Security News > 2023

Playbook: Your First 100 Days as a vCISO - 5 Steps to Success
2023-12-11 11:45

In an increasingly digital world, no organization is spared from cyber threats. Yet, not every organization has the luxury of hiring a full-time, in-house CISO. This gap in cybersecurity...

SpyLoan Scandal: 18 Malicious Loan Apps Defraud Millions of Android Users
2023-12-11 11:30

Cybersecurity researchers have discovered 18 malicious loan apps for Android on the Google Play Store that have been collectively downloaded over 12 million times. "Despite their attractive...

Webinar — Psychology of Social Engineering: Decoding the Mind of a Cyber Attacker
2023-12-11 10:53

In the ever-evolving cybersecurity landscape, one method stands out for its chilling effectiveness – social engineering. But why does it work so well? The answer lies in the intricate dance...

VictoriaMetrics takes organic growth over investor pressure
2023-12-11 10:15

Co-founder Roman Khavronenko, who was speaking to us at a recent Kubecon event about open source, licensing, and the pressure of accepting venture capital, opines that, barring a few success stories, "In most cases, startups fail because of this huge pressure." The company operates open source time series database monitoring.

Kubescape open-source project adds Vulnerability Exploitability eXchange (VEX) support
2023-12-11 07:57

With its innovative feature for generating reliable Vulnerability Exploitability eXchange documents, Kubescape became the first open-source project to provide this functionality. Vulnerability Exploitability eXchange is a standard that facilitates the sharing and analyzing of information about vulnerabilities and their potential for exploitation.

Why are IT professionals not automating?
2023-12-11 06:00

The survey results clearly indicate that many IT professionals are not familiar with or don't see the value of certificate automation. Given the cost of certificate outages, this will be a precarious situation for IT professionals and security teams if they don't have a solid plan to deal with the accelerated certificate lifecycle management.

New PoolParty Process Injection Techniques Outsmart Top EDR Solutions
2023-12-11 05:58

A new collection of eight process injection techniques, collectively dubbed PoolParty, could be exploited to achieve code execution in Windows systems while evading endpoint detection and response...

SCS 9001 2.0 reveals enhanced controls for global supply chains
2023-12-11 05:30

Enhancing its predecessor, the SCS 9001 2.0 standard presents a more comprehensive global cybersecurity and supply chain security framework adaptable to various communication networks across industries and sectors. How does the SCS 9001 2.0 standard differ from its predecessor regarding cybersecurity and supply chain security?

Cybercriminals continue targeting open remote access products
2023-12-11 05:00

Cybercriminals still prefer targeting open remote access products, or like to leverage legitimate remote access tools to hide their malicious actions, according to WatchGuard. "Threat actors continue using different tools and methods in their attack campaigns, making it critical for organizations to keep abreast of the latest tactics to fortify their security strategy," said Corey Nachreiner, chief security officer at WatchGuard.

Security automation gains traction, prompting a “shift everywhere” philosophy
2023-12-11 04:30

The use of automated security technology is growing rapidly, which in turn is propagating the "Shift everywhere" philosophy - performing security tests throughout the entire software development life cycle - across more organizations, according to Synopsys. This year's findings revealed a clear trend of firms increasingly taking advantage of security automation to replace manual, subject matter expert-driven security activities to reduce cost and improve effectiveness.