Catégorie: Enterprise

Une sélection quotidienne provenant de sources fiables.

2026-09-07 11:39 — BleepingComputer

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. [...]

2026-08-26 15:21 — Dark Reading

Red Flags That Expose Fake North Korean IT Workers

North Korean operatives posing as IT workers are improving their tactics, but researchers say there are still ways to spot them before they do damage.

2026-08-26 11:35 — The Hacker News

Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler

Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC). Group-IB, in a new analysis published today, described the cyber espionage actor as among the most active Iranian APT groups in 2026.…

2026-08-26 04:00 — Dark Reading

Nigeria Looks to Sovereign Cloud for Cyber, National Security

The West African nation launched financing, procurement, and infrastructure policies to boost its sovereign cloud initiative and increase domestic technical knowledge.

2026-08-21 10:00 — Dark Reading

Calling on Cyber Pros to Help Defend City Hall

Government agencies with smaller budgets need support — and here's how you can help.

2026-08-18 05:24 — BleepingComputer

Microsoft confirms outage affecting search in Microsoft 365 apps

Microsoft says some users are experiencing issues searching in Microsoft 365 apps, including Outlook on the web, Outlook desktop, SharePoint Online, and OneDrive. [...]

2026-08-14 10:00 — Dark Reading

What Boards Need to Know About Tech Risk

Why do so many boards underestimate technology risk until it becomes a crisis?

2026-08-13 10:41 — SecurityWeek

Cybersecurity M&A Roundup: 21 Deals Announced in July 2026

Significant cybersecurity M&A deals announced by Barracuda, CrowdStrike, Cyera, Okta, Palo Alto Networks, and Qualcomm. The post Cybersecurity M&A Roundup: 21 Deals Announced in July 2026 appeared first on SecurityWeek .

2026-08-12 12:28 — Dark Reading

Walmart Takes a 'Trusted Agent' Approach to Purple Teaming

Walmart colocates red and blue teams to build trust and improve security through collaborative purple teaming exercises

2026-08-12 08:41 — Dark Reading

Walmart Leaders Transform Security Operations Without Going Bananas

The big-box giant has scaled its defenses by encouraging trust and innovation. Good communications, transparency, and team spirit are key factors.

2026-08-10 11:59 — Dark Reading

Sherlock Holmes Was the 'OG' Social Engineer

The crime solver wore disguises, spied on targets, and built intelligence networks long before modern-day tactics emerged. He has lessons for today's ethical- and unethical hackers.

2026-08-06 16:07 — BleepingComputer

Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group

A recent wave of cyberattacks targeting hedge funds, private-equity firms, and other financial organizations has been linked to UNC6671, an extortion group reportedly associated with the BlackFile threat actors. [...]

2026-08-05 15:08 — Dark Reading

15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning

Researchers are calling attention to the risks inherent in automated network device provisioning, using a world-leading device manufacturer as a case study.

2026-08-04 17:45 — BleepingComputer

Phishing service spoofs RingCentral to steal Microsoft 365 accounts

The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing targeting Microsoft 365 accounts. [...]

2026-08-03 10:00 — Dark Reading

Is There Really a Fix for CISO Fatigue?

Accountability without any real authority is driving CISO burnout, and organizations need to take notice.

2026-07-31 10:00 — Dark Reading

The Morning After We Pull a Root of Trust, Nobody Owns It

The most valuable move any security team can make is building a certificate and key inventory.

2026-07-31 09:19 — Dark Reading

DROP Platform Lets Californians Reduce Digital Footprint

Hundreds of thousands of California residents have already registered for the Delete Request and Opt-out Platform (DROP), which launches Aug. 1. Other states could follow if the process goes smoothly.

2026-07-31 09:00 — Dark Reading

USA Fencing Lunges Into the Hidden Identity Challenge in Amateur Sports

The organization behind Team USA's Olympic/Paralympic fencing teams has automated identity verification to handle growing membership, cutting manual review time while ensuring athletes compete in the correct categories.

2026-07-30 11:28 — Dark Reading

Claude Mythos — Hype vs. Reality: What Security Teams Need to Know

In this edition of Reporters' Notebook, our journalists discuss the ins and outs of Anthropic's Claude Mythos rollout. How seriously should we take its risks? How big of a deal is it?

2026-07-30 07:54 — The Hacker News

Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents

Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file. Håkon Måløy disclosed the technique on July 28, 144 days after reporting it to Microsoft. In his proof of concept, the internally generated file triggered the same behavior when it was used in a second Copilot drafting…

2026-07-29 21:00 — Dark Reading

SE Asian Cybercriminal Syndicates Become a Global Power

The organized crime groups have moved from goods to services and continue to traffic people from at least 80 countries, costing nations in the region at least $88 billion in 2025 alone.

2026-07-29 19:26 — Dark Reading

Cybersecurity, Then & Now: A Visual Look at 20 Years of Change

Since 2006, Dark Reading has been at the forefront of covering cybersecurity. The more things change, the more they stay the same.

2026-07-29 19:26 — Dark Reading

Cybersecurity, Then & Now

Since 2006, Dark Reading has been at the forefront of covering cybersecurity. The more things change, the more they stay the same.

2026-07-27 17:39 — Dark Reading

Agentic Browsers Rewind Web Security by 20 Years

PleaseFix class of flaws makes it easy to socially engineer agentic browsers and highlights weaknesses in how they handle cross-origin requests.

2026-07-24 13:50 — BleepingComputer

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

2026-07-23 11:34 — BleepingComputer

Microsoft 365 outage affects Teams, SharePoint and other services

Microsoft is impacted by a massive outage affecting Teams and Microsoft 365 services, primarily affecting users in North America. [...]

2026-07-20 10:00 — Dark Reading

Cybersecurity Keeps Events 'Uneventful'

From the World Cup to the United States' 250th celebration, this year's event calendar has been packed with high-profile gatherings that drew global audiences, intense scrutiny, and enormous security demands.

2026-07-14 13:44 — Dark Reading

Manage Vendor Risk in a Few Practical Steps

Risk tolerance, exposure visibility, board oversight — handling third-party risk is complicated but achievable with disciplined, precise governance.

2026-07-13 03:30 — The Hacker News

Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365

An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing switched on. The command that did it: python3 -m http.server 8080, was still sitting in the readable .bash_history. From that one lapse, French security firm Lexfo lifted the operator's entire toolkit and pivoted through it…

2026-07-10 15:08 — Dark Reading

Jen Ellis: Connecting Cyber Community With Political Machinery

Security Pro File: On the heels of her recent honors as a Member of the Order of the British Empire (MBE), we take a look back at the events that shaped Jen Ellis' advocacy on behalf of security researchers.

2026-07-10 10:00 — Dark Reading

Fresh ATM Crypto Software Bugs: Jackpot or Bust?

Organizations, and possibly ATMs, are at risk of compromise, thanks to holes in a Microsoft BitLocker security wrapper.

2026-07-10 09:50 — Dark Reading

More Countries Jump on the Social Media 'Ban Wagon'

Age restrictions on accounts may be more of a stopgap because industry compliance is already falling short. Tech giants are struggling to follow the laws without affecting users.

2026-07-09 04:00 — Dark Reading

European Organizations Have a Collaboration Security Confidence Gap

A new survey shows security leaders have an inflated sense of safety regarding their collaboration tools and platforms.

Dernières