Security
Headlines
HeadlinesLatestCVEs

Source

DARKReading

FedRAMP Rev. 5: How Cloud Service Providers Can Prepare

What cloud service providers need to know to prepare for FedRAMP Baselines Rev. 5, as documented in the new Transition Guide.

DARKReading
#auth#sap
9 Innovative Ways to Boost Security Hygiene for Cyber Awareness Month

If we really want to move the dial on security habits, it's time to think beyond phishing tests. Our panel of CISOs and other security heavy-hitters offer expert tips that go beyond the obvious.

More Okta Customers Hacked

Attackers compromised customer support files containing cookies and session tokens, which could result in malicious impersonation of valid Okta users.

From Snooze to Enthuse: Making Security Awareness Training 'Sticky'

Most companies offer some kind of awareness training these days. But how much of those lessons are employees actually retaining?

Critical SolarWinds RCE Bugs Enable Unauthorized Network Takeover

SolarWinds' access controls contain five high and three critical-severity security vulnerabilities that need to be patched yesterday.

Cisco Finds New Zero Day Bug, Pledges Patches in Days

A patch for the max severity zero-day bug tracked as CVE-2023-20198 is coming soon, but the bug has already led to the compromise of tens of thousands of Cisco devices. And now, there's a new unpatched threat.

DoD Gets Closer to Nominating Cyber Policy Chief

Though there is speculation regarding potential candidates, the Department of Defense will likely not nominate someone in the near term.

Ducktail Infostealer, DarkGate RAT Linked to Same Threat Actors

Vietnamese cybercrime groups are using multiple different MaaS infostealers and RATs to target the digital marketing sector.

SIM Card Ownership Slashed in Burkina Faso

Users could hold up to five SIM cards previously, but now they can only have two; it's a move that the government says is intended to cut down mobile spam levels.

Change From Within: 3 Cybersecurity Transformation Traps for CISOs to Avoid

To make cybersecurity an organizationwide priority, CISOs must avoid these common input, empathy, and alignment obstacles.