Security
Headlines
HeadlinesLatestCVEs

Source

DARKReading

Outsourced Software Pose Greater Risks to Enterprise Application Security

In the wake of SolarWinds and other third-party attacks, security teams worry that outsourced applications pose risks to the organization's application security, according to Dark Reading's recent "How Enterprises Are Developing Secure Applications" report.

DARKReading
NSA, CISA Issue Guidelines for Selecting and Securing VPNs

Joint document includes configuration recommendations for hardening VPNs, and recommendations on how to select the most secure ones.

Most Large Enterprises Fail to Protect Their Domain Names

Of the largest 2,000 companies in the world, 81% fail to take simple security measures, such as locking their domain with the registrar, leaving them open to domain shenanigans.

US Extradites CardPlanet Operator Back to Russia

Russian national Aleksi Burkov was sentenced to nine years in prison for his operation of two websites facilitating payment card fraud.

Notorious Spyware Tool Found Hiding Beneath Four Layers of Obfuscation

FinFisher (aka FinSpy) surveillance software now goes to extreme lengths to duck analysis and discovery, researchers found in a months-long investigation.

Modern Security Breaches Demand Diligent Planning and Executive Support

Teams that remain reactive will always be on the back foot — take an active stance.

Master Lock Introduces New Bluetooth ProSeries Padlocks

New high-security padlocks integrate with easy-to-use software solution to offer security and cloud-based simplicity.

Washington's New Cyber Focus Raises the Bar for IT Pros Across Supply Chains

Rather than fight against tighter security regulations, MSPs and IT pros should step up to lead conversations about the future of their industry.

CISA: Wide Exploitation of New VMware vCenter Server Flaw Likely

Attackers can use the vulnerability to remotely execute arbitrary code.

Microsoft Adds Emergency Threat Mitigation to Its Exchange Server Software

The built-in service automates mitigations to known Exchange Server threats.