Security: Page 12


  • The U.S. Capitol Building at night with lightning in the background.
    Image attribution tooltip
    Naomi Eide/CIO Dive
    Image attribution tooltip

    Log4j is far from over, cyber review board says

    Exploitation of Log4j occurred at lower levels than experts predicted, yet it remains an "endemic vulnerability," the Cyber Safety Review Board said.

    By Naomi Eide • July 14, 2022
  • A sign is posted in front of a Marriott hotel.
    Image attribution tooltip
    Justin Sullivan via Getty Images
    Image attribution tooltip

    Latest Marriott breach shows a human error pattern

    The latest incident at the hotel chain is relatively minor compared to major breaches in late 2018 and early 2020, but it signals a pattern of neglect.

    By Matt Kapko • July 7, 2022
  • A conference room equipped with laptops in a modern panoramic office.
    Image attribution tooltip
    ismagilov via Getty Images
    Image attribution tooltip

    Cybersecurity expertise creeps onto Fortune 500 boards

    Companies are trusting technology experts to advise on cybersecurity and regulatory pressures from the board’s perspective.

    By Barbara DeLollis • July 6, 2022
  • A diverse group of executives talking in meeting room.
    Image attribution tooltip
    FangXiaNuo via Getty Images
    Image attribution tooltip

    CISO priorities for the second half of 2022

    Security executives from Zoom, NS1 and Oomnitza shared their security priorities for the rest of 2022, with a special emphasis on mastering the basics. 

    By Sue Poremba • July 5, 2022
  • Cyberattack and internet crime, hacking and malware concepts.
    Image attribution tooltip
    Techa Tungateja via Getty Images
    Image attribution tooltip

    Is your remote IT job candidate legit?

    Organizations are seeing a rise in deepfakes and stolen identities during the job application process, the FBI said.

    By Naomi Eide • June 29, 2022
  • Communication network concept. GUI (Graphical User Interface).
    Image attribution tooltip
    metamorworks via Getty Images
    Image attribution tooltip

    Organizations lag on confidence and policies to manage open source security

    It's taking longer for companies to find open source vulnerabilities, and shaky policies mean only the most critical flaws are attended to. 

    By David Jones • June 24, 2022
  • Team of professionals meeting in office around computers
    Image attribution tooltip
    gorodenkoff via Getty Images
    Image attribution tooltip

    Analysts nudge businesses to decentralize cybersecurity leadership

    The push is to enable employees to make informed security decisions while meeting enterprise needs with spread out security leadership. 

    By June 22, 2022
  • Software building
    Image attribution tooltip
    iStock / Getty Images Plus via Getty Images
    Image attribution tooltip
    Q&A

    What enterprise leaders can divine from software bills of materials

    Cyber defense tool: Software bills of materials (SBOMs) can expose elements of risks in applications.

    By June 13, 2022
  • An aerial view on a sunny morning of several of San Francisco's most well known architectural landmarks. A backdrop of the skyscrapers and Bay Bridge behind them.
    Image attribution tooltip
    DianeBentleyRaymond via Getty Images
    Image attribution tooltip

    5 takeaways from the RSA Conference

    The event tried to pick up where it left off 28 months ago. Can companies keep up with the accelerated pace and scale of cyber threats?

    By Matt Kapko • June 13, 2022
  • software, code, computer
    Image attribution tooltip

    Markus Spiske

    Image attribution tooltip

    Organizational changes required to mitigate security risks

    CIOs are implementing new strategies to lower software supply chain risk, but evaluating internal operations could prove more effective.

    By June 7, 2022
  • Server room (Sefa Ozel/Getty)
    Image attribution tooltip
    Sefa Ozel/Getty via Getty Images
    Image attribution tooltip

    Attackers aim for Atlassian Confluence zero day with mass, targeted exploitation

    The threat activity comes days after the company released a security fix for the on-premise vulnerability.

    By David Jones • June 7, 2022
  • A group of co-workers surround a computer screen
    Image attribution tooltip
    Yuri Arcurs via Getty Images
    Image attribution tooltip

    Microsoft Office zero day leaves researchers scrambling over the holiday weekend

    The company warns a successful attack could allow an attacker to install programs, delete data or create new accounts. 

