Balbix, Thursday, August 14th, 2025
From Vulnerabilities To Exposures: Cyber Risk Lessons From The 2025 DBIR
Cybersecurity teams are drowning in CVEs - and attackers are counting on it.
more →
2,486 articles · page 14 of 50
Balbix, Thursday, August 14th, 2025
Cybersecurity teams are drowning in CVEs - and attackers are counting on it.
more →
CSO, Thursday, August 14th, 2025
Breaches continue to happen as SOC analysts deal with too many alerts or rules of engagement that stops them from acting. Here are some of the common problems and how to fix them.
more →
SC Media, Wednesday, August 13th, 2025
The cyber threat environment in 2025 has been characterized by the convergence of geopolitical ambition and advanced offensive tradecraft, with direct implications for global markets.
more →
HelpNet Security, Tuesday, August 12th, 2025
DNS is once again in the crosshairs of threat actors. According to the 2025 DNS Threat Landscape Report by Infoblox, attackers are changing tactics, and enterprises are feeling the pressure.
more →
The Hacker News, Tuesday, August 12th, 2025
Most security tools can't see what happens inside the browser, but that's where the majority of work, and risk, now lives. Security leaders deciding how to close that gap often face a choice: deploy a dedicated Enterprise Browser or add an enterprise-grade control layer to the browsers employees already use and trust.
more →
Architecture And Governance, Tuesday, August 12th, 2025
With the increasing uncertainty we currently experience in the political world stage comes that more and more companies reevaluate their presence in the cloud and the on-premise data center in the light of operational resilience and data sovereignty.
more →
Cyber Defense Magazine, Monday, August 11th, 2025
AI is transforming the way work gets done across industries. But while it improves business efficiencies, it also arms cybercriminals with highly effective tools.
more →
HelpNet Security, Friday, August 8th, 2025
Cybercriminals are getting better at lying. That's the takeaway from a new LevelBlue report, which outlines how attackers are using social engineering and legitimate tools to quietly move through environments before they're caught.
more →
eWeek, Friday, August 8th, 2025
We asked a simple question to cybersecurity pros at Black Hat 25: What keeps you up at night?
more →
Cloud Native Now
After spending a few days walking around Mandalay Bay for Black Hat 2025, one theme stood out more than the others: the widening gap between the security industry's innovations and the well-being of its people.
more →
ITProToday, Tuesday, August 5th, 2025
Exposed API keys are enabling sophisticated cyber-attacks, with organizations struggling to implement effective key management while infostealers quietly exfiltrate credentials to the dark web.
more →
SC Media, Tuesday, August 5th, 2025
Identity and access management is more about people than technology, according to Gerry Gebel, Strata Identity's Head of Standards, reports Forbes.
more →
techradar, Tuesday, August 5th, 2025
Security operations are under pressure from all sides. Threats are faster, attack surfaces are expanding, and demands on people and tools continue to grow.
more →
ITProToday, Tuesday, August 5th, 2025
Tool sprawl is a problem that just won't go away for security teams
more →
SC Media, Tuesday, August 5th, 2025
In October 2023, a coordinated cyberattack shut down parts of Denmark's railway network, delaying trains nationwide.
more →
HelpNet Security, Monday, August 4th, 2025
Organizations most confident in their identity security are often the least prepared, according to a new report from BeyondID. The study reveals a troubling gap between what organizations believe about their identity security programs and how they actually behave. Surprisingly, those expressing the highest confidence are adopting fewer best practices than their more cautious peers.
more →
CSO Online, Monday, August 4th, 2025
Cyberattackers are well aware of what's happening at this time of year, which is why they take advantage of seasonal circumstances to launch more aggressive campaigns.
more →
Cyber Defense Magazine, Monday, August 4th, 2025
When a major breach makes headlines, the impact ripples far beyond the individuals whose data has been compromised.
more →
SC Media, Friday, August 1st, 2025
Threat actors have launched a deluge of cyberattacks during the first six months of 2025, resulting in record-high credential theft, ransomware, and data breach incidence, Cybernews reports.
more →
Informationweek, Friday, August 1st, 2025
When security leaders embrace this truth and learn to speak in the language of leadership, they don't just protect the enterprise, they help lead it forward.
more →
DARKReading, Friday, August 1st, 2025
By creating a safe environment for open discussion, prioritizing human context alongside technical data, and involving diverse stakeholders, organizations can turn security incidents into accelerators of resilience.
more →
HelpNet Security, Thursday, July 31st, 2025
It's often the case that the simplest tools have the longest staying power, because they ultimately get the job done.
more →
DARKReading, Thursday, July 31st, 2025
Following a number of high-profile security and development issues surrounding the use of LLMs and GenAI to code and create applications, it's worth taking a temperature check to ask: Is this technology ready for prime time?
more →
The Register, Wednesday, July 30th, 2025
IBM report shows a rush to embrace technology without safeguarding it, and as for governance...
more →
ITPro, Wednesday, July 30th, 2025
Spending across major fronts comes in the wake of rising cloud security threats and growing skills gaps
more →
HelpNet Security, Wednesday, July 30th, 2025
Artemis is an open-source modular vulnerability scanner that checks different aspects of a website's security and translates the results into easy-to-understand messages that can be shared with the organizations being scanned.
