High-profile attacks have sharpened organizations' focus on software security

DevSecOps

High-profile ransomware and software supply chain disruptions are driving increased attention on software security, according to the latest Building Security In Maturity Model (BSIMM) report from Synopsys.

The BSIMM12 data indicates a 61 percent increase in software security groups' identification and management of open source over the past two years, almost certainly due to the popularity of open source components in modern software and the rise of attacks using open source projects as vectors.

Continue reading

New solution helps mid-sized businesses guard against cyberthreats

Threat concept

It isn't just big companies that suffer from cyberattacks. Increasingly smaller companies have become attractive targets as they have fewer resources to defend themselves.

Managed detection and response specialist deepwatch is today launching a new solution for medium sized businesses to significantly strengthen their protection against cyber threats.

Continue reading

Major companies lag in adopting domain security

Domain name

A majority of companies in the Forbes Global 2000 have been slow to adopt domain security measures that could help prevent them from ransomware attacks.

A new report from CSC finds 57 percent of the Global 2000 are relying on off-the-shelf consumer-grade domain registrars who offer limited security mechanisms to protect against domain and DNS hijacking.

Continue reading

Automated analysis can help stop security teams wasting 10,000 hours a year

Automation

It's well known that security teams are suffering from alert overload and new research from Invicti Security shows that false positives and the need for manual verification are serious problems.

Analysis of six years' worth of real-world vulnerability data shows enterprise security teams are spending nearly 10,000 hours a year checking unreliable vulnerability reports, and this could cost as much as half a million dollars annually.

Continue reading

Upgrading to Windows 11? Here are the compatible antivirus products you need

Microsoft is set to begin rolling out Windows 11 next week. For the most part, any programs you run on Windows 10 should run just fine on the new OS, although there will be exceptions.

Antivirus and security solutions are not all certified yet and installing security software that hasn't been fully tested with the new operating system could prove disastrous. Don't worry though, as antivirus testing service AV-Comparatives has done the hard work for you and today releases a list of "approved" security software. Is yours on the list?

Continue reading

IT leaders want trusted advice on SASE

SASE Secure Access Service Edge

New research from IT decision making platform AVANT shows that 85 percent of IT decision makers are familiar with and know about SASE solutions, but only 35 percent are using SASE currently.

However, there is a desire for more expertise, with 76 percent of IT decision-makers wishing to consult a trusted advisor to inform them on SASE decision making.

Continue reading

Add an extra layer of security to your entire household for under $30 with our Malwarebytes offer!

Malwarebytes

Just how bulletproof is your security package? Sadly, even the most reputable names are occasionally caught flat-footed by a new threat. If you’re serious about protecting your computer, you’ll leap at the chance to add a secondary layer of protection that works in tandem with your main package to catch threats that are missed (or ignored).

The good news is that Malwarebytes 4.0 stands ready and waiting to answer the call for reinforcements. And we’ve got a mouth-watering deal that will enable you to protect up to five devices -- Windows, Mac and Android -- in your household for the next two years -- all for under $30!

Continue reading

The impact of DDoS attacks on the enterprise [Q&A]

DDoS attacks

With the UK and US being amongst the top four most targeted nations for network DDoS attacks during the first half of 2021, this is clearly a problem that hasn't gone away amid all the pandemic-related news.

We spoke to David Elmaleh, senior product manager, Edge Services at Imperva. to discuss the impact DDoS attacks can have and why it's essential for organizations to monitor for anomalies relating to unexplained traffic spikes.

Continue reading

Security testing: Essential or simply supplemental?

testing

A 2019 study on the effectiveness of enterprise security strategies found that 53 percent of enterprises are clueless if their security tools are working. This means that they do not undertake security testing. If they have anything that has the guise of security validation, it is likely inconclusive or conducted in an unsystematic manner.

However, a more recent study found that around 70 percent of organizations perform penetration tests as a way of preventing cyber breaches. Many already acknowledge the importance of testing their security controls. This finding coincides with a report that says that the global security testing market is huge and rapidly accelerating.

Continue reading

3.8 billion combined Clubhouse and Facebook records for sale on the dark web

hack money

Data combined from the July 24 Clubhouse breach and Facebook user profiles has been used to compile a database of 3.8 billion entries and it could be yours for $100,000 -- though the seller is willing to split it up if you're strapped for cash.

The CyberNews research team uncovered a hacker forum posting from September 4 offering the data for sale. The poster claims the records include names, phone numbers, Clubhouse ranks, and Facebook profile links.

Continue reading

How banks are strengthening their cybersecurity posture [Q&A]

online banking

Cyberattacks and data breaches affect all kinds of organizations, but banks and financial services firms are at particular risk.

The shift to using mobile devices to carry out financial transactions has changed the threat landscape in recent years too. We spoke to Will LaSala, director of security solutions and security evangelist at OneSpan to find out more about what banks can do to bolster their security.

Continue reading

APT group uses Exchange vulnerability to spy on hotels, businesses and governments

Snooping

Cybersecurity company ESET has released new research into FamousSparrow, a cyberespionage group attacking hotels worldwide, as well as governments, international organizations, engineering companies and law firms.

The Advanced Persistent Threat (APT) group FamousSparrow has been exploiting the Microsoft Exchange vulnerability known as ProxyLogon, which allows hackers to take control of Exchange servers.

Continue reading

Divide between developer and security teams widens

Divided split chasm gulf gap

New research by Forrester for VMWare reveals a growing gulf between security and development teams.

Over half of developers surveyed (52.4 percent) say they feel that security policies stifle their innovation, and only 22 percent strongly agree that they understand which security policies they are expected to comply with.

Continue reading

Ransomware dominates attacks and new malware targets Unix systems

ransomware laptop

Ransomware now accounts for 69 percent of all attacks involving malware, according to the latest threatscape report from Positive Technologies.

The researchers have also identified a growing pattern of new malware specifically designed to penetrate Unix systems.

Continue reading

SIEM, SOAR and their role in improving cloud security [Q&A]

Cloud data security

It's increasingly common for enterprise systems to be in the cloud rather than in-house, but that throws up a whole range of new challenges when it comes to securing them.

We spoke to Dario Forte, vice president and general manager, security orchestration, at cloud management specialist Sumo Logic to find out more about what's involved in cloud security and how automation can help.

Continue reading

Load More Articles