    By David Jones • Updated May 31, 2022
  • A large hallway with supercomputers inside a server room data center.
    Image attribution tooltip
    luza studios via Getty Images
    Image attribution tooltip

    Critical VMware vulnerabilities resurface after threat actors evade patches within 48 hours

    Even with new patches available, CISA is concerned that threat actors will easily shake off the fixes once again.

    By Matt Kapko • May 19, 2022
  • A stock image of a calculator alongside financial numbers
    Image attribution tooltip
    atiatiati via Getty Images
    Image attribution tooltip

    What cyber insurance companies want from clients

    Insurers evaluate how a company leverages technology and what internal standards are in place to manage risk.

    By Sue Poremba • April 28, 2022
  • Computer language script and coding on screen.
    Image attribution tooltip
    themotioncloud via Getty Images
    Image attribution tooltip

    IT leaders remain bullish on open source despite security hiccups

    Enterprise adoption of open source has not cooled, but flaws have highlighted the need for a better understanding of dependencies. 

    By Brian Eastwood • April 25, 2022
  • Rendered image depicting global networks.
    Image attribution tooltip
    DKosig via Getty Images
    Image attribution tooltip

    Threat detection accelerates in Asia, Europe, as notification trends shift

    As companies boost defenses and share threat intelligence, malicious actors have less time to escalate attacks.

    By David Jones • April 19, 2022
  • Image attribution tooltip
    Sam Wasson via Getty Images
    Image attribution tooltip

    2 years later: What's next in security for the pandemic-era workforce

    Organizations can expect the return-to-work model to stress a corporate infrastructure that has languished in recent years. 

    By Sue Poremba • April 13, 2022
  • Image attribution tooltip
    Stefani Reynolds / Stringer via Getty Images
    Image attribution tooltip

    Federal authorities urged to bolster intel sharing amid nation-state threats

    Current Russian cyber activity has been limited, but experts called on federal authorities to keep providing actionable intelligence as risks endure.

    By David Jones • April 6, 2022
  • Dozens of lines of computer code on a monitor.
    Image attribution tooltip
    iStock / Getty Images Plus via Getty Images
    Image attribution tooltip

    Big tech is fixing bugs faster. Will that influence trickle down?

    If a customer lacks urgency in deploying a patch, a flaw can linger. 

    By Sue Poremba • April 1, 2022
  • Image attribution tooltip
    sakkmesterke via Getty Images
    Image attribution tooltip
    Sponsored by Hyperproof

    The security challenge for 2022: Operating under a continuous assurance model

    Companies are turning to continuous assurance to answer increased compliance maturity expectations.

    March 28, 2022
  • Image attribution tooltip
    Alex Wong via Getty Images
    Image attribution tooltip

    White House warns US of possible Russian cyberattack linked to Ukraine invasion

    The warnings come after federal authorities convened more than 100 critical infrastructure organizations to share classified cyberthreat information.

    By David Jones • March 21, 2022
  • Company signage outside Google's offices in Germany
    Image attribution tooltip
    Sean Gallup via Getty Images
    Image attribution tooltip

    Dinner is served: Cyber M&A feeding frenzy shows hunger for trust

    Google spent $5.4 billion to acquire Mandiant, which it plans to fold into Google Cloud. It was just one of 200-plus cybersecurity deals struck last year.

    By Naomi Eide • March 17, 2022
  • Image attribution tooltip
    Carsten Koall via Getty Images
    Image attribution tooltip

    Russian state-sponsored actors target PrintNightmare, MFA settings

    ESET researchers are separately warning about new data wiping malware.

    By David Jones • March 16, 2022
  • Google logo displayed outside the company's New York City office.
    Image attribution tooltip
    Drew Angerer via Getty Images
    Image attribution tooltip

    Google swoops in to buy Mandiant for $5.4B after weeks of market speculation

    The deal follows reported negotiations between Microsoft and Mandiant, after the incident response specialist sold off its FireEye products business late last year.

    By David Jones • March 8, 2022
  • A group of demonstrators hold U.S. and Ukrainian flags as they march in support of Ukraine in its war against Russia.
    Image attribution tooltip
    Kenny Holston via Getty Images
    Image attribution tooltip

    How to prepare employees for elevated cyber risk from the Ukraine crisis

    The conflict is still in its early stages, which may complicate employer response. But a good place to start may be to ensure baseline preparedness.

    By Ryan Golden • March 3, 2022