Security News

Why Every Security Practitioner Should Attend mWISE
2023-08-02 14:01

What's in store for mWISE 2023? 80+ curated sessions. Organizers of the mWISE conference from Mandiant have announced a keynote panel addressing these questions, with a focus on both the challenges and the opportunities of the current times.

What is Data Security Posture Management (DSPM)?
2023-08-01 10:15

Data Security Posture Management is an approach to securing cloud data by ensuring that sensitive data always has the correct security posture - regardless of where it's been duplicated or moved...

Strategies for ensuring compliance and security in outdated healthcare IT systems
2023-08-01 04:00

With the average price tag for a healthcare data breach at an all-time high, the overall financial damage to an organization is high regarding economic loss and reputation repair. According to the...

The gap in users’ identity security knowledge gives cybercriminals an opening
2023-08-01 03:30

With exponential growth in the number of human and machine actors on the network and more sophisticated technology in more places, identity in this new era is rapidly becoming a super-human problem, according to RSA. Paradoxically, even in this world where AI can dynamically assess risks and automate responses to threats, humans will have an even more important and strategic role in cybersecurity and identity security. The report found significant gaps in respondents' knowledge concerning critical identity vulnerabilities, best practices for securing identity, and how to develop stronger identity security.

Canon warns of Wi-Fi security risks when discarding inkjet printers
2023-07-31 16:51

Canon is warning users of home, office, and large format inkjet printers that their Wi-Fi connection settings stored in the devices' memories are not wiped, as they should, during initialization, allowing others to gain access to the data. The specific information stored in a Canon printer varies depending on the model and configuration but generally includes the network SSID, the password, network type, assigned IP address, MAC address, and network profile.

What would sustainable security even look like?
2023-07-31 08:30

If one good shot can blow an organization open, where's the money going? More pertinently, why don't more people care? If that's politically acceptable in climate policy while large parts of the world are literally burning during the hottest month on record, where will the political will come from to fixing the much more abstruse problems with cybersecurity?

Open-source security challenges and complexities
2023-07-31 03:30

Open source refers to software or technology that is made available to the public with its source code openly accessible, editable, and distributable. In other words, the source code contains the underlying programming instructions and is freely available for anyone to view, modify, enhance, and share.

Hackers Deploy "SUBMARINE" Backdoor in Barracuda Email Security Gateway Attacks
2023-07-29 04:59

The U.S. Cybersecurity and Infrastructure Security Agency on Friday disclosed details of a "Novel persistent backdoor" called SUBMARINE deployed by threat actors in connection with the hack on Barracuda Email Security Gateway appliances. The findings come from an analysis of malware samples obtained from an unnamed organization that had been compromised by threat actors exploiting a critical flaw in ESG devices, CVE-2023-2868, which allows for remote command injection.

Twitter's rebranding to 'X' triggers Microsoft Edge security alert
2023-07-28 16:30

Microsoft Edge web browser has been displaying security warnings after Twitter changed its name to 'X'. Amid its rapid rebranding over the last few days, Twitter has also ditched the famed bird icon for a Unicode character which resembles the letter X but infact bears Mathematical meaning. Microsoft Edge warns this is a potential security issue-and it's working as intended.

Major Security Flaw Discovered in Metabase BI Software – Urgent Update Required
2023-07-28 05:46

Users of Metabase, a popular business intelligence and data visualization software package, are being advised to update to the latest version following the discovery of an "Extremely severe" flaw that could result in pre-authenticated remote code execution on affected installations. Tracked as CVE-2023-38646, the issue impacts open-source editions prior to 0.46.6.1 and Metabase Enterprise versions before 1.46.6.1.