Security News > 2024 > November

Navigating the compliance labyrinth: A CSO’s guide to scaling security
2024-11-18 05:40

Imagine navigating a labyrinth where the walls constantly shift, and the path ahead is obscured by fog. If this brings up a visceral image, you’ve either seen David Bowie’s iconic film or are very...

Transforming code scanning and threat detection with GenAI
2024-11-18 05:30

In this Help Net Security interview, Stuart McClure, CEO of Qwiet AI, discusses the evolution of code scanning practices, highlighting the shift from reactive fixes to proactive risk management....

Evaluating GRC tools
2024-11-18 05:00

According to Gartner, the broad range of pricing for government, risk, and compliance (GRC) tools requires enterprise risk management (ERM) leaders to be well-versed in distinct pricing tiers of...

Urgent: Critical WordPress Plugin Vulnerability Exposes Over 4 Million Sites
2024-11-18 04:52

A critical authentication bypass vulnerability has been disclosed in the Really Simple Security (formerly Really Simple SSL) plugin for WordPress that, if successfully exploited, could grant an...

ScubaGear: Open-source tool to assess Microsoft 365 configurations for security gaps
2024-11-18 04:30

ScubaGear is an open-source tool the Cybersecurity and Infrastructure Security Agency (CISA) created to automatically evaluate Microsoft 365 (M365) configurations for potential security gaps....

How and where to report cybercrime: What you need to know
2024-11-18 04:00

Cybercrime reporting mechanisms vary across the globe, with each country offering different methods for citizens to report cybercrime, including online fraud, identity theft, and other...

Teen serial swatter-for-hire busted, pleads guilty, could face 20 years
2024-11-18 00:31

PLUS: Cost of Halliburton hack disclosed; Time to dump old D-Link NAS; More UN cybercrime convention concerns; and more Infosec in brief A teenager has pleaded guilty to calling in more than 375...

Will passkeys ever replace passwords? Can they?
2024-11-17 18:30

Here's why they really should Systems Approach I have been playing around with passkeys, or as they are formally known, discoverable credentials.…

Phishing emails increasingly use SVG attachments to evade detection
2024-11-17 16:25

Threat actors increasingly use Scalable Vector Graphics (SVG) attachments to display phishing forms or deploy malware while evading detection. [...]

Security plugin flaw in millions of WordPress sites gives admin access
2024-11-17 15:19

A critical authentication bypass vulnerability has been discovered impacting the WordPress plugin 'Really Simple Security' (formerly 'Really Simple SSL'), including both free and Pro versions. [...]