkReading
Are data brokers misbehaving when it comes to compliance with CCPA? Are their actions sinister or simply part of their learning curve? A UCI study looked at these data brokers' actions. Here's my take in #DarkReading
Why Cybersecurity Should Come Before AI in Schools
https://www.darkreading.com/endpoint-security/cybersecurity-before-ai-schools
more ai vulns on hugging face - lots of opps for security #darkreading
https://www.darkreading.com/cyber-risk/open-source-ai-models-pose-risks-of-malicious-code-vulnerabilities
I've been saying for decades now - NO SYSTEM IS SAFE FROM #HACKERS! #Mac users have always evangelized that "Macs are more secure, so I don't need antivirus software". Still untrue. Today, #Apple has a larger market share than ever. And while Apple hardware is seen as more secure by design, due in part to their closed eco-system, users are still the weakest link, which means YOU NEED TO PROTECT YOURSELF, FROM YOURSELF. This article from #DarkReading highlights this fact - no system is safe, including Macs.
Install anti-everything software on all your systems and devices. EVERYTHING is at risk. #StayVigalent #CyberSecurity #Hacking #InfoStealers
https://www.darkreading.com/threat-intelligence/banshee-malware-steals-apple-encryption-macs
#darkreading
Zivver, a leader in secure #communications, has published its latest report, shedding light on critical gaps in #email #security practices and their alignment with increasing regulatory requirements 2025
https://www.darkreading.com/endpoint-security/zivver-report-reveals-critical-challenges-in-email-security-for-2025
Hey lookie... I got quoted. Great article, @spiegelmama !
#infosec #darkreading
https://www.darkreading.com/cybersecurity-operations/hiring-gap-not-talent-gap
Hey, my first byline since disability leave is up at Dark Reading! It's about the hiring gap in cybersecurity and where it comes from. Big thanks to @Xavier and @hexamander for helping me with the research. It ended up being pretty involved, but with help from my boss, it found focus. #DarkReading #journalism #TheEdge #HiringGap #JobMarket #SelfPromotion https://www.darkreading.com/cybersecurity-operations/hiring-gap-not-talent-gap
#DarkReading I thought at first it was just missing a comma, but then the list continued. Whatever the case, it is a #typo
/application-security/gitlab-warns-max-severity-authentication-bypass-bug
Microsoft Copilot Studio Exploit Leaks Sensitive Cloud Data
#cybersecurity #AI #llmsecurity #llm #OWASP #Vulnerability #infosec #privacy #privacymatters #datasecurity #cloudsecurity #Copilot #exploit #aisecurity #darkreading
@ryo @StartpageSearch And where the war reporter (#darkreading.com) is ironically a #Cloudflare site thatβs broken for all those on the right side of privacy, and where the archive.org refuge is just a blank page:
Without being able to reach the article, I can only guess thereβs a healthy dose of #hypocrisy there.
SMBs often need cyber insurance too, but they don't necessarily have the staff or expertise to qualify for it. Here's what they can do today. Check it out in #DarkReading #cyberinsurance
https://www.darkreading.com/cyber-risk/making-cyber-insurance-available-for-small-biz-contractors
Title: "π¨ Critical Vulnerability Unearthed in PHPFusion CMS! π¨"
Researchers have discovered a critical vulnerability in PHPFusion CMS that could allow remote code execution. No patch is available yet, making it a ticking time bomb for websites using this CMS. ππ£
Security researchers at Synopsys have identified two significant vulnerabilities in PHPFusion, an open-source Content Management System (CMS) used by approximately 15 million websites globally.
CVE-2023-2453: A critical authenticated local file inclusion flaw that allows for remote code execution (RCE). To exploit this, an attacker needs to:
CVE-2023-4480: A moderate-severity bug related to an outdated dependency in a Fusion file manager component. To exploit this, an attacker needs administrator or super administrator privileges. The vulnerability allows an attacker to:
The vulnerabilities pose a significant risk, especially for small and midsize businesses that commonly use PHPFusion for online forums and community-driven websites. Immediate action is advised for vulnerability management.
