Netscout has expanded its Adaptive DDoS Protection solution to include outbound attack mitigation, allowing service providers to automatically detect and block DDoS traffic originating from compromised subscriber devices. This extension shifts protection focus upstream toward attack sources, helping operators prevent their own networks from being used to disrupt other targets. The week also featured new releases from F5 Networks, Intezer, and Tufin.
Policy & LegalSANS Internet Storm Center·2 days ago
In every MFA rollout, there will come a time where you think you are closing in on "done", and some automation to list what&#;x26;#;39;s left would be handy. Something quicker than scrolling through the web interface through thousands of accounts ...
One thing that folks never seem to do after "going to the CLOOOOUUUUD" is to look at their logs, logs that they would have checked daily when things were on premise.
Russian threat actors are incorporating OAuth abuse tactics into their targeted phishing campaigns, leveraging legitimate authentication mechanisms to compromise victims. The attacks specifically impersonate State Department communications, making them particularly credible to government and diplomatic personnel.
Enterprise cybersecurity expert Jake Williams joins the Dark Reading News Desk to explain why he decided to release his new agentic AI framework in the wake of the OpenAI attacks on Hugging Face.
A compromised maintainer account was used to publish malicious versions of three popular Rust crates—arrayref, internment, and append-only-vec—that injected a typosquatted dependency designed to download and execute arbitrary code during the build process. The Rust Project has since removed these poisoned releases from crates.io, though the affected versions had accumulated over 245 million downloads across their histories. This supply chain attack demonstrates the risk of build-time code execution in dependency management, where malicious payloads can be triggered silently during compilation rather than at runtime.
Suspected Russian cyber espionage groups UNC6293, UNC7005, and UNC5976 are exploiting legitimate authentication mechanisms including Google OAuth and WhatsApp linking to compromise accounts of individuals in academia, aerospace, defense, government, and think tanks across Europe and the United States. The threat actors demonstrate persistent and adaptive tactics in targeting these high-value sectors, leveraging trusted services to bypass conventional security measures and gain unauthorized access to sensitive accounts.
Chinese military-grade threat actors have deployed AI-assisted malware in a sophisticated espionage campaign dubbed 'SilkParasite' targeting Central Asian government entities. The operation leverages artificial intelligence in malware development to enhance the effectiveness of their infiltration efforts against the region.
In this video, Dark Reading editors discuss some of the news they didn't get a chance to cover, including some scary airplane security risks and the US government's newest "hack back" strategy.
Kyle Spitze, a leader of an offshoot group within the violent extremist collective Early 764, received a 77-year prison sentence for victimizing dozens of girls through coercion and exploitation. Spitze used threats of doxing and swatting to force victims to degrade themselves, marking the longest prison term yet imposed for a member of this nihilistic violent extremist network.
OpenAI presented details of its AI’s model’s cyberattack on Hugging Face at Black Hat last week. Simon Willison details the timeline. It’s really interesting to read through—and really impressive cyberoffense work.
N-able's Passportal password manager contained a vulnerability exposing master keys to the password vault, leaving sensitive credentials at risk for managed service providers and small-to-medium businesses. Despite the availability of patches, security concerns persist due to the product's cloud-based architecture, raising questions about whether such sensitive security tools should rely on cloud infrastructure at all.
Law enforcement training is falling behind the volume and rapid evolution of cybercrimes. Officers really only need to learn the basics, but lack of focus and budget hinder progress.
A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do. Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to code execution. Elsewhere, exposed systems, old bugs, odd hiding tricks, and AI-assisted exploit research keep lowering the effort needed to cause damage. Nothing here needs
U.S. government has issued a warning about active exploitation of Siemens S7 Series PLCs in critical infrastructure using AI-generated exploit scripts disguised as legitimate monitoring tools. The threat actors are leveraging AI-generated code for reconnaissance and capability development against organizations nationwide. This represents an emerging attack vector combining automated exploit generation with social engineering tactics to compromise industrial control systems.
A researcher has demonstrated that Apple's Find My location-tracking service can be manipulated to function on Linux systems through protocol manipulation, despite being designed exclusively for Apple devices. The exploit reveals a potential security gap in how the service validates and handles location data requests from non-Apple platforms.
Malicious versions of the arrayref Rust crate and other packages executed backdoors during the compilation process, representing a significant supply chain threat to developers using these dependencies. The attack infrastructure shows considerable overlap with recent North Korean-attributed supply chain campaigns targeting Mastra and axios, suggesting a potential connection or shared operational infrastructure between these threat actors.