Security News

SaaS Compliance through the NIST Cybersecurity Framework
2024-02-20 10:53

The US National Institute of Standards and Technology (NIST) cybersecurity framework is one of the world's most important guidelines for securing networks. It can be applied to any number of...

Critical Flaws Found in ConnectWise ScreenConnect Software  - Patch Now
2024-02-20 10:38

ConnectWise has released software updates to address two security flaws in its ScreenConnect remote desktop and access software, including a critical bug that could enable remote code execution on...

Critical ConnectWise ScreenConnect vulnerabilities fixed, patch ASAP!
2024-02-20 10:02

ConnectWise has fixed two vulnerabilities in ScreenConnect that could allow attackers to execute remote code or directly impact confidential data or critical systems. ConnectWise ScreenConnect is a remote desktop software solution popular with managed services providers and businesses they offer services to, as well as help desk teams.

WordPress Bricks Theme Under Active Attack: Critical Flaw Impacts 25,000+ Sites
2024-02-20 09:08

A critical security flaw in the Bricks theme for WordPress is being actively exploited by threat actors to run arbitrary PHP code on susceptible installations. The flaw, tracked as CVE-2024-25600...

Two days into the Digital Services Act, EU wields it to deepen TikTok probe
2024-02-20 08:26

Two days after its Digital Services Act came into effect, the European Union used it to open an investigation into made-in-China social network TikTok. European Commissioner Thierry Breton delivered news of the probe in a Xeet that revealed the investigation will consider "Suspected breach of transparency & obligations to protect minors."

Iran and Hezbollah Hackers Launch Attacks to Influence Israel-Hamas Narrative
2024-02-20 06:01

Hackers backed by Iran and Hezbollah staged cyber attacks designed to undercut public support for the Israel-Hamas war after October 2023. This includes destructive attacks against key Israeli...

How to make sense of the new SEC cyber risk disclosure rules
2024-02-20 06:00

SEC's new cybersecurity risk management, strategy, governance, and incident disclosure rules, which require increased transparency around cybersecurity incidents, have been in effect since December 18, 2023. For businesses that already harbor concerns over their cybersecurity protections, visibility, and incident response preparedness, meeting the SEC's new incident reporting rules can be a serious challenge.

How decentralized identity is shaping the future of data protection
2024-02-20 05:30

Decentralized identity is an approach to identity management that allows users to control their identity information and eliminate the need to provide unnecessary amounts of personal information in order to access a service. By putting personal data in the power of the individual, decentralized identity increases privacy and reduces the possibility of fraud and account takeovers by helping ensure the person behind the credential is who they claim.

LockBit Ransomware's Darknet Domains Seized in Global Law Enforcement Raid
2024-02-20 05:25

An international law enforcement operation has led to the seizure of multiple darknet domains operated by LockBit, one of the most prolific ransomware groups, marking the latest in a long list of...

Why identity fraud costs organizations millions
2024-02-20 05:00

92% of respondents to a recent report shared that their organization had been a victim of identity fraud, costing an average of $4.3 million over the last 12 months. Only 40% stated identity verification as a top identity challenge, noting that many organizations still need to trust more secure authentication practices, patchy identity monitoring, and other outdated manual processes to do the job.