Application Security
New guidance from CISA and the NSA provides recommendations on securing CI/CD pipelines against malicious attacks.
Hi, what are you looking for?
Fifteen years after coining the framework, John Kindervag insists zero trust still works in the AI era—if you get the implementation right.
New guidance from CISA and the NSA provides recommendations on securing CI/CD pipelines against malicious attacks.
New SaaS-based secrets manager from Akeyless requires no new infrastructure, and no specialist staff nor secrets management team.
Microsoft is making SMB signing a default requirement in Windows 11 Enterprise editions, starting with insider preview build 25381.
When teams have a way to break down enterprise silos and see and understand what is happening, they can improve protection across their increasingly...
Hundreds of companies are showcasing their products and services this week at the 2023 edition of the RSA Conference in San Francisco.
An important area of differentiation to evaluate when you make your next security investment is the vendor’s effectiveness when it comes to customer success.
CISA has published the second version of its guide describing the necessary strategies and policies to achieve zero trust maturity.
NATO is looking for penetration testing vendors to assess the security of its internet-facing web assets.
The FDA is asking medical device manufacturers to provide cybersecurity-related information when submitting an application for a new product.
NSA publishes recommendations on maturing identity, credential, and access management capabilities to improve cyberthreat protections.
ChatGPT is increasingly integrated into cybersecurity products and services as the industry is testing its capabilities and limitations.
Microsoft and Mitre release Arsenal plugin to help cybersecurity professionals emulate attacks on machine learning (ML) systems.
In this virtual summit, SecurityWeek brings together expert defenders to share best practices around reducing attack surfaces in modern computing.
Attack surface management is nothing short of a complete methodology for providing effective cybersecurity. It doesn’t seek to protect everything, but concentrates on areas...
Hackers rarely hack in anymore. They log in using stolen, weak, default, or otherwise compromised credentials. That’s why it’s so critical to break the...
Out of the 335 public recommendations on a comprehensive cybersecurity strategy made since 2010, 190 were not implemented by federal agencies as of December...
Fortinet on Monday issued an emergency patch to cover a severe vulnerability in its FortiOS SSL-VPN product, warning that hackers have already exploited the...
Implementation of security automation can be overwhelming, and has remained a barrier to adoption
Vulnerability researchers at Google Project Zero are calling attention to the ongoing “patch-gap” problem in the Android ecosystem, warning that downstream vendors continue to...