Security News

US companies commit to safe, transparent AI development
2023-07-24 13:28

Seven US artificial intelligence giants - Amazon, Anthropic, Google, Inflection, Meta, Microsoft, and OpenAI - have publicly committed to "Help move toward safe, secure, and transparent development of AI technology." Test the security of their AI systems before launch Share knowledge about AI risk management best practices among themselves and with the government.

How to create Portainer teams for restricted development access
2023-04-17 23:03

How to create Portainer teams for restricted development access Jack Wallen shows you how to create a team and add users in Portainer in a secure way. With Teams, you can create multiple teams, add users and then create containers with restricted access to only the teams who need to manage specific deployments.

How to prevent fork bombs on your Linux development servers
2023-03-28 16:13

A fork bomb is a form of denial-of-service attack that uses the fork operation, which is executed recursively and can consume all system resources. How do you prevent this from happening? You lower the number of processes allowed on your Linux server.

In uncertain times, organizations prioritize tech skills development
2023-03-24 04:00

Though 65% of tech team leaders have been asked to cut costs, 72% still plan to increase their investment in tech skill development in 2023. 67% of tech managers reported that workforce reductions in their organization across software, IT, and data have resulted in their teams taking on more responsibility, while 47% of technologists agree they have had to perform additional responsibilities outside of their primary job function.

CI/CD: Necessary for modern software development, yet it carries a lot of risk
2023-03-02 23:10

SCSW CI/CD over the past decade has become the cornerstone of modern software development. "Today, CI/CD is where application code, build tools, third-party components, secrets, identities and even cloud resources come together," Adrian Diglio, principal program manager of secure software supply chain at Microsoft, told The Register.

What is the Best Pen Testing Schedule for Your Development Cycle?
2023-02-22 15:05

Whether you are using the traditional waterfall method for development, the more flexible agile approach, or the always-on continuous development, your pen testing schedule should reflect your specific needs. This pen testing schedule is sometimes referred to as traditional pen testing.

Establishing secure habits for software development in 2023
2023-02-09 06:00

Software development teams always strive to master their trade, improve their practices, and deliver secure applications and services, especially because application security risks are mounting and expectations are higher than ever. Despite continuous breaches at the fault of insecure code, secure coding training for development teams is still almost completely absent from computer science programs in top US colleges.

(ISC)² to aid cybersecurity professional development in emerging economies
2022-10-20 11:20

has signed a Memorandum of Understanding with the Korea Internet & Security Agency to strenghten cybersecurity professional development in emerging economies. The collaboration will leverage the expertise of both organizations to nurture the global cybersecurity workforce in South Korea and Global Cybersecurity Collaboration Network member countries.

GTA 6 in-development footage leaked, hack still unconfirmed
2022-09-19 11:27

"Its possible i could leak more data soon, GTA 5 and 6 source code and assets, GTA 6 testing build," added the individual, who goes by the handle "Teapotuberhacker" on GTAForums. Rockstar Games has yet to comment on any of the claims, but is working on getting the leaked videos removed from YouTube.

Hackers Had Access to LastPass's Development Systems for Four Days
2022-09-17 02:47

Password management solution LastPass shared more details pertaining to the security incident last month, disclosing that the threat actor had access to its systems for a four-day period in August 2022. "There is no evidence of any threat actor activity beyond the established timeline," LastPass CEO Karim Toubba said in an update shared on September 15, adding, "There is no evidence that this incident involved any access to customer data or encrypted password vaults."