From critical to controlled: Cutting vulnerabilities in a live manufacturing environment

A vulnerability scanner flags a critical CVSS 10 vulnerability on an industrial asset. The report lands in the boss’ inbox and now he wants to know why we’re sitting on a critical vulnerability. In a normal IT environment, you patch it then close the t… Continue reading From critical to controlled: Cutting vulnerabilities in a live manufacturing environment→

Attackers already know the secrets are on your developers’ machines. Do you?

In a recent GitGuardian analysis, an average of 150 secrets were found on a sample of developer endpoints. Private keys accounted for 38% of unique secrets, while cloud, identity provider, and secret management credentials (AWS IAM, Hashicorp vault) ad… Continue reading Attackers already know the secrets are on your developers’ machines. Do you?→

Simplify security management with CIS SecureSuite Platform

New operating systems prioritize usability, a reality which threat actors use to exploit security gaps. Every misconfiguration creates an opportunity for compromise, and lean teams struggle in their security management efforts to harden hundreds or tho… Continue reading Simplify security management with CIS SecureSuite Platform→

What CISOs need to do about post-quantum migration in the next 24 months

In this Help Net Security video, Garfield Jones, SVP Global Strategy and Research, QuSecure, lays out what CISOs should do over the next 24 months. A recent Google paper moved the expected arrival of a cryptographically relevant quantum computer from 2… Continue reading What CISOs need to do about post-quantum migration in the next 24 months→

Why you need BAS and autonomous pentesting together

Most security teams know the drill: A new autonomous penetration testing tool gets deployed, and the first run is genuinely impressive. The dashboard surfaces critical findings, maps lateral movement paths nobody had documented before, and exposes a le… Continue reading Why you need BAS and autonomous pentesting together→

Week in review: Infostealer dropped via FortiClient EMS flaw, exploited Trend Micro Apex One flaw

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Coinflow CISO on crypto payments security under AI pressure Crypto payment firms sit near the top of the target list for advanced persistent threat groups… Continue reading Week in review: Infostealer dropped via FortiClient EMS flaw, exploited Trend Micro Apex One flaw→

Building a risk-based vulnerability management program that scales

In this Help Net Security video, Shankar Somasundaram, CEO at Asimily, explains how to build a risk-based vulnerability program. He notes that vulnerabilities are exploding by an order of magnitude in the age of AI-driven attacks, with one customer fin… Continue reading Building a risk-based vulnerability management program that scales→

The alert economy is driving security analyst burnout

In this Help Net Security video, Ido Livneh, CEO of Jazz, explains why security analysts burn out and what leaders can do about it. The cause, he argues, is not long hours but meaningless work. Analysts spend their days closing repetitive tickets while… Continue reading The alert economy is driving security analyst burnout→

Manage machine identities: The hidden privileged access layer you need to manage

Why are machine identities becoming the majority of “things with access”? Every automation, integration, and workload needs a way to authenticate and the right permissions to act. That quiet requirement has created a massive population of machine ident… Continue reading Manage machine identities: The hidden privileged access layer you need to manage→