Security
Headlines
HeadlinesLatestCVEs

Source

DARKReading

Microsoft 365 Users in US Face Raging Spate of Attacks

A voicemail-themed phishing campaign is hitting specific industry verticals across the country, bent on scavenging credentials that can be used for a range of nefarious purposes.

DARKReading
#vulnerability#web#mac#google#microsoft#git#java#acer#ssh
Synopsys Completes Acquisition of WhiteHat Security

Addition of WhiteHat Security provides Synopsys with SaaS capabilities and dynamic application security testing (DAST) technology.

Aqua Security Collaborates With Center for Internet Security to Create Guide for Software Supply Chain Security

In addition, Aqua Security unveiled a new open source tool, Chain-Bench, for auditing the software supply chain to ensure compliance with the new CIS guidelines.

Neustar Security Services Launches Public UltraDNS Health Check Site

Open service generates free report detailing potential gaps in compliance, configuration, and security for a user’s multiple domain names.

Russia's APT28 Launches Nuke-Themed Follina Exploit Campaign

Researchers have spotted the threat group, also known as Fancy Bear and Sofacy, using the Windows MSDT vulnerability to distribute information stealers to users in Ukraine.

Fresh Magecart Skimmer Attack Infrastructure Flagged by Analysts

Don't sleep on Magecart attacks, which security teams could miss by relying solely on automated crawlers and sandboxes, experts warn.

Getting a Better Handle on Identity Management in the Cloud

Treat identity management as a first-priority problem, not something to figure out later while you get your business up and running in the cloud.

Tanium Partners With ScreenMeet to Enable Employees to Securely Connect to Their Remote Desktops

partnership lets users access one-click ScreenMeet sessions from the Tanium platform.

Zscaler and AWS Expand Relationship

Zscaler also announced innovations built on Zscaler’s Zero Trust architecture and AWS.

Zscaler Launches Posture Control Solution

Enables DevOps and security teams to prioritize and remediate risks in cloud-native applications earlier in the development life cycle.