Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Latest News

Recently, the WannaCry ransomware worm was big news.  For security professionals working inside organizations with unpatched systems vulnerable to infection, it was a particularly busy period.  Plenty has been written about the malware itself, how it spread, the need to patch, and many other technical topics around the recent outbreak.  Much great analysis has been done, and I certainly don’t need to rehash that here.  I’d like to focus on a different angle ent

With numerous instances of account takeovers impacting companies like Groupon, TeamViewer and Camelot, the company that operates the U.K.’s National Lottery, as well as the recent breach of the Anti Public tool that’s used for verifying the legitimacy of hacked credentials, it’s time to take a closer look at these attacks and how to mitigate risk.

Centrify, a Santa Clara, Calif.-based provider of identity and access management (IAM) solutions, has teamed up with Bugcrowd for a public bug bounty program that offers researchers up to $3,000 per vulnerability.

California-based operational intelligence firm OSIsoft has released updates for its PI Web API and PI Server products to address several vulnerabilities, including ones rated high severity.ICS-CERT has published two advisories this week to inform organizations about three remotely exploitable flaws affecting the OSIsoft products.

As organizations move to the cloud, one of the biggest changes we’ve seen is in the nature of the application landscape. This is the age of apps. Large companies are dealing with hundreds if not thousands of them, and nearly every enterprise is engaged in software development of some kind. 

A series of events converged during the past few weeks that reemphasized the need for our industry to do a better job of establishing measurable and repeatable processes. 

The United States Computer Emergency Readiness Team (US-CERT) released a technical alert on Tuesday on behalf of the DHS and the FBI to warn organizations of North Korea’s “Hidden Cobra” activities, particularly distributed denial-of-service (DDoS) attacks.

SAP this week released its June 2017 set of security patches to address various bugs across its products, including a denial of service vulnerability that potentially impacts over 3,400 services exposed to the Internet.

It’s the best of the internet of things and the worst of the internet of things: unprecedented connectivity that creates both tremendous opportunity and considerable risk. In an environment extending from sensors and devices at the network edge to applications and services in the cloud, an end-to-end IoT ecosystem is essential to realizing opportunity without risking security, manageability and interoperability.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

By continuously analyzing security, infrastructure, and governance data, TrustCloud aims to give CISOs a real-time view of application risk and board-ready assurance.

Cloud Security

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.