Microsoft Hires New CISO in Major Security Shakeup

Microsoft announced a major shakeup of its security hierarchy, removing the CISO and Deputy CISO and handing the reins to a recent hire who previously served as CTO and President at Bridgewater.
The post Microsoft Hires New CISO in Major Security Shake… Continue reading Microsoft Hires New CISO in Major Security Shakeup

Trail of Bits Spinout iVerify Tackles Mercenary Spyware Threat

iVerify, a seed-stage startup spun out of Trail of Bits, ships a mobile threat hunting platform to neutralize iOS and Android zero-days.
The post Trail of Bits Spinout iVerify Tackles Mercenary Spyware Threat appeared first on SecurityWeek.
Continue reading Trail of Bits Spinout iVerify Tackles Mercenary Spyware Threat

Staples Confirms ‘Cybersecurity Risk’ Disrupting Online Stores

Office supply retail giant confirms security incident disrupted online orders, communications channels and customer service lines.
The post Staples Confirms ‘Cybersecurity Risk’ Disrupting Online Stores appeared first on SecurityWeek.
Continue reading Staples Confirms ‘Cybersecurity Risk’ Disrupting Online Stores

Apple Patches WebKit Flaws Exploited on Older iPhones

Apple’s security response team warns that flaws CVE-2023-42916 and CVE-2023-42917 were already exploited against versions of iOS before iOS 16.7.1.
The post Apple Patches WebKit Flaws Exploited on Older iPhones appeared first on SecurityWeek.
Continue reading Apple Patches WebKit Flaws Exploited on Older iPhones

Major Security Flaws in Zyxel Firewalls, Access Points, NAS Devices

Zyxel patches at least 15 security flaws that expose users to authentication bypass, command injection and denial-of-service attacks.
The post Major Security Flaws in Zyxel Firewalls, Access Points, NAS Devices appeared first on SecurityWeek.
Continue reading Major Security Flaws in Zyxel Firewalls, Access Points, NAS Devices

Keyless Goes Independent, Raises $6M for Biometric Authentication

British startup building biometric authentication technology has snagged $6 million in a new round of funding led by Rialto Ventures.
The post Keyless Goes Independent, Raises $6M for Biometric Authentication appeared first on SecurityWeek.
Continue reading Keyless Goes Independent, Raises $6M for Biometric Authentication

Okta Broadens Scope of Data Breach: All Customer Support Users Affected

Okta expands scope of October breach, saying hackers stole names and email addresses of all its customer support system users.
The post Okta Broadens Scope of Data Breach: All Customer Support Users Affected appeared first on SecurityWeek.
Continue reading Okta Broadens Scope of Data Breach: All Customer Support Users Affected

Researchers Discover Dangerous Exposure of Sensitive Kubernetes Secrets

Researchers at Aqua call urgent attention to the public exposure of Kubernetes configuration secrets, warning that hundreds of organizations are vulnerable to this “ticking supply chain attack bomb.”
The post Researchers Discover Dangerous Exposure of… Continue reading Researchers Discover Dangerous Exposure of Sensitive Kubernetes Secrets

FCC Tightens Telco Rules to Combat SIM-Swapping

Under the new rules, wireless carriers are required to notify customers of any SIM transfer requests, a measure designed to thwart fraudulent attempts by cybercriminals.
The post FCC Tightens Telco Rules to Combat SIM-Swapping appeared first on Securi… Continue reading FCC Tightens Telco Rules to Combat SIM-Swapping