π Source: Dark Reading by Jai Vijayan
π·οΈ Tags: #PHPFusion #CMS #Vulnerability #RemoteCodeExecution #InfoSec #CyberSecurity #DarkReading
Yes, this can actually be done. There's a tool called #MastoFeed that allows you to post RSS content to the fediverse. Some publications like #DarkReading are exploring using MastoFeed to publish their articles.
Their account can be found here: https://infosec.town/@darkreading
That being said, not sure if a bot account is what people are hoping for if #CBC decides to join the fediverse...
From Dark Reading:
#Linux #Ransomware Poses Significant Threat to Critical Infrastructure
https://www.darkreading.com/vulnerabilities-threats/linux-ransomware-poses-significant-threat-to-critical-infrastructure
Organizations running Linux distributions need to prepare to defend their systems against ransomware attacks. Steps to ensure resiliency and basics such as access control reduce major disruptions. ...
#darkreading
#darkreading coverage about our latest research
https://www.darkreading.com/attacks-breaches/purpleurchin-devops-cloud-malware-campaign
@cyberfixation I have a few sources I use:
:finger_point:#Thehackernews :heart_cyber: @thehackernews
:finger_point:#BleepingComputer :heart_cyber: @BleepingComputer
:finger_point:#DarkReading :heart_cyber:
:finger_point:#SCMedia
:finger_point:#DarknetDiaries podcast by @jackrhysider is just fun to listen to
:finger_point:Google's #TAG via RSS
:finger_point:Cisco Talos
:finger_point:US-CERT/CISA @CISAgov :fbi: :cia: :nsa: :nsaverified:
:finger_point:#OSINT via various #Telegram channels
:finger_point:#Politico on their dot-onion site :tor:
:finger_point:VX-Underground @vxunderground
:finger_point:darkfeed.io
:finger_point:and the occasional stroll across the #Darkweb forums I have access to. I don't like to be in the Darkweb for too long. That place can get real sketchy :anonymous: :WeAreNameless: :tor:
Most of the sites I mention have newsletters you can subscribe to, some you can stream via RSS to your favorite reader, others you just need to do the manual work and load up their site (worth it).
Dark Reading's panel of security experts deliver a magnum of bubbly hot takes on what 2023 will look like, featuring evil AIs, WWIII, wild workplace soon-to-be-norms, and more.. https://www.darkreading.com/attacks-breaches/boldest-cybersecurity-predictions-2023 #DarkReading #SecurityExperts #AI #WWIII
Regarding #Web3 and #Security thoughts for 2023. I don't do the predictions thing (just ask my marketing department), but I did share a few thoughts that will shape the Web3 space in during my keynote at the #BlackHat and #DarkReading Cybersecurity Outlook 2023 conference.
-All of the conditions and challenges present in 2022 will still be there in 2023
-As long as something has value, it will continue to be attacked by nation-states and criminals
-Survival mode isn't the best mode of operation for great security choices
-Look for increased government scrutiny, sanctions, and potential regulations
-The world is not a better place when vulnerable technology is in play
One thing is for sure, 2023 will bring more attacks and more compromises, so it's important to be vigilant.
DDoS Attack Platforms Shut Down in Global Law Enforcement Operation
Sweeping operation took down around 50 popular DDoS platforms, just one of which was used in 30M attacks, Europol says.
Seven administrators have been arrested, according to Europol's announcement, adding that just one of the services shut down by Operation Power Off was responsible for more than 30 million DDoS attacks.
Where #DarkReading Goes Next. #DarkReading Editor-in-Chief gives a complete rundown of all the #DarkReading #projects you might not even know about, his insight into the future of the #security industry, and how we plan to cover it.
https://www.darkreading.com/careers-and-people/where-dark-reading-goes-next/d/d-id/1338569?_mc=rss_x_drr_edt_aud_dr_x_x-rss-simple