Why more security data has blurred companies’ view of risk
More security data can create blind spots. Here's how to regain visibility.
Cybersecurity News
Live Last read · last published · next check

The company said the remote-code execution vulnerability has been fully mitigated and no further action is necessary.

A "confidence disconnect" is plaguing the industry, a consulting firm said.

Resilience, not prevention, is key, analysts at the credit-rating agency said in a pair of new reports.

Support is growing for stricter oversight and increased financial resources for utilities in the wake of a cyberattack spree, suspected to be the work of Iran-linked threat groups.

Hackers are developing scripts disguised as legitimate software in attacks aimed at multiple industries, including energy and water.

These companies often have the hardest time balancing their roles as suppliers and customers, according to the risk management firm Black Kite.

Officials allege an IRGC-linked organization was behind a coordinated effort to steal research from American universities, companies and government agencies.

Researchers warn that unauthenticated attackers would be able to delete or modify publicly accessible projects.

The U.S. government's promises about the Gold Eagle coordination program are overblown, experts said, but the initiative could help organizations prioritize patching and mitigation.

The vulnerability has a maximum severity score of 10, indicating serious potential impact and relative ease to exploit by an attacker.

The June breach, which also exposed employees' information, underscored the supply-chain risks facing the healthcare sector.
More security data can create blind spots. Here's how to regain visibility.

The exfiltrated data may be related to misconfiguration of Microsoft Power Page portals, according to a new report.

With companies confronting more sophisticated threats, AI agents are driving demand for cybersecurity tools, CEO Chuck Robbins said.

A report shows how criminal actors are lowering the barriers to entry with sophisticated services, without ethical constraints.

The new program, meant to aggressively disrupt costly cybercrime schemes, carries numerous legal and security risks.
Network defenders are racing to secure their IT systems before criminal and state-actors circumvent existing guardrails.

Threat actors have already begun exploiting the flaw, according to the U.S. government.

Researchers warned that hackers are using voice-phishing attacks to pressure company employees under the guise of providing IT help desk services.