Security News

5 types of cybersecurity tools every admin should know
2022-03-29 19:08

I have a shortlist of five types of tools your admins must know to keep tabs on your desktops, servers and networks. Pentesting tools are an absolute must for gauging the security of your systems.

ANY.RUN vs. Joe Sandbox: Malware analysis tools comparison
2022-03-23 22:02

This type of an environment is generally built to run risky files and determine whether those files represent a malware threat. Modern sandboxes allow companies or individuals to check any kind of files, including Microsoft Office files, PDF files and any executable file.

The problem with multiple cloud security tools: Alert fatigue and burnout
2022-03-18 05:00

Orca Security released a research report on public cloud security alert fatigue. "Multiple, disconnected tools continue to plague security teams. Having to sift through hundreds of 'high priority' often meaningless alerts is causing security practitioners to become overwhelmed and leading to burnout and turnover, exacerbating cybersecurity staff shortages," said Avi Shua, CEO, Orca Security.

Why Enterprise Threat Mitigation Requires Automated, Single-Purpose Tools
2022-03-14 06:19

As much as threat mitigation is to a degree a specialist task involving cybersecurity experts, the day to day of threat mitigation often still comes down to systems administrators. In this article, we outline the difficulties implied by enterprise threat mitigation, and explain why automated, purpose-built mitigation tools are the way forward.

Russian Ransomware Gang Retool Custom Hacking Tools of Other APT Groups
2022-03-14 05:48

A Russian-speaking ransomware outfit likely targeted an unnamed entity in the gambling and gaming sector in Europe and Central America by repurposing custom tools developed by other APT groups like Iran's MuddyWater, new research has found. The unusual attack chain involved the abuse of stolen credentials to gain unauthorized access to the victim network, ultimately leading to the deployment of Cobalt Strike payloads on compromised assets, said Felipe Duarte and Ido Naor, researchers at Israeli incident response firm Security Joes, in a report published last week.

U.S. Cybersecurity Agency Publishes List of Free Security Tools and Services
2022-02-19 21:51

The U.S. Cybersecurity and Infrastructure Security Agency on Friday published a repository of free tools and services to enable organizations to mitigate, detect, and respond effectively to malicious attacks and further improve their security posture. The "Free Cybersecurity Services and Tools" resource hub comprises a mix of services provided by CISA, open-source utilities, and other implements offered by private and public sector organizations across the cybersecurity community.

CISA compiles list of free cybersecurity tools and services
2022-02-19 16:15

The U.S. Cybersecurity and Infrastructure Security Agency has published a list of free cybersecurity services and tools to help organizations increase their security capabilities and better defend against cyberattacks. While the set is neither comprehensive nor impervious to change, it aims to mature an entity's cybersecurity risk management when combined with baseline security practices for a strong cybersecurity program.

Cyber threat intelligence software: How to choose the right CTI tools for your business
2022-02-18 23:04

Cyber threat intelligence is a concept that is crucial to the security of corporate networks, yet it can be difficult to really understand the ideas behind it, not to mention the implementation of threat intelligence within the company's IT and security structures. Before diving into what cyber threat intelligence is, it is essential to understand what the word "Threat" defines.

CISA publishes list of free security tools for business protection
2022-02-18 20:08

"CISA is super proud to announce the start of a new catalog of free resources available to those critical infrastructure owners and operators who would benefit from tools to help their security and resilience," said CISA director Jen Easterly in a statement. The Register asked CISA to clarify the selection criteria for inclusion on the list.

Kali Linux 2022.1 released: New tools, kali-linux-everything, visual changes
2022-02-15 08:46

Offensive Security has released Kali Linux 2022.1, the latest version of its popular open source penetration testing platform. Visually refreshed and with improved usability for visually impaired users, it comes also with a new "Kali-linux-everything" image, wider compatibility for Kali's SSH client, and new tools.