Security News

6 Best VPNs for Canada in 2024 (Free & Paid VPNs)
2024-05-28 10:57

To help you choose a VPN, we've tested and named the top six best VPNs in Canada for 2024, including a totally free option. I picked IPVanish as one of the best VPNs for Canada because not only it supports unlimited devices, but it also offers apps and many unusual products, including smart TVs and the Apple Vision Pro.

Researchers Warn of CatDDoS Botnet and DNSBomb DDoS Attack Technique
2024-05-28 10:15

The threat actors behind the CatDDoS malware botnet have exploited over 80 known security flaws in various software over the past three months to infiltrate vulnerable devices and co-opt them into...

Attackers are probing Check Point Remote Access VPN devices
2024-05-28 09:41

Attackers are trying to gain access to Check Point VPN devices via local accounts protected only by passwords, the company has warned on Monday. In mid-April 2024, Cisco Talos warned about a global increase in brute-force attacks against VPN services, web application authentication interfaces and SSH services.

Take two APIs and call me in the morning: How healthcare research can cure cyber crime
2024-05-28 08:30

Your profile can be used to present content that appears more relevant based on your possible interests, such as by adapting the order in which content is shown to you, so that it is even easier for you to find content that matches your interests. Content presented to you on this service can be based on your content personalisation profiles, which can reflect your activity on this or other services, possible interests and personal aspects.

WordPress Plugin Exploited to Steal Credit Card Data from E-commerce Sites
2024-05-28 06:30

Unknown threat actors are abusing lesser-known code snippet plugins for WordPress to insert malicious PHP code in victim sites that are capable of harvesting credit card data. The campaign,...

TP-Link Gaming Router Vulnerability Exposes Users to Remote Code Attacks
2024-05-28 05:11

A maximum-severity security flaw has been disclosed in the TP-Link Archer C5400X gaming router that could lead to remote code execution on susceptible devices by sending specially crafted...

The evolution of security metrics for NIST CSF 2.0
2024-05-28 05:00

The NIST Cybersecurity Framework 2.0 underscored that metrics like these alone are insufficient and probably even improper when used as proxies for security outcomes. Combining effective use of metrics plus a deeper understanding of how security processes play out is the best way to build more security agility and enable teams to react more quickly and effectively.

How to combat alert fatigue in cybersecurity
2024-05-28 04:30

In this Help Net Security interview, Ken Gramley, CEO at Stamus Networks, discusses the primary causes of alert fatigue in cybersecurity and DevOps environments. Alert fatigue results from the overwhelming volume of event data generated by security tools, the prevalence of false positives, and the lack of clear event prioritization and actionable guidance.

Cybersecurity teams gear up for tougher challenges in 2024
2024-05-28 04:00

API sprawl - Researchers identified 1.7 million APIs in March alone-creating an uncharted network of 'shadow' and 'zombie' APIs that operate behind the scenes of many enterprise applications. Attacks targeting JSON and XML content types accounted for 38% of the blocks observed, highlighting attackers' focus on APIs.

Widespread data silos slow down security response times
2024-05-28 03:30

Although the goals and challenges of IT and security professionals intersect, 72% report security data and IT data are siloed in their organization, which contributes to corporate misalignment and elevated security risk, according to Ivanti. "While data silos can be a technology issue, resolving them and gaining a comprehensive understanding of an organization's risk landscape requires leadership. However, CIOs and CISOs are at odds. They face a tug-of-war challenge between enabling employee productivity while ensuring data security, which can lead to an increase in cyberattacks. To foster a more secure workplace, collaboration is essential," said Jeff Abbott, CEO, Ivanti.