more →
Virtualization, Wednesday, July 30th, 2025
In a stark warning for cloud security teams, a new Thales report reveals that while enterprises are pouring resources into AI-specific protections, only 8% are encrypting the majority of their sensitive cloud data -- leaving critical assets exposed even as AI-driven threats escalate and traditional security budgets shrink.
more →
TechRepublic, Tuesday, July 29th, 2025
Too many threat intelligence data feeds and not enough skilled analysts top the list of challenges for cybersecurity teams, says a new Google Cloud/Forrester report.
more →
ITProToday, Tuesday, July 29th, 2025
Organizations are increasingly inundated with cybersecurity reporting demands from a growing community of stakeholders. Follow these tips to eliminate reporting chaos, regain control, and enjoy peace of mind.
more →
The Hacker News, Tuesday, July 29th, 2025
Until recently, the cyber attacker methodology behind the biggest breaches of the last decade or so has been pretty consistent
more →
The Register, Friday, July 25th, 2025
Nobody thinks of running a website without HTTPs. Safer DNS still seems optional
more →
HelpNet Security, Friday, July 25th, 2025
Most organizations still miss basic identity security controls in the cloud, leaving them exposed to breaches, audit failures, and compliance violations. A new midyear benchmark from Unosecur found that nearly every company scanned had at least one high-risk issue, with an average of 40 control failures per organization.
more →
theCUBE research, Friday, July 25th, 2025
I spend my days talking to CISOs, analysts, and engineers. I sit in on vendor briefings, read the latest industry reports, and, like many of you, I scroll through the forums where real practitioners share their uncensored frustrations. And a clear, frankly alarming, theme is emerging: a deep and widening disconnect between the cybersecurity solutions being sold and the realities of the teams on the ground.
more →
techradar, Thursday, July 24th, 2025
Retail ransomware surges via trusted tools, insiders
more →
HelpNet Security, Thursday, July 24th, 2025
The Identity Theft Resource Center (ITRC) reports 1,732 publicly disclosed data breaches in H1 2025, marking a 5% increase over the same period in 2024. The ITRC could track a record number of compromises in 2025 if the current data breach trend continues through Q3 and Q4.
more →
Professional Security Magazine, Thursday, July 24th, 2025
The UK's National Cyber Security Centre (NCSC) has issued updated guidance on password best practices - recommending the use of password managers and passkeys to enhance organisational cybersecurity, writes Darren Guccione, CEO and co-founder of the vendor Keeper Security.
more →
DARKReading, Wednesday, July 23rd, 2025
Anyone can buy or collect data, but the goal must be to realize actionable insight relevant to the organization in question.
more →
techradar, Tuesday, July 22nd, 2025
Cyber attacks on retail are on the rise, and businesses are struggling to keep up
more →
ITPro, Monday, July 21st, 2025
The use of unauthorized devices is putting enterprises at huge risk
more →
DataCenter Knowledge, Monday, July 21st, 2025
Here's how cloud-native compares in meaning to cloud-based, cloud-ready, cloud-hosted, and cloud-first.
more →
DARKReading, Monday, July 21st, 2025
We cannot keep reacting to vulnerabilities as they emerge. We must assume the presence of unknown threats and reduce the blast radius that they can affect.
more →
CIODIVE, Monday, July 21st, 2025
Security chiefs are concerned about flaws in agents but also eager to see them replace humans in some roles, according to a report.
more →
The Hacker News, Monday, July 21st, 2025
By 2025, Zero Trust has evolved from a conceptual framework into an essential pillar of modern security. No longer merely theoretical, it's now a requirement that organizations must adopt.
more →
SC Media, Thursday, July 10th, 2025
Most of us are familiar with the concept of vulnerability management. But in recent years we've heard newer terms like cyber exposure, continuous threat exposure management (CTEM) and the more-encompassing exposure management.
more →
HelpNet Security, Thursday, July 10th, 2025
In this Help Net Security interview, Galal Ibrahim Maghola, former Head of Cybersecurity at G42 Company, discusses strategic approaches to implementing DevSecOps at scale.
more →
Technative, Thursday, July 10th, 2025
HackerOne is a leading platform that connects organizations with ethical hackers to identify and fix security vulnerabilities through bug bounty programs.
more →
Security Boulevard, Thursday, July 10th, 2025
Most security teams subscribe to more threat‑intel feeds than they can digest, yet attackers keep winning. Cyware's Jawahar Sivasankaran explains why: Outside the Fortune 500 and federal agencies, many organizations still treat cyberthreat intelligence (CTI) as another inbox rather than an engine for action.
more →
Search Security, Thursday, July 10th, 2025
In this video, Informa TechTarget customer success specialist Ben Clossey explains what identity and access management is and best practices that organizations should be following.
more →
techradar.pro, Thursday, July 10th, 2025
Crooks found a way to break up malware and hide it on DNS servers
more →
ITPro, Thursday, July 10th, 2025
Malicious actors are already using FileFix technique in malware-delivery dummy runs, Check Point claims
more →