Security
Headlines
HeadlinesLatestCVEs

Source

DARKReading

Learning Sales Skills Can Make Security Professionals More Effective

Amazon Web Services VP Sara Duffer highlights the top lessons she brought back to her security role after taking part in Amazon's shadow program.

DARKReading
#web#amazon#aws
Identity Governance and Administration, App Proliferation, and the App Integration Chasm

Most enterprises use more than 1,000 apps, according to ESG research, yet about half are integrated with IGA. Industry innovations enable teams to expand app coverage and get more IGA value.

How CISOs Can Best Work With CEOs and the Board: Lessons From the Field

To build an effective relationship with the CEO and board, CISOs must translate technical risks into business terms and position cybersecurity as a strategic business enabler rather than just a business function.

Orgs Move to SSO, Passkeys to Solve Bad Password Habits

In 2025, employees are still using weak passwords. Instead of forcing an impossible change, security leaders are working around the problem.

Coyote, Maverick Banking Trojans Run Rampant in Brazil

South America's largest country is notorious for banking malware attacks; Maverick self-terminates if its targeted user is based outside Brazil.

Kenya Kicks Off 'Code Nation' With a Nod to Cybersecurity

The African country aims to train 1 million workers in tech skills in the short term, with a focus on software engineering, cybersecurity, and data science.

'CitrixBleed 2' Wreaks Havoc as Zero-Day Bug

The same APT hammered critical bugs in Citrix NetScaler (CVE-2025-5777) and the Cisco Identity Service Engine (CVE-2025-20337) in a sign of growing adversary interest in identity and access management systems.

Google Looks to Dim 'Lighthouse' Phishing-as-a-Service Op

The phishing kit, run by a group known as the "Smishing Triad," has powered massive amounts of unpaid tolls and package tracking texts.

Microsoft Exchange 'Under Imminent Threat,' Act Now

Threats against Microsoft Exchange continue to mount, but there are steps both organizations and Microsoft can take to limit them.

Phishing Tool Uses Smart Redirects to Bypass Detection

A campaign against Microsoft 365 users leverages Quantum Route Redirection, which simplifies previously technical attack steps and has affected victims across 90 